Logo Hardware.com.br
piresjam
piresjam Veterano Registrado
798 Mensagens 49 Curtidas

[Resolvido] Problema com Vírus: solução?

#1 Por piresjam 23/02/2022 - 15:41
Boa tarde!

Surgiu um problema com vírus na minha máquina (fica gerando alertas de vírus constantemente por meio de notificações)

1º) Fiz varredura com o Avira, e foram encontrados 4 itens (vide imagem "WhatsApp Imagem 2022-02-23 at..." em anexo), os quais já realizei a exclusão. Contudo, o mesmo problema persiste (vide imagem "Captura de tela 2022-02-23 152508..." em anexo).
OBS! Tenho o log da varredura gravado. Acho que tenho aguardar alguém autorizar o envio.

2º) Realizei o procedimento descrito na página de "Análise de log, remoção de vírus..." com o Farbar Recovery Scan Tool.
OBS! Tenho os liinks salvos e os respectivos logs: FRST e Addition


Acredito que devo aguardar alguém solicitar os logs, conforme orientação descrita aqui: https://www.hardware.com.br/comunidade/v-t/1226830/ certo?

Anexo do post Anexo do post

Att,

Anexos

Henrique - RJ
Henrique - R... Cyber Highlander Registrado
6.6K Mensagens 1.7K Curtidas
#2 Por Henrique - R...
23/02/2022 - 16:17
PUP ou PUA ou programas potencialmente indesejáveis.

Faz uma limpeza do cache do navegador e da lixeira vc se livra de dois.

Desinstala o Advanced Sustem Care que vc ae livra de mais dois.
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...

São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam.


Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano
PH
PH Cyber Highlander Registrado
61.3K Mensagens 10.7K Curtidas
#3 Por PH
23/02/2022 - 18:19
piresjam disse:
Boa tarde!

Surgiu um problema com vírus na minha máquina (fica gerando alertas de vírus constantemente por meio de notificações)

1º) Fiz varredura com o Avira, e foram encontrados 4 itens (vide imagem "WhatsApp Imagem 2022-02-23 at..." em anexo), os quais já realizei a exclusão. Contudo, o mesmo problema persiste (vide imagem "Captura de tela 2022-02-23 152508..." em anexo).
OBS! Tenho o log da varredura gravado. Acho que tenho aguardar alguém autorizar o envio.

2º) Realizei o procedimento descrito na página de "Análise de log, remoção de vírus..." com o Farbar Recovery Scan Tool.
OBS! Tenho os liinks salvos e os respectivos logs: FRST e Addition


Acredito que devo aguardar alguém solicitar os logs, conforme orientação descrita aqui: https://www.hardware.com.br/comunidade/v-t/1226830/ certo?

Att,


Boa noite!

Não precisa aguardar alguém pedir os logs, já pode postar no tópico para que possamos analisar.

Anexo do post

Não caia nessa, se tem o Avira instalado, não precisa de outros antivírus, esse aviso é do McAfee. Na realidade eu não usaria nenhum nem outro, prefiro usar o Kaspersky.

Anexos

Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
piresjam
piresjam Veterano Registrado
798 Mensagens 49 Curtidas
#4 Por piresjam
23/02/2022 - 21:12
Boa noite, PH!! Na verdade, antes da pôr o Avira, verifiquei e não encontrei no sistema o McAfee. Acredito que já o tinha desinstalado.

"Log FRST"

Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 14-02-2022 01
Executado por Dell (administrador) em DESKTOP-S32LBR1 (Dell Inc. Inspiron 3583) (23-02-2022 20:36:28)
Executando a partir de C:\Users\Dell\Downloads
Perfis Carregados: Dell
Plataforma: Microsoft Windows 10 Home Single Language Versão 21H1 19043.1526 (X64) Idioma: Português (Brasil)
Navegador padrão: Edge
Modo da Inicialização: Normal

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(C:\Program Files (x86)\Avira\Antivirus\avguard.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe ->) (IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Pub\PubPlatform.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <42>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <10>
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_9384fc4d30af89c3\WavesSvc64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe
(IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(services.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(services.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\protectedservice.exe
(services.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(services.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe
(services.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe
(services.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
(services.exe ->) (IObit CO., LTD -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(services.exe ->) (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD) C:\Program Files\Topaz OFD\Warsaw\core.exe <2>
(Spotify AB) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe <6>
(svchost.exe ->) (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Systray.Application.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxAccounts.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxTsr.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe

==================== Registro (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_8443b1c224b06d42\RtkAudUService64.exe [1256824 2021-04-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_9384fc4d30af89c3\WavesSvc64.exe [1645664 2020-04-14] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [707256 2021-12-15] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe --startup_mode (Nenhum Arquivo)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe --startup_mode (Nenhum Arquivo)
HKU\S-1-5-21-1052734516-3327908542-3545902175-1001\...\Run: [MicrosoftEdgeAutoLaunch_B5BC174A7B4ABF98EC6D64B02610726A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKU\S-1-5-21-1052734516-3327908542-3545902175-1001\...\Run: [Advanced SystemCare] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3779152 2021-09-28] (IObit CO., LTD -> IObit)
HKU\S-1-5-21-1052734516-3327908542-3545902175-1002\...\Run: [MicrosoftEdgeAutoLaunch_D858EA49C56778ACA0D6F057A3825E4B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKU\S-1-5-21-1052734516-3327908542-3545902175-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\54.0.3.0\GoogleDriveFS.exe [55330648 2022-01-11] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1052734516-3327908542-3545902175-1003\...\Run: [MicrosoftEdgeAutoLaunch_232ED57ABE9D55FB25DD2EDECEFDE91C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
HKU\S-1-5-21-1052734516-3327908542-3545902175-1003\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe --startup_mode (Nenhum Arquivo)
HKU\S-1-5-21-1052734516-3327908542-3545902175-1003\...\Run: [] => [X]
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\55.0.3.0\GoogleDriveFS.exe --startup_mode (Nenhum Arquivo)
HKU\S-1-5-18\...\Run: [Advanced SystemCare] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3779152 2021-09-28] (IObit CO., LTD -> IObit)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\98.0.4758.102\Installer\chrmstp.exe [2022-02-16] (Google LLC -> Google LLC)

==================== Tarefas Agendadas (Whitelisted) ============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {0CD92EC1-B9E0-4186-B926-0B2C3423BF87} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1052734516-3327908542-3545902175-1002 => C:\Users\Dell\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (Nenhum Arquivo)
Task: {21471697-2D76-438B-97D1-8088CDE6DD01} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2021-12-01] (Google LLC -> Google LLC)
Task: {31AE7588-902A-49EE-A4AA-E6E8B0BA0FBF} - \ASC_SkipUac_Dell -> Nenhum Arquivo <==== ATENÇÃO
Task: {44894DE1-9A13-4E5C-926C-B923EB92B973} - System32\Tasks\Avira_Security_Maintenance => Command(1): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> FallbackTelemetry
Task: {44894DE1-9A13-4E5C-926C-B923EB92B973} - System32\Tasks\Avira_Security_Maintenance => Command(2): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> ServiceWatchdog
Task: {44894DE1-9A13-4E5C-926C-B923EB92B973} - System32\Tasks\Avira_Security_Maintenance => Command(3): C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe -> CrashCollector
Task: {681B7323-DA24-4933-B797-D31609175549} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2648424 2021-10-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {6B57B808-93D1-4F06-8BD3-9BA73378724B} - System32\Tasks\Avira_Security_Service_SCM_Watchdog => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.Worker.exe [255416 2022-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {76AD8279-8FAE-4723-B285-C5DA99999F37} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2021-12-01] (Google LLC -> Google LLC)
Task: {92A58082-4760-484A-84AF-69B2840426A0} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1052734516-3327908542-3545902175-1002 => C:\Users\Dell\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (Nenhum Arquivo)
Task: {A4DB7CF0-C8C9-4E34-88EB-8ABE4B01868E} - System32\Tasks\Avira_Security_Systray => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Systray.Application.exe [1663432 2022-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {DD947204-9614-4870-A175-B981D87AD2FC} - System32\Tasks\AviraSystemSpeedupUpdate => C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [30208384 2022-02-22] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {E9F8E126-E9B4-4E01-AEE2-6F551C98D08F} - System32\Tasks\Microsoft\Windows\WaaSMedic\MaintenanceWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}
Task: {EBFC14EF-6D56-4C84-973E-EA9691E786ED} - System32\Tasks\Avira_Security_Update => C:\Windows\system32\net.exe [59904 2019-12-07] (Microsoft Windows -> Microsoft Corporation)

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)


==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{3fc5b7a6-23f3-4e59-bd4c-731ff12d89db}: [DhcpNameServer] 181.213.132.2 181.213.132.3
Tcpip\..\Interfaces\{c9acef69-0bfe-496a-b0d3-91b7709d742b}: [DhcpNameServer] 208.67.222.222 208.67.220.220

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Dell\AppData\Local\Microsoft\Edge\User Data\Default [2022-02-23]
Edge Extension: (Avira Safe Shopping) - C:\Users\Dell\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\caiblelclndcckfafdaggpephhgfpoip [2022-02-23]
Edge Extension: (Avira Password Manager) - C:\Users\Dell\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emgfgdclgfeldebanedpihppahgngnle [2022-02-23]
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.321.2 -> C:\Program Files\Java\jre1.8.0_321\bin\dtplugin\npDeployJava1.dll [2022-01-22] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.321.2 -> C:\Program Files\Java\jre1.8.0_321\bin\plugin2\npjp2.dll [2022-01-22] (Oracle America, Inc. -> Oracle Corporation)

Chrome:
=======
CHR Profile: C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default [2022-02-23]
CHR Notifications: Default -> hxxps://www.facebook.com
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com.br/","hxxp://www.hotmail.com/","hxxp://www.uol.com.br/","hxxp://www.gsmfans.com.br/","hxxp://www.google.com.br/?gfe_rd=cr&ei=jAmNU_mrHIbBgATN54CgDg"
CHR Session Restore: Default -> está habilitado.
CHR Extension: (Apresentações) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-12-01]
CHR Extension: (Documentos) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-12-01]
CHR Extension: (Google Drive) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-12-01]
CHR Extension: (MEGA) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2022-02-23]
CHR Extension: (Chamada pelo Skype) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2021-12-01]
CHR Extension: (YouTube) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-12-01]
CHR Extension: (Avira Password Manager) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2022-02-23]
CHR Extension: (Avira Safe Shopping) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2022-02-23]
CHR Extension: (Adblock Plus - bloqueador de anúncios grátis) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-01-22]
CHR Extension: (Planilhas) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-12-01]
CHR Extension: (Segurança do navegador Avira) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2022-02-23]
CHR Extension: (Documentos Google off-line) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-23]
CHR Extension: (AdBlock — o melhor bloqueador de anúncios) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-02-08]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-01]
CHR Extension: (Gmail) - C:\Users\Dell\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-12-01]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]

==================== Serviços (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 AdvancedSystemCareService15; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [1873488 2021-08-21] (IObit CO., LTD -> IObit)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1206648 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntivirProtectedService; C:\Program Files (x86)\Avira\Antivirus\ProtectedService.exe [538000 2021-06-25] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [485048 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [485048 2021-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [574832 2022-01-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2998096 2021-11-23] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [382944 2022-01-25] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraSecurity; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe [265096 2022-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S2 AviraSecurityUpdater; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Common.Updater.exe [265008 2022-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [38600 2021-07-20] (Dell Inc -> )
S4 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [260256 2022-01-30] (HP Inc. -> HP Inc.)
R2 Warsaw Technology; C:\Program Files\Topaz OFD\Warsaw\core.exe [975472 2021-02-10] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe [2909208 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe [128376 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 WMIRegistrationService; C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe [538736 2021-10-05] (Intel Corporation -> Intel Corporation)

===================== Drivers (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R3 AscFileFilter; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [46552 2021-07-07] (IObit CO., LTD -> IObit)
R3 AscRegistryFilter; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [46552 2021-07-07] (IObit CO., LTD -> IObit)
R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [78936 2019-06-07] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S0 avelam; C:\Windows\System32\drivers\avelam.sys [22848 2021-06-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [209088 2021-10-22] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [199312 2021-02-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [46704 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [89736 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [45472 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 googledrivefs3688; C:\Windows\System32\DRIVERS\googledrivefs3688.sys [381456 2021-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 iobit_monitor_server2021; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win10_x64.sys [33256 2021-08-11] (IObit CO., LTD -> IObit)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2022-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [438520 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [90360 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
R1 wsddfac; C:\Windows\System32\drivers\wsddfac.sys [37840 2022-02-23] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
R1 wsddntf; C:\Windows\system32\DRIVERS\wsddntf.sys [51160 2021-02-11] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
R1 wsddpp; C:\Windows\system32\drivers\wsddpp.sys [34768 2021-02-11] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
R3 wsddprm; C:\Windows\system32\drivers\wsddprm.sys [33728 2021-02-10] (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
S3 cpuz150; \??\C:\Windows\temp\cpuz150\cpuz150_x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três meses (criados) (Whitelisted) =========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2022-02-23 20:36 - 2022-02-23 20:38 - 000020656 _____ C:\Users\Dell\Downloads\FRST.txt
2022-02-23 20:34 - 2022-02-23 20:34 - 002312192 _____ (Farbar) C:\Users\Dell\Downloads\FRST64.exe
2022-02-23 20:26 - 2022-02-23 20:26 - 000000000 ___HD C:\$SysReset
2022-02-23 16:39 - 2022-02-23 16:39 - 000000000 _____ C:\Windows\invcol.tmp
2022-02-23 16:00 - 2022-02-23 16:00 - 000000000 ____D C:\Users\cicer\AppData\Roaming\Zoom
2022-02-23 16:00 - 2022-02-23 16:00 - 000000000 ____D C:\Users\cicer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2022-02-23 15:20 - 2022-02-23 15:20 - 000052374 _____ C:\Users\cicer\Downloads\WhatsApp Image 2022-02-23 at 15.21.12.jpeg
2022-02-23 15:02 - 2022-02-23 15:06 - 000032974 _____ C:\Users\cicer\Downloads\Addition.txt
2022-02-23 14:51 - 2022-02-23 20:37 - 000000000 ____D C:\FRST
2022-02-23 14:51 - 2022-02-23 15:06 - 000053650 _____ C:\Users\cicer\Downloads\FRST.txt
2022-02-23 14:50 - 2022-02-23 14:50 - 002312192 _____ (Farbar) C:\Users\cicer\Downloads\FRST64.exe
2022-02-22 22:36 - 2022-02-22 22:36 - 085880832 _____ C:\Windows\system32\config\SOFTWARE.iobit
2022-02-22 22:36 - 2022-02-22 22:36 - 000454656 _____ C:\Windows\system32\config\DEFAULT.iobit
2022-02-22 22:36 - 2022-02-22 22:36 - 000131072 _____ C:\Windows\system32\config\SAM.iobit
2022-02-22 22:36 - 2022-02-22 22:36 - 000045056 _____ C:\Windows\system32\config\SECURITY.iobit
2022-02-22 22:20 - 2022-02-22 22:20 - 000000000 ____D C:\Users\Public\Security Sessions
2022-02-22 22:20 - 2022-02-22 22:20 - 000000000 ____D C:\Users\cicer\AppData\Local\Avira
2022-02-22 22:19 - 2022-02-22 22:19 - 000000000 ____D C:\Windows\SysWOW64\statReporter
2022-02-22 22:16 - 2022-02-22 22:16 - 000003374 _____ C:\Windows\system32\Tasks\Avira_Antivirus_Systray
2022-02-22 22:16 - 2022-02-22 22:16 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2022-02-22 22:16 - 2021-10-22 09:45 - 000209088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2022-02-22 22:16 - 2021-06-25 14:59 - 000022848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avelam.sys
2022-02-22 22:16 - 2021-02-09 18:03 - 000199312 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2022-02-22 22:16 - 2019-06-07 15:09 - 000078936 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avdevprot.sys
2022-02-22 22:16 - 2019-03-20 18:50 - 000089736 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2022-02-22 22:16 - 2019-03-20 18:50 - 000046704 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2022-02-22 22:16 - 2019-03-20 18:50 - 000045472 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys
2022-02-22 22:13 - 2022-02-22 22:13 - 000003776 _____ C:\Windows\system32\Tasks\AviraSystemSpeedupUpdate
2022-02-22 22:13 - 2022-02-22 22:13 - 000000000 ____D C:\Users\Public\Speedup Sessions
2022-02-22 22:13 - 2022-02-22 22:13 - 000000000 ____D C:\Users\Dell\AppData\Local\Avira
2022-02-22 22:12 - 2022-02-22 22:16 - 000000000 ____D C:\Program Files (x86)\Avira
2022-02-22 22:12 - 2022-02-22 22:12 - 000003888 _____ C:\Windows\system32\Tasks\Avira_Security_Maintenance
2022-02-22 22:12 - 2022-02-22 22:12 - 000003480 _____ C:\Windows\system32\Tasks\Avira_Security_Update
2022-02-22 22:12 - 2022-02-22 22:12 - 000003428 _____ C:\Windows\system32\Tasks\Avira_Security_Service_SCM_Watchdog
2022-02-22 22:12 - 2022-02-22 22:12 - 000002818 _____ C:\Windows\system32\Tasks\Avira_Security_Systray
2022-02-22 22:12 - 2022-02-22 22:12 - 000001176 _____ C:\Users\Public\Desktop\Avira.lnk
2022-02-22 22:12 - 2022-02-22 22:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2022-02-22 22:09 - 2022-02-22 22:20 - 000000000 ____D C:\ProgramData\Avira
2022-02-22 22:08 - 2022-02-22 22:08 - 005547256 _____ (Avira Operations GmbH & Co. KG) C:\Users\cicer\Downloads\avira_pt-br_sptl1_1505298336-1645578460__phpws.exe
2022-02-22 20:44 - 2022-02-22 20:44 - 000367056 _____ C:\Users\cicer\Downloads\CT 32.2020 - ETANERCEPTE 25MG.ML - 25000.079894.2020-43 - 05.03 - LABORATORIOS PFIZER LTDA.pdf
2022-02-21 20:50 - 2022-02-21 20:50 - 000033745 _____ C:\Users\Jacqueline Gerbase\Downloads\RelatorioConsultaDevedorPDF.pdf
2022-02-21 20:47 - 2022-02-21 20:47 - 000012802 _____ C:\Users\Jacqueline Gerbase\Downloads\Relatorio.pdf
2022-02-21 20:26 - 2022-02-21 20:26 - 000000000 ____D C:\Users\Jacqueline Gerbase\Documents\IR 2021
2022-02-21 20:24 - 2022-02-21 20:24 - 000076513 _____ C:\Users\Jacqueline Gerbase\Downloads\50518119491-IRPF-A-2021-2020-REC (2).pdf
2022-02-21 20:24 - 2022-02-21 20:24 - 000076280 _____ C:\Users\Jacqueline Gerbase\Downloads\50518119491-IRPF-A-2021-2020-REC (1).pdf
2022-02-20 21:18 - 2022-02-20 21:38 - 000000000 ____D C:\Users\cicer\.rfb
2022-02-20 21:18 - 2022-02-20 21:18 - 000000000 ____D C:\Users\cicer\.irpf
2022-02-20 15:36 - 2022-02-20 15:37 - 000086177 _____ C:\Users\cicer\Downloads\Informe de Rendimentos.pdf
2022-02-18 16:22 - 2022-02-18 16:22 - 000132971 _____ C:\Users\cicer\Downloads\WhatsApp Image 2022-02-18 at 16.02.45.jpeg
2022-02-18 16:22 - 2022-02-18 16:22 - 000117571 _____ C:\Users\cicer\Downloads\WhatsApp Image 2022-02-18 at 16.01.27.jpeg
2022-02-18 16:19 - 2022-02-18 16:19 - 000289332 _____ C:\Users\cicer\Downloads\WhatsApp Image 2022-02-18 at 16.02.37.jpeg
2022-02-17 15:28 - 2022-02-17 15:28 - 000035747 _____ C:\Users\cicer\Downloads\Comprovante de pgto mensalidade 06_2021.pdf
2022-02-17 15:25 - 2022-02-17 15:25 - 000035772 _____ C:\Users\cicer\Downloads\Foto de Cícero Pires (1).pdf
2022-02-17 14:56 - 2022-02-17 14:56 - 000006112 _____ C:\Users\cicer\Downloads\comprovante (1).html
2022-02-16 11:45 - 2022-02-16 11:45 - 007905280 _____ C:\Windows\system32\config\DRIVERS.iobit
2022-02-16 11:45 - 2022-02-16 11:45 - 000000002 _____ C:\Users\Jacqueline
2022-02-15 19:53 - 2022-02-15 19:53 - 000003406 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1052734516-3327908542-3545902175-1002
2022-02-15 19:53 - 2022-02-15 19:53 - 000002428 _____ C:\Users\Jacqueline Gerbase\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-02-11 13:42 - 2022-02-11 13:42 - 000011813 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-02-11 13:41 - 2022-02-11 13:41 - 000223744 _____ C:\Windows\SysWOW64\TpmTool.exe
2022-02-11 13:39 - 2022-02-11 13:39 - 000288768 _____ C:\Windows\system32\Windows.Management.InprocObjects.dll
2022-02-11 13:39 - 2022-02-11 13:39 - 000272384 _____ C:\Windows\system32\TpmTool.exe
2022-02-11 13:39 - 2022-02-11 13:39 - 000162816 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe
2022-02-11 13:38 - 2022-02-11 13:39 - 035118899 _____ C:\Users\cicer\Downloads\Norberto Avena - ProcessoPenal - 2017 (Pdf).pdf
2022-02-11 13:05 - 2022-02-11 13:05 - 000000000 ___HD C:\$WinREAgent
2022-02-08 20:11 - 2022-02-08 20:11 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2022-02-08 11:47 - 2022-02-08 11:47 - 000001091 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2022-02-08 11:47 - 2022-02-08 11:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2022-02-08 11:47 - 2022-02-08 11:47 - 000000000 ____D C:\Program Files\VS Revo Group
2022-02-08 11:46 - 2022-02-08 11:47 - 007513880 _____ (VS Revo Group ) C:\Users\Dell\Downloads\revosetup.exe
2022-02-08 00:02 - 2022-02-08 00:13 - 2117363412 _____ C:\Users\cicer\Downloads\iGO_2021.rar
2022-02-07 10:17 - 2022-02-07 10:17 - 000077655 _____ C:\Users\cicer\Downloads\Formulário Vamu SMTT.pdf
2022-02-03 20:23 - 2022-02-03 20:29 - 915169832 _____ C:\Users\cicer\Downloads\DIREITO - UNINASSAU 2019 - 2024-20220203T232222Z-001.zip
2022-02-03 20:01 - 2021-10-08 11:00 - 000167544 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys
2022-02-02 22:24 - 2022-02-02 22:24 - 000033869 _____ C:\Users\cicer\Downloads\DecVinculo_07023561_4E368F.pdf
2022-02-02 13:27 - 2022-02-02 13:27 - 000040651 _____ C:\Users\cicer\Downloads\Boleto de pagamento (1).pdf
2022-02-02 12:36 - 2022-02-02 12:36 - 000206340 _____ C:\Users\cicer\Downloads\SEI_E_41010.0000020678_2021.pdf
2022-02-01 21:03 - 2022-02-01 21:03 - 000000000 ____D C:\ProgramData\Intel Package Cache {58E22E6B-0E58-4E93-AF9A-036556EB66F5}
2022-02-01 20:58 - 2022-02-01 20:58 - 000000000 ____D C:\Program Files\Dell
2022-02-01 19:51 - 2022-02-01 19:51 - 000043483 _____ C:\Users\cicer\Downloads\historico_195225.pdf
2022-02-01 19:29 - 2022-02-01 19:29 - 000533765 _____ C:\Users\cicer\Downloads\COMO_SALVAR_SEU_FILHO_pela_via_judicial_CONHECA_seus_direitos_primeiro_14012022.pdf
2022-01-24 11:50 - 2022-01-24 11:50 - 000043802 _____ C:\Users\cicer\Downloads\historico_115128.pdf
2022-01-22 15:38 - 2022-01-22 15:39 - 000000000 ____D C:\Users\Dell\.rfb
2022-01-22 15:38 - 2022-01-22 15:38 - 000000000 ____D C:\Users\Dell\.irpf
2022-01-22 14:14 - 2022-01-22 14:16 - 000001791 _____ C:\Users\Dell\Desktop\GCAP 2021 - Ganhos de Capital 2021.lnk
2022-01-22 14:13 - 2022-01-22 14:13 - 024447496 _____ (Receita Federal do Brasil) C:\Users\Jacqueline Gerbase\Downloads\GCAP2021Win32v1.3 (1).exe
2022-01-22 14:02 - 2022-01-22 14:02 - 000192736 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2022-01-22 14:02 - 2022-01-22 14:02 - 000000000 ____D C:\Users\Dell\AppData\Roaming\Sun
2022-01-22 14:02 - 2022-01-22 14:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2022-01-22 14:01 - 2022-01-22 14:01 - 000000000 ____D C:\ProgramData\Oracle
2022-01-22 14:01 - 2022-01-22 14:01 - 000000000 ____D C:\Program Files\Java
2022-01-22 13:56 - 2022-01-22 13:57 - 085969096 _____ (Oracle Corporation) C:\Users\Jacqueline Gerbase\Downloads\jre-8u321-windows-x64 (1).exe
2022-01-22 13:51 - 2022-01-22 13:51 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Roaming\Sun
2022-01-22 13:51 - 2022-01-22 13:51 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\LocalLow\Sun
2022-01-22 13:49 - 2022-01-22 13:49 - 000000000 ____D C:\Users\Dell\AppData\LocalLow\Sun
2022-01-22 13:48 - 2022-01-22 13:49 - 085969096 _____ (Oracle Corporation) C:\Users\Jacqueline Gerbase\Downloads\jre-8u321-windows-x64.exe
2022-01-22 09:01 - 2022-01-22 09:02 - 024447496 _____ (Receita Federal do Brasil) C:\Users\Jacqueline Gerbase\Downloads\GCAP2021Win32v1.3.exe
2022-01-22 08:43 - 2022-01-22 08:44 - 000076281 _____ C:\Users\Jacqueline Gerbase\Downloads\50518119491-IRPF-A-2021-2020-REC.pdf
2022-01-22 08:23 - 2022-01-22 08:23 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\CEF
2022-01-20 22:00 - 2022-01-20 22:00 - 000513694 _____ C:\Users\cicer\Downloads\NOTA SEDUC 2021 _ CEBRASPE.pdf
2022-01-18 10:57 - 2022-01-18 10:57 - 000041562 _____ C:\Users\cicer\Downloads\5182632656.pdf
2022-01-17 20:06 - 2022-01-17 20:06 - 000237555 _____ C:\Users\cicer\Downloads\EDITAL_PONTAPE_EDUCACAO.pdf
2022-01-12 15:23 - 2022-01-12 15:23 - 000523776 _____ (curl, hxxps://curl.se/) C:\Windows\system32\curl.exe
2022-01-12 15:23 - 2022-01-12 15:23 - 000464384 _____ (curl, hxxps://curl.se/) C:\Windows\SysWOW64\curl.exe
2022-01-12 15:10 - 2022-01-12 15:10 - 000043797 _____ C:\Users\cicer\Downloads\historico_escolar_cra (2).pdf
2022-01-12 10:23 - 2022-01-12 10:23 - 000006100 _____ C:\Users\cicer\Downloads\comprovante.html
2022-01-07 11:54 - 2022-02-22 07:31 - 000000000 ____D C:\Users\Jacqueline Gerbase\.irpf
2022-01-07 11:54 - 2022-01-22 14:14 - 000000000 ___HD C:\Program Files (x86)\InstallJammer Registry
2022-01-07 11:54 - 2022-01-22 14:14 - 000000000 ____D C:\Users\Dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programas RFB2021
2022-01-07 11:54 - 2022-01-07 11:57 - 000000000 ____D C:\Users\Jacqueline Gerbase\.rfb
2022-01-07 11:54 - 2022-01-07 11:54 - 000001781 _____ C:\Users\Public\Desktop\IRPF2021 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País.lnk
2022-01-07 11:54 - 2022-01-07 11:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programas RFB2021
2022-01-07 11:53 - 2022-01-22 14:14 - 000000000 ____D C:\Arquivos de Programas RFB
2022-01-07 11:47 - 2022-01-07 11:51 - 082503008 _____ (Receita Federal do Brasil) C:\Users\Jacqueline Gerbase\Downloads\IRPF2021Win32v1.9.exe
2022-01-05 22:30 - 2022-01-05 22:30 - 000044127 _____ C:\Users\cicer\Downloads\historico_223138.pdf
2022-01-04 13:35 - 2022-01-04 13:36 - 000593723 _____ C:\Users\cicer\Downloads\GGMONPfizerpediatrica.pdf
2021-12-27 21:49 - 2017-09-07 05:52 - 004800160 _____ (HP Inc.) C:\Windows\system32\HPScanTEDrv_DJ2600_x64.dll
2021-12-27 21:49 - 2017-09-07 05:52 - 003399328 _____ (HP Inc.) C:\Windows\SysWOW64\HPScanTEDrv_DJ2600.dll
2021-12-27 21:49 - 2017-09-07 05:52 - 000783520 _____ (HP Inc.) C:\Windows\system32\HPScanTEDrv_DJ2600_x64_DiscoveryLibDyn.dll
2021-12-27 21:49 - 2017-09-07 05:52 - 000613536 _____ (HP Inc., LP) C:\Windows\system32\HPWia2_DJ2600.dll
2021-12-27 21:49 - 2017-09-07 05:52 - 000588448 _____ (HP Inc.) C:\Windows\SysWOW64\HPScanTEDrv_DJ2600_DiscoveryLibDyn.dll
2021-12-25 21:59 - 2021-12-25 21:59 - 000000000 ____D C:\Users\cicer\Tracing
2021-12-25 21:21 - 2021-12-25 21:21 - 000594133 _____ C:\Users\cicer\Downloads\JAQUELINE LOTE F21 LAYOUT (1).pdf
2021-12-25 21:21 - 2021-12-25 21:21 - 000496357 _____ C:\Users\cicer\Downloads\JAQUELINE LOTE F21 PLANTA BAIXA COTADA (1).pdf
2021-12-23 12:48 - 2021-12-23 12:48 - 000043797 _____ C:\Users\cicer\Downloads\historico_escolar_cra (1).pdf
2021-12-23 12:30 - 2021-12-23 12:30 - 000043797 _____ C:\Users\cicer\Downloads\historico_escolar_cra.pdf
2021-12-23 12:26 - 2021-12-23 12:26 - 000047316 _____ C:\Users\cicer\Downloads\Termo de Uso.pdf
2021-12-23 11:50 - 2021-12-23 11:50 - 000371914 _____ C:\Users\cicer\Documents\06 - DECLARAÇÃO QUE NÃO EXERCE CARGO PÚBLICO.pdf
2021-12-23 11:46 - 2021-12-23 11:46 - 000001171 _____ C:\Users\Dell\Desktop\Wordpad.lnk
2021-12-23 11:46 - 2021-12-23 11:46 - 000001134 _____ C:\Users\Dell\Desktop\Snipping Tool.lnk
2021-12-22 14:29 - 2021-12-22 14:29 - 000000000 ____D C:\Users\cicer\AppData\Local\OneDrive
2021-12-20 20:57 - 2021-12-14 07:44 - 000381456 _____ (Google, Inc.) C:\Windows\system32\Drivers\googledrivefs3688.sys
2021-12-18 01:21 - 2021-12-18 01:21 - 000000000 ____D C:\Windows\SystemTemp
2021-12-15 18:30 - 2021-12-15 18:30 - 000000000 ____D C:\Users\Dell\AppData\Local\CEF
2021-12-15 18:29 - 2021-12-15 18:29 - 000000000 ____D C:\Users\Dell\AppData\Local\ElevatedDiagnostics
2021-12-14 11:56 - 2021-12-14 11:56 - 000265539 _____ C:\Users\cicer\Downloads\mpdf (1).pdf
2021-12-14 11:54 - 2021-12-14 11:54 - 000265539 _____ C:\Users\cicer\Downloads\mpdf.pdf
2021-12-12 21:37 - 2021-12-12 21:37 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\OneDrive
2021-12-12 18:09 - 2021-12-12 18:09 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Roaming\LibreOffice
2021-12-12 17:57 - 2022-02-15 19:53 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1052734516-3327908542-3545902175-1002
2021-12-12 17:52 - 2021-10-08 11:00 - 000160376 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudbus2.sys
2021-12-12 17:51 - 2021-12-12 17:51 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2021-12-09 12:16 - 2021-12-09 12:16 - 000000000 ____D C:\Users\cicer\AppData\Roaming\LibreOffice
2021-12-08 18:02 - 2021-12-08 18:08 - 1289073820 _____ C:\Users\cicer\Downloads\João Pessoa - PB 2021-001.zip
2021-12-08 17:58 - 2021-12-08 18:01 - 757829922 _____ C:\Users\cicer\Downloads\Santa Catarina - 2021-001.zip
2021-12-08 17:54 - 2022-02-02 11:41 - 000001907 _____ C:\Users\Dell\Desktop\Google Slides.lnk
2021-12-08 17:54 - 2022-02-02 11:41 - 000001907 _____ C:\Users\Dell\Desktop\Google Sheets.lnk
2021-12-08 17:54 - 2022-02-02 11:41 - 000001895 _____ C:\Users\Dell\Desktop\Google Docs.lnk
2021-12-08 17:54 - 2021-12-08 17:54 - 000000000 ____D C:\Users\cicer\AppData\Local\CEF
2021-12-08 17:47 - 2021-12-08 17:48 - 262132056 _____ (Google, Inc.) C:\Users\cicer\Downloads\GoogleDriveSetup.exe
2021-12-06 17:44 - 2021-12-06 17:44 - 000000000 ____D C:\Users\Dell\AppData\Roaming\LibreOffice
2021-12-06 17:38 - 2022-02-01 21:05 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2021-12-06 17:33 - 2022-01-12 11:21 - 000000000 ____D C:\ProgramData\HP
2021-12-05 21:20 - 2021-12-05 21:20 - 000747177 _____ C:\Users\cicer\Downloads\Direito das famílias - filiação.pdf
2021-12-03 15:45 - 2021-12-03 15:45 - 000142262 _____ C:\Users\cicer\Downloads\WhatsApp Image 2021-12-03 at 15.43.45.jpeg
2021-12-03 15:09 - 2021-12-03 15:09 - 000000000 ____D C:\Users\cicer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\apps do Chrome
2021-12-02 14:52 - 2021-12-02 14:52 - 000001207 _____ C:\Users\Public\Desktop\LibreOffice 7.2.lnk
2021-12-02 14:52 - 2021-12-02 14:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 7.2
2021-12-02 14:51 - 2021-12-02 14:52 - 000000000 ____D C:\Program Files\LibreOffice
2021-12-02 14:46 - 2021-12-02 14:48 - 339107840 _____ C:\Users\cicer\Downloads\LibreOffice_7.2.3_Win_x64.msi
2021-12-02 13:51 - 2021-12-02 13:51 - 000040332 _____ C:\Users\cicer\Downloads\Boleto de pagamento.pdf
2021-12-02 13:33 - 2022-02-21 20:01 - 000000000 ___RD C:\Users\Jacqueline Gerbase\OneDrive
2021-12-02 13:32 - 2022-01-12 14:33 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\PlaceholderTileLogoFolder
2021-12-02 13:32 - 2021-12-02 13:32 - 000001828 _____ C:\Users\Jacqueline Gerbase\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MaxxAudio Pro by Waves - Controle de Áudio de Alto-falante e Microfone e Som Nx 3D.lnk
2021-12-02 13:32 - 2021-12-02 13:32 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\Comms
2021-12-02 12:35 - 2021-12-02 12:35 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\LocalLow\IObit
2021-12-02 12:26 - 2022-02-15 20:03 - 000000000 ____D C:\Users\Jacqueline Gerbase
2021-12-02 12:26 - 2022-01-26 07:21 - 000000000 __SHD C:\Users\Jacqueline Gerbase\IntelGraphicsProfiles
2021-12-02 12:26 - 2022-01-22 08:25 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\D3DSCache
2021-12-02 12:26 - 2022-01-22 08:23 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\Google
2021-12-02 12:26 - 2022-01-22 08:22 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\ConnectedDevicesPlatform
2021-12-02 12:26 - 2022-01-12 11:22 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\Packages
2021-12-02 12:26 - 2021-12-02 13:34 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\Publishers
2021-12-02 12:26 - 2021-12-02 12:26 - 000000020 ___SH C:\Users\Jacqueline Gerbase\ntuser.ini
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Modelos
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Meus Documentos
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Menu Iniciar
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Documents\Minhas Músicas
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Documents\Minhas Imagens
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Documents\Meus Vídeos
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Dados de Aplicativos
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Configurações Locais
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\AppData\Local\Histórico
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\AppData\Local\Dados de Aplicativos
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Ambiente de Rede
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 _SHDL C:\Users\Jacqueline Gerbase\Ambiente de Impressão
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 ___RD C:\Users\Jacqueline Gerbase\3D Objects
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Roaming\IObit
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Roaming\Adobe
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\LocalLow\Intel
2021-12-02 12:26 - 2021-12-02 12:26 - 000000000 ____D C:\Users\Jacqueline Gerbase\AppData\Local\VirtualStore
2021-12-01 22:12 - 2021-12-27 21:49 - 000000000 ____D C:\Users\cicer\AppData\LocalLow\IObit
2021-12-01 22:09 - 2021-12-12 21:41 - 000000000 ___HD C:\OneDriveTemp
2021-12-01 22:08 - 2022-02-08 20:12 - 000000000 ___RD C:\Users\cicer\OneDrive
2021-12-01 22:08 - 2021-12-01 22:10 - 000000000 ____D C:\Users\cicer\AppData\Local\Comms
2021-12-01 22:07 - 2022-02-22 21:41 - 000000000 ____D C:\Users\cicer\AppData\Local\PlaceholderTileLogoFolder
2021-12-01 22:07 - 2021-12-01 22:07 - 000001828 _____ C:\Users\cicer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MaxxAudio Pro by Waves - Controle de Áudio de Alto-falante e Microfone e Som Nx 3D.lnk
2021-12-01 22:05 - 2022-02-23 14:35 - 000000000 ____D C:\Users\cicer\AppData\Local\D3DSCache
2021-12-01 22:05 - 2022-02-22 22:12 - 000000000 ____D C:\Users\cicer\AppData\Local\Packages
2021-12-01 22:05 - 2022-02-07 10:11 - 000000000 __SHD C:\Users\cicer\IntelGraphicsProfiles
2021-12-01 22:05 - 2022-01-12 11:15 - 000000000 ____D C:\Users\cicer\AppData\Local\Google
2021-12-01 22:05 - 2021-12-27 21:49 - 000000000 ____D C:\Users\cicer\AppData\Roaming\IObit
2021-12-01 22:05 - 2021-12-01 22:29 - 000000000 ____D C:\Users\cicer\AppData\Local\ConnectedDevicesPlatform
2021-12-01 22:05 - 2021-12-01 22:25 - 000000000 ____D C:\Users\cicer\AppData\Local\Publishers
2021-12-01 22:05 - 2021-12-01 22:05 - 000000000 ___RD C:\Users\cicer\3D Objects
2021-12-01 22:05 - 2021-12-01 22:05 - 000000000 ____D C:\Users\cicer\AppData\Roaming\Adobe
2021-12-01 22:05 - 2021-12-01 22:05 - 000000000 ____D C:\Users\cicer\AppData\LocalLow\Intel
2021-12-01 22:05 - 2021-12-01 22:05 - 000000000 ____D C:\Users\cicer\AppData\Local\VirtualStore
2021-12-01 22:04 - 2022-02-20 21:18 - 000000000 ____D C:\Users\cicer
2021-12-01 22:04 - 2021-12-01 22:04 - 000000020 ___SH C:\Users\cicer\ntuser.ini
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Modelos
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Meus Documentos
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Menu Iniciar
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Documents\Minhas Músicas
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Documents\Minhas Imagens
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Documents\Meus Vídeos
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Dados de Aplicativos
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Configurações Locais
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\AppData\Local\Histórico
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\AppData\Local\Dados de Aplicativos
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Ambiente de Rede
2021-12-01 22:04 - 2021-12-01 22:04 - 000000000 _SHDL C:\Users\cicer\Ambiente de Impressão
2021-12-01 17:18 - 2022-02-23 20:07 - 000037840 _____ (Topaz OFD) C:\Windows\system32\Drivers\wsddfac.sys
2021-12-01 17:18 - 2021-12-01 17:18 - 000000000 ___HD C:\Program Files (x86)\Topaz OFD
2021-12-01 17:18 - 2021-12-01 17:18 - 000000000 ____D C:\Program Files\Topaz OFD
2021-12-01 17:18 - 2021-02-11 19:37 - 000051160 _____ (Topaz OFD) C:\Windows\system32\Drivers\wsddntf.sys
2021-12-01 17:18 - 2021-02-11 19:37 - 000034768 ____N (Topaz OFD) C:\Windows\system32\Drivers\wsddpp.sys
2021-12-01 17:18 - 2021-02-11 19:37 - 000010722 _____ C:\Windows\system32\Drivers\wsddntf.cat
2021-12-01 17:18 - 2021-02-10 19:55 - 000033728 ____N (Topaz OFD) C:\Windows\system32\Drivers\wsddprm.sys
2021-12-01 17:17 - 2021-12-01 17:17 - 000000000 ____D C:\Users\Dell\Desktop\DIREITO - UNINASSAU 2019 - 2024
2021-12-01 17:14 - 2021-12-01 17:19 - 000000000 ____D C:\ProgramData\Temp
2021-12-01 17:14 - 2021-12-01 17:14 - 006104192 _____ (CAIXA) C:\Users\Dell\Downloads\GBPCEF.exe
2021-12-01 17:12 - 2021-12-01 17:16 - 911397887 _____ C:\Users\Dell\Downloads\DIREITO - UNINASSAU 2019 - 2024-20211201T200943Z-001.zip
2021-12-01 16:27 - 2021-12-01 16:27 - 000000000 ____D C:\ProgramData\{F86B0233-9A85-4589-8AAF-524CC4F8211B}
2021-12-01 16:26 - 2022-02-23 12:15 - 000000000 ____D C:\ProgramData\IObit
2021-12-01 16:26 - 2022-02-23 12:09 - 000000000 ____D C:\ProgramData\ProductData
2021-12-01 16:26 - 2021-12-01 16:54 - 000000000 ____D C:\Users\Dell\AppData\LocalLow\IObit
2021-12-01 16:26 - 2021-12-01 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare
2021-12-01 16:26 - 2021-12-01 16:26 - 000000000 ____D C:\Program Files (x86)\IObit
2021-12-01 16:25 - 2021-12-01 16:27 - 000000000 ____D C:\Users\Dell\AppData\Roaming\IObit
2021-12-01 16:24 - 2021-12-01 16:25 - 056193976 _____ (IObit ) C:\Users\Dell\Downloads\advanced-systemcare-setup.exe
2021-12-01 15:45 - 2021-12-01 15:45 - 001687040 _____ C:\Windows\system32\libcrypto.dll
2021-12-01 15:43 - 2021-12-01 15:43 - 002371072 _____ C:\Windows\system32\rdpnano.dll
2021-12-01 15:43 - 2021-12-01 15:43 - 000672768 _____ C:\Windows\system32\FsNVSDeviceSource.dll
2021-12-01 15:42 - 2021-12-01 15:42 - 002111488 _____ (Digimarc) C:\Windows\SysWOW64\DMRCDecoder.dll
2021-12-01 15:42 - 2021-12-01 15:42 - 001864192 _____ (The ICU Project) C:\Windows\SysWOW64\icu.dll
2021-12-01 15:42 - 2021-12-01 15:42 - 001333760 _____ C:\Windows\SysWOW64\TextInputMethodFormatter.dll
2021-12-01 15:42 - 2021-12-01 15:42 - 001164288 _____ C:\Windows\system32\MBR2GPT.EXE
2021-12-01 15:42 - 2021-12-01 15:42 - 000611960 _____ C:\Windows\SysWOW64\TextShaping.dll
2021-12-01 15:42 - 2021-12-01 15:42 - 000468440 _____ C:\Windows\SysWOW64\WindowManagementAPI.dll
2021-12-01 15:41 - 2021-12-01 15:41 - 000060928 _____ C:\Windows\system32\runexehelper.exe
2021-12-01 15:40 - 2021-12-01 15:40 - 002295296 _____ (Digimarc) C:\Windows\system32\DMRCDecoder.dll
2021-12-01 15:40 - 2021-12-01 15:40 - 002260992 _____ C:\Windows\system32\TextInputMethodFormatter.dll
2021-12-01 15:40 - 2021-12-01 15:40 - 002260480 _____ (The ICU Project) C:\Windows\system32\icu.dll
2021-12-01 15:40 - 2021-12-01 15:40 - 000706536 _____ C:\Windows\system32\TextShaping.dll
2021-12-01 15:40 - 2021-12-01 15:40 - 000657464 _____ C:\Windows\system32\WindowManagementAPI.dll
2021-12-01 15:40 - 2021-12-01 15:40 - 000287232 _____ C:\Windows\system32\CoreMas.dll
2021-12-01 15:40 - 2021-12-01 15:40 - 000098304 _____ C:\Windows\system32\Drivers\cimfs.sys
2021-12-01 15:40 - 2021-12-01 15:40 - 000013312 _____ C:\Windows\system32\agentactivationruntimestarter.exe
2021-12-01 15:23 - 2022-02-20 13:53 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-12-01 15:23 - 2021-12-01 15:23 - 000000000 ____D C:\Windows\Firmware
2021-12-01 15:10 - 2022-02-16 11:50 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-12-01 15:10 - 2022-02-16 11:50 - 000002204 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-12-01 15:09 - 2021-12-08 17:53 - 000000000 ____D C:\Program Files\Google
2021-12-01 15:08 - 2022-02-01 21:00 - 000000000 ____D C:\ProgramData\Package Cache
2021-12-01 15:08 - 2022-01-20 21:15 - 000003590 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-12-01 15:08 - 2022-01-20 21:15 - 000003466 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2021-12-01 15:06 - 2022-02-23 20:20 - 000000000 ____D C:\Program Files (x86)\Google
2021-12-01 15:05 - 2021-12-08 17:54 - 000000000 ____D C:\Users\Dell\AppData\Local\Google
2021-12-01 15:04 - 2021-12-01 15:04 - 001341272 _____ (Google LLC) C:\Users\Dell\Downloads\ChromeSetup.exe
2021-12-01 15:04 - 2021-12-01 15:04 - 001341272 _____ (Google LLC) C:\Users\Dell\Downloads\ChromeSetup (1).exe

==================== Três meses (modificados) ==================

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2022-02-23 20:22 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-02-23 20:06 - 2021-06-04 11:56 - 000008192 ___SH C:\DumpStack.log.tmp
2022-02-23 20:06 - 2021-06-04 11:56 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-02-23 20:06 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\ServiceState
2022-02-23 20:05 - 2019-12-07 06:03 - 001310720 _____ C:\Windows\system32\config\BBI
2022-02-23 19:49 - 2021-06-04 11:56 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-02-23 16:39 - 2019-12-07 06:13 - 000000000 ____D C:\Windows\INF
2022-02-23 16:14 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\AppReadiness
2022-02-23 15:54 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-02-23 12:14 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\security
2022-02-23 12:08 - 2021-06-04 11:56 - 000457864 _____ C:\Windows\system32\FNTCACHE.DAT
2022-02-22 22:16 - 2019-12-07 06:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2022-02-20 13:33 - 2021-06-04 11:58 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-02-20 13:33 - 2021-06-04 11:58 - 000002276 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-02-17 15:58 - 2021-06-04 12:08 - 001651882 _____ C:\Windows\system32\PerfStringBackup.INI
2022-02-17 15:58 - 2019-12-07 11:54 - 000717080 _____ C:\Windows\system32\prfh0416.dat
2022-02-17 15:58 - 2019-12-07 11:54 - 000141220 _____ C:\Windows\system32\prfc0416.dat
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SystemResources
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\et-EE
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\es-MX
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\Dism
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\appraiser
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\ShellExperiences
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2022-02-17 15:48 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\bcastdvr
2022-02-17 15:48 - 2019-12-07 06:03 - 000000000 ____D C:\Windows\servicing
2022-02-16 12:26 - 2019-12-07 06:03 - 000000000 ____D C:\Windows\CbsTemp
2022-02-11 13:39 - 2021-06-04 11:59 - 002877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2022-02-10 14:36 - 2021-06-04 11:57 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-02-09 12:37 - 2021-11-19 08:41 - 000000000 ____D C:\Windows\system32\MRT
2022-02-09 12:27 - 2021-11-19 08:40 - 149611728 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-02-08 20:15 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\NDF
2022-02-08 01:11 - 2021-11-18 17:35 - 000000000 ____D C:\Users\Dell\AppData\Local\D3DSCache
2022-02-08 00:19 - 2021-06-04 12:12 - 000000000 ____D C:\ProgramData\Packages
2022-02-02 11:33 - 2021-11-18 16:46 - 000000000 ____D C:\Intel
2022-02-01 21:03 - 2021-11-18 17:23 - 000000000 ____D C:\ProgramData\Intel Package Cache {29d6077f-6adb-42de-abac-1c60aeb0e237}
2022-02-01 21:03 - 2021-11-18 17:23 - 000000000 ____D C:\ProgramData\Intel Package Cache {1CEAC85D-2590-4760-800F-8DE5E91F3700}
2022-02-01 21:02 - 2021-11-18 17:23 - 000000000 ____D C:\ProgramData\Intel Package Cache {d8170687-85fa-4716-bafd-087205d0db72}
2022-02-01 21:02 - 2021-11-18 17:23 - 000000000 ____D C:\ProgramData\Intel Package Cache {9f9c9e51-d42f-4462-a27a-7d419da18045}
2022-01-26 07:19 - 2021-06-04 11:57 - 000003618 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-01-26 07:19 - 2021-06-04 11:57 - 000003494 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore

==================== SigCheck ============================

(Não há correção automática para arquivos que não passaram na verificação.)

==================== Fim de FRST.txt ========================


"Log Addition"

Resultado da análise adicional Farbar Recovery Scan Tool (x64) Versão: 14-02-2022 01
Executado por Dell (23-02-2022 20:44:05)
Executando a partir de C:\Users\Dell\Downloads
Microsoft Windows 10 Home Single Language Versão 21H1 19043.1526 (X64) (2021-06-04 15:03:59)
Modo da Inicialização: Normal
==========================================================


==================== Contas: =============================


(Se uma entrada for incluída na fixlist, será removida.)

Administrador (S-1-5-21-1052734516-3327908542-3545902175-500 - Administrator - Disabled)
cicer (S-1-5-21-1052734516-3327908542-3545902175-1003 - Limited - Enabled) => C:\Users\cicer
Convidado (S-1-5-21-1052734516-3327908542-3545902175-501 - Limited - Disabled)
DefaultAccount (S-1-5-21-1052734516-3327908542-3545902175-503 - Limited - Disabled)
Dell (S-1-5-21-1052734516-3327908542-3545902175-1001 - Administrator - Enabled) => C:\Users\Dell
Jacqueline Gerbase (S-1-5-21-1052734516-3327908542-3545902175-1002 - Limited - Enabled) => C:\Users\Jacqueline Gerbase
WDAGUtilityAccount (S-1-5-21-1052734516-3327908542-3545902175-504 - Limited - Disabled)

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AV: Avira Antivirus (Enabled - Up to date) {8A154ED8-4428-DB2D-0E3F-BD82C448FD94}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

Advanced SystemCare (HKLM-x32\...\Advanced SystemCare_is1) (Version: 15.0.1 - IObit)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.2201.2134 - Avira Operations GmbH & Co. KG) Hidden
Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.38.1.15219 - Avira Operations GmbH & Co. KG) Hidden
Avira Security (HKLM-x32\...\Avira Security_is1) (Version: 1.1.62.26939 - Avira Operations GmbH & Co. KG) Hidden
Avira Security (HKLM-x32\...\AviraSecurityUninstaller) (Version: - Avira Operations GmbH & Co. KG)
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 6.16.0.11273 - Avira Operations GmbH & Co. KG) Hidden
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{08E7C8D5-F2B5-4F09-B0EA-F28913BEFDB0}) (Version: 5.5.1.16143 - Dell Inc.) Hidden
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{2a8bafd6-22ae-4d0e-87a4-686b2a4a2ab0}) (Version: 5.5.1.16143 - Dell Inc.)
Dell Update (HKLM-x32\...\{944FB5B0-9588-45FD-ABE8-73FC879801ED}) (Version: 4.3.0 - Dell Inc.)
Dynamic Application Loader Host Interface Service (HKLM\...\{0AFA46DB-6E86-479E-BF66-B25C29324A5F}) (Version: 1.0.0.0 - Intel Corporation) Hidden
GCAP 2021 - Ganhos de Capital 2021 (HKLM-x32\...\GCAP2021) (Version: 1.3 - Receita Federal do Brasil)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 98.0.4758.102 - Google LLC)
Intel(R) HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 2.2.1.375 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2141.15.0.2511 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{bbc40478-54e7-4914-965f-de8043a2ed0e}) (Version: 22.100.0.3 - Intel Corporation) Hidden
IRPF2021 (HKLM-x32\...\IRPF2021) (Version: 1.9 - Receita Federal do Brasil)
Java 8 Update 321 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180321F0}) (Version: 8.0.3210.7 - Oracle Corporation)
LibreOffice 7.2.3.2 (HKLM\...\{81490660-3C36-47B4-AE9F-73B6C5BD4F98}) (Version: 7.2.3.2 - The Document Foundation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 98.0.1108.56 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 98.0.1108.56 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1052734516-3327908542-3545902175-1002\...\OneDriveSetup.exe) (Version: 22.012.0117.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{16E50919-B07A-4B4E-994A-476D4773F5BF}) (Version: 3.65.0.0 - Microsoft Corporation)
OptaneDowngradeGuard (HKLM\...\{86B0E6C1-32E0-42CC-BC4F-BF3C0730CECB}) (Version: 18.0.0.0 - Intel Corporation) Hidden
Revo Uninstaller 2.3.8 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.3.8 - VS Revo Group, Ltd.)
RstDowngradeGuard (HKLM\...\{13C2A26E-7AD4-4D82-BB4F-DEA6E871B958}) (Version: 18.0.0.0 - Intel Corporation) Hidden
Verificação de integridade do PC Windows (HKLM\...\{BDA76587-4949-46D7-8427-AE49451F93D4}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Warsaw 2.26.0.20 64 bits (HKLM\...\{20E60725-16C8-4FB9-8BC2-AF92C5F8D06D}_is1) (Version: 2.26.0.20 - Topaz)
Zoom (HKU\S-1-5-21-1052734516-3327908542-3545902175-1003\...\ZoomUMX) (Version: 5.9.3 (3169) - Zoom Video Communications, Inc.)

Packages:
=========
Centro de comando de gráficos Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3407.0_x64__8j3eq9eme6ctt [2021-12-15] (INTEL CORP) [Startup Task]
Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.23.4.0_x64__6rarf9sa4v8jt [2022-02-08] (Disney)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_134.1.221.0_x64__v10z8vjag6ke6 [2022-02-08] (HP Inc.)
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1024.0_x64__8j3eq9eme6ctt [2022-02-23] (INTEL CORP)
Lexmark Printer Home -> C:\Program Files\WindowsApps\58539F3C.LexmarkPrinterHome_3.0.73.0_neutral__xyj5e99tmxdva [2021-12-02] (Lexmark International, Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-12-02] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-12-02] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.2180.0_x64__8wekyb3d8bbwe [2022-02-23] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0 [2022-02-23] (Spotify AB) [Startup Task]
Waves MaxxAudio Pro for Dell 2019 -> C:\Program Files\WindowsApps\WavesAudio.MaxxAudioProforDell2019_2.0.54.0_x64__fh4rh281wavaa [2021-12-02] (Waves Audio)

==================== Análise Personalizada CLSID (Whitelisted): ==============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

CustomCLSID: HKU\S-1-5-21-1052734516-3327908542-3545902175-1001_Classes\CLSID\{0BAD39CB-DD3E-4F21-9156-649B0156C28E}\localserver32 -> C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_9384fc4d30af89c3\WavesSvc64.exe (Waves Inc -> Waves Audio Ltd.)
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\Windows\System32\DriverStore\FileRepository\iastorpinningcomponent.inf_amd64_b31ddd6f2a24807e\OptaneShellExt.dll [2021-02-09] (Intel(R) Rapid Storage Technology -> )
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2021-07-31] (IObit CO., LTD -> IObit)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2021-04-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {14cb2bd0-2375-3d10-9b5d-5e18865c8959} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2021-12-23] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2021-07-31] (IObit CO., LTD -> IObit)
ContextMenuHandlers3: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2021-07-31] (IObit CO., LTD -> IObit)
ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\Windows\System32\DriverStore\FileRepository\iastorpinningcomponent.inf_amd64_b31ddd6f2a24807e\OptaneShellExt.dll [2021-02-09] (Intel(R) Rapid Storage Technology -> )
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2021-07-31] (IObit CO., LTD -> IObit)
ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {700866bb-c8e9-3e71-b359-abb28baed0e8} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2021-12-23] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {0cab5786-30e8-3185-9b3b-ccefbf1b8afe} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2021-12-23] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2021-04-27] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)

==================== Codecs (Whitelisted) ====================

==================== Atalhos & WMI ========================

==================== Módulos Carregados (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

(Se uma entrada for incluída na fixlist, somente o ADS será removido.)

AlternateDataStreams: C:\ProgramData:chnpbmzkyg [274]
AlternateDataStreams: C:\ProgramData:YXVtLmh6aQ [16786]
AlternateDataStreams: C:\Windows\system32\Drivers\wsddfac.sys:X5ZN8aGXs4 [2142]
AlternateDataStreams: C:\Users\All Users:chnpbmzkyg [274]
AlternateDataStreams: C:\Users\All Users:YXVtLmh6aQ [16786]
AlternateDataStreams: C:\Users\Todos os Usuários:chnpbmzkyg [274]
AlternateDataStreams: C:\Users\Todos os Usuários:YXVtLmh6aQ [16786]
AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:chnpbmzkyg [274]
AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:YXVtLmh6aQ [16786]

==================== Modo de Segurança (Whitelisted) ==================

==================== Associação (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_321\bin\ssv.dll [2022-01-22] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_321\bin\jp2ssv.dll [2022-01-22] (Oracle America, Inc. -> Oracle Corporation)

==================== Hosts Conteúdo: =========================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2019-12-07 06:14 - 2019-12-07 06:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Outras Áreas ===========================

(Atualmente não há nenhuma correção automática para esta seção.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1052734516-3327908542-3545902175-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1052734516-3327908542-3545902175-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1052734516-3327908542-3545902175-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\cicer\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img2.jpg
DNS Servers: 181.213.132.2 - 181.213.132.3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Firewall do Windows está habilitado.

Network Binding:
=============
Ethernet: Topaz OFD Network Monitor -> nt_wsddntf (enabled)
Wi-Fi: Topaz OFD Network Monitor -> nt_wsddntf (enabled)

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==

(Se uma entrada for incluída na fixlist, será removida.)

MSCONFIG\Services: AdvancedSystemCareService15 => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: cplspcon => 2
MSCONFIG\Services: esifsvc => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HPPrintScanDoctorService => 2
MSCONFIG\Services: iaStorAfsService => 3
MSCONFIG\Services: igccservice => 2
MSCONFIG\Services: igfxCUIService2.0.0.0 => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: Intel(R) TPM Provisioning Service => 2
MSCONFIG\Services: IntelAudioService => 2
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: RstMwService => 2
MSCONFIG\Services: RtkAudioUniversalService => 2
MSCONFIG\Services: WavesSysSvc => 2
MSCONFIG\Services: WMIRegistrationService => 2
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1052734516-3327908542-3545902175-1001\...\StartupApproved\Run: => "Advanced SystemCare"
HKU\S-1-5-21-1052734516-3327908542-3545902175-1001\...\StartupApproved\Run: => "GoogleDriveFS"

==================== Regras do Firewall (Whitelisted) ================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [{BAE5D10D-7B96-4E1F-BFF9-CFE49EB64E11}] => (Allow) C:\Program Files\Topaz OFD\Warsaw\core.exe (TPZ SOLUCOES DIGITAIS LTDA -> Topaz OFD)
FirewallRules: [{05215913-FC7A-403F-BE8A-E9B317D03298}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{5EF23E52-8A83-4CD6-8848-5D925157AF6F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{4FB0E47B-E875-469B-B325-86FE8EE96C5D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{C2F6A3B1-CBDE-484D-B653-41D8ABD58B4D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{4F3C1A23-632C-4CA0-A1D1-5F1B7337BD04}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{CAF667BA-ED6A-4A8E-9578-016A64509225}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{BB3C3E38-1767-4084-B885-82EC1278FA3D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8D6F95AF-E679-4A9D-B47B-558828B418E7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.178.765.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{C5025422-8B1C-4658-8E0B-AF0F42B78512}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{A9E27797-8046-4EEB-9842-AEC9AACF1A08}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{4B95EA7E-BA42-470D-BD97-6D5CEDD7DAB8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C127C55D-9C53-4E34-B574-426545B5CDAD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{4639C24F-F526-427E-9417-8D26A1965F5E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{10F6A119-BD97-4059-9EE1-00399BE5F1D1}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\98.0.1108.56\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D16EFB64-E780-4C45-9A93-F517397519CD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B37A52BE-5DF8-413E-BA9E-B781EBAC9306}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{03BE95F0-46D4-42CC-B60A-CB06AB46800F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FB4505ED-7959-4014-9B9C-A24290DFE1D6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{41F036B7-AD7F-4216-A20C-CEF416F03C12}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{0A278042-E112-48CE-95AD-75B2DF677EA2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{11F3B76C-3D50-4F10-BDAE-60AABC2DB533}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A9CFEBC4-0537-441E-AD7B-E4A2A233EDBA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.179.763.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)

==================== Pontos de Restauração =========================


==================== Dispositivos Apresentando Falhas No Gerenciador ============


==================== Erros no Log de eventos: ========================

Erros em Aplicativos:
==================
Error: (02/22/2022 11:10:49 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: O programa Skype.exe versão 8.79.0.95 parou de interagir com o Windows e foi fechado. Para ver se mais informações sobre o problema estão disponíveis, verifique o histórico de problemas no painel de controle Segurança e Manutenção.

ID do Processo: 4bc

Hora de Início: 01d824e6da7e5fcc

Hora de Término: 4294967295

Caminho do Aplicativo: C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe

ID do Relatório: 3d382ad3-02fe-46d1-9f00-dc535c0613d4

Nome completo do pacote com falha: Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c

ID do aplicativo relativo ao pacote com falha: App

Tipo com falha: Quiesce

Error: (02/22/2022 10:19:48 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: AUTORIDADE NT)
Description: O Windows não pode carregar a DLL de contador extensível "C:\Windows\system32\sysmain.dll" (código de erro do Win32 126).

Error: (02/22/2022 10:14:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome do aplicativo com falha: VpnInstaller.exe, versão: 2.38.1.15219, carimbo de data/hora: 0x5df6d4e3
Nome do módulo com falha: nsisXML.dll, versão: 0.0.0.0, carimbo de data/hora: 0x502443ee
Código de exceção: 0xc0000005
Deslocamento da falha: 0x0000326f
ID do processo com falha: 0x2614
Hora de início do aplicativo com falha: 0x01d82852ad695f21
Caminho do aplicativo com falha: C:\Users\Dell\AppData\Local\Temp\.CR.27964\7b92024f-415d-4271-a963-4ceeb61f98b7\VpnInstaller.exe
Caminho do módulo com falha: C:\Users\Dell\AppData\Local\Temp\.CR.27964\7b92024f-415d-4271-a963-4ceeb61f98b7\nsistemp\nsr8320.tmp\nsisXML.dll
ID do Relatório: 554073c1-df99-457d-aad5-a18b65fba74d
Nome completo do pacote com falha:
ID do aplicativo relativo ao pacote com falha:

Error: (02/08/2022 12:25:43 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao chamar a rotina CoCreateInstance. hr = 0x8007045b, O sistema está sendo desligado.
.

Error: (02/08/2022 12:25:43 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informações sobre o Serviço de Cópias de Sombra de Volume: não é possível iniciar o Servidor COM com CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} e nome CEventSystem. [0x8007045b, O sistema está sendo desligado.
]

Error: (02/08/2022 12:23:13 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao chamar a rotina QueryFullProcessImageNameW. hr = 0x80070006, Identificador inválido.
.


Operação:
Executando Operação Assíncrona

Contexto:
Estado Atual: DoSnapshotSet

Error: (02/08/2022 12:22:17 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Erro do Serviço de Cópias de Sombra de Volume: erro inesperado ao consultar a interface IVssWriterCallback. hr = 0x80070005, Acesso negado.
.
Muitas vezes, isso é causado por configurações de segurança incorretas no processo gravador ou solicitante.


Operação:
Obtendo Dados do Gravador

Contexto:
Id de Classe de Gravador: {e8132975-6f93-4464-a53e-1050253ae220}
Nome do Gravador: System Writer
ID de Instância de Gravador: {59dfb5eb-7dd9-45c2-a6e5-34f9c7862a8c}

Error: (02/08/2022 11:51:09 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Erro do serviço de cópias de sombra de volume: erro inesperado ao chamar a rotina QueryFullProcessImageNameW. hr = 0x80070006, Identificador inválido.
.


Operação:
Executando Operação Assíncrona

Contexto:
Estado Atual: DoSnapshotSet


Erros de Sistema:
=============
Error: (02/23/2022 08:10:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço Dell Client Management Service devido ao seguinte erro:
O serviço não respondeu à requisição de início ou controle em tempo hábil.

Error: (02/23/2022 08:10:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço Dell Client Management Service.

Error: (02/23/2022 08:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Não foi possível iniciar o serviço AviraSecurity devido ao seguinte erro:
O serviço não respondeu à requisição de início ou controle em tempo hábil.

Error: (02/23/2022 08:07:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Tempo limite esgotado (45000 milissegundos) ao aguardar a conexão do serviço AviraSecurity.

Error: (02/23/2022 08:07:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Tempo limite esgotado (45000 milissegundos) ao aguardar a conexão do serviço AviraPhantomVPN.

Error: (02/23/2022 08:05:24 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: O serviço Avira Agendamento terminou com o seguinte erro específico de serviço:
Função incorreta.

Error: (02/23/2022 08:04:44 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-S32LBR1)
Description: O servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} não se registrou no DCOM dentro do tempo limite necessário.

Error: (02/23/2022 08:04:43 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-S32LBR1)
Description: O servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} não se registrou no DCOM dentro do tempo limite necessário.


Windows Defender:
================
Date: 2022-02-22 21:38:38
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {101090F7-568E-4E52-A5FD-4DC81336D991}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Completa
Usuário: DESKTOP-S32LBR1\cicer

Date: 2022-02-20 13:23:04
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {264A1A05-B07D-4390-9DAF-B645BF5B0EC0}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2022-02-11 15:49:26
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {C5972339-40D8-4B5F-8C16-EAFE2F183012}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2022-02-11 14:42:33
Description:
O exame do Microsoft Defender Antivírus foi interrompido antes da conclusão.
ID do Exame: {E7484908-3F54-4FAA-87C1-75C34D756DBF}
Tipo de Exame: Antimalware
Parâmetros do Exame: Verificação Rápida
Usuário: AUTORIDADE NT\SISTEMA

Date: 2022-02-08 11:41:12
Description:
Microsoft Defender Antivírus detectou malware ou outro software potencialmente indesejado.
Para obter mais informações, veja a seguir:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/Sepdot&threatid=312018&enterprise=0
Nome: PUADlManager:Win32/Sepdot
Gravidade: Baixo
Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Dell\Downloads\Baixaki_Revo Uninstaller_v1.696.037.72.3.exe; webfile:_C:\Users\Dell\Downloads\Baixaki_Revo Uninstaller_v1.696.037.72.3.exe|https://d1pgogkl0rslyx.cloudfront.net/v/br/v7.143.84.882.5|pid:7384,ProcessStart:132888048540276676
Origem da Detecção: Internet
Tipo da Detecção: Concreto
Fonte da Detecção: Downloads e anexos
Usuário: DESKTOP-S32LBR1\Dell
Nome do Processo: C:\Program Files\Google\Chrome\Application\chrome.exe
Versão da Inteligência de Segurança: AV: 1.357.303.0, AS: 1.357.303.0, NIS: 1.357.303.0
Versão do Mecanismo: AM: 1.1.18900.2, NIS: 1.1.18900.2
Event[0]:

Date: 2022-02-08 20:15:54
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.357.303.0
Fonte da Atualização: Servidor do Microsoft Update
Tipo da Inteligência de Segurança: Antivírus
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SISTEMA
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.18900.2
Código de Erro: 0x80240438
Descrição do Erro: Erro inesperado ao verificar atualizações. Para obter informações sobre como instalar ou solucionar problemas de atualizações, consulte Ajuda e Suporte.

Date: 2021-12-28 21:30:04
Description:
O recurso de Proteção em Tempo Real do Microsoft Defender Antivírus encontrou um erro e falhou.
Recurso: Em Tempo de Acesso
Código do Erro: 0x80004005
Descrição do erro: Erro não especificado
Motivo: O driver de filtro ignorou o exame de itens e está no modo de passagem. Isso pode ter acontecido por causa de condições de poucos recursos.

Date: 2021-11-18 17:15:58
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.353.1219.0
Fonte da Atualização: Centro de Proteção contra Malware da Microsoft
Tipo da Inteligência de Segurança: Antivírus
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SERVIÇO DE REDE
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.18700.4
Código de Erro: 0x8050a003
Descrição do Erro: Este pacote não contém arquivos de definição atualizados para este programa. Para obter mais informações, consulte o Centro de Ajuda e Suporte.

Date: 2021-11-18 17:15:58
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.353.1219.0
Fonte da Atualização: Centro de Proteção contra Malware da Microsoft
Tipo da Inteligência de Segurança: Anti-spyware
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SERVIÇO DE REDE
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.18700.4
Código de Erro: 0x8050a003
Descrição do Erro: Este pacote não contém arquivos de definição atualizados para este programa. Para obter mais informações, consulte o Centro de Ajuda e Suporte.

Date: 2021-11-18 17:15:58
Description:
Microsoft Defender Antivírus encontrou um erro ao tentar atualizar a inteligência de segurança.
Nova Versão da Inteligência de Segurança:
Versão da Inteligência de Segurança anterior: 1.353.1219.0
Fonte da Atualização: Centro de Proteção contra Malware da Microsoft
Tipo da Inteligência de Segurança: Antivírus
Tipo da atualização: Completa
Usuário: AUTORIDADE NT\SERVIÇO DE REDE
Versão Atual do Mecanismo:
Versão Anterior do Mecanismo: 1.1.18700.4
Código de Erro: 0x8050a003
Descrição do Erro: Este pacote não contém arquivos de definição atualizados para este programa. Para obter mais informações, consulte o Centro de Ajuda e Suporte.

CodeIntegrity:
===============
Date: 2022-02-23 20:28:09
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\msedge.exe) attempted to load \Device\HarddiskVolume3\Program Files\Topaz OFD\Warsaw\wslbdhm64.dll that did not meet the Microsoft signing level requirements.

Date: 2022-02-23 19:50:11
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Topaz OFD\Warsaw\wslbscrwh64.dll that did not meet the Microsoft signing level requirements.

Date: 2022-02-23 19:50:11
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Topaz OFD\Warsaw\wslbscr64.dll that did not meet the Microsoft signing level requirements.

Date: 2022-02-23 19:49:51
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Topaz OFD\Warsaw\wslbscrwh64.dll that did not meet the Microsoft signing level requirements.


==================== Informações da Memória ===========================

BIOS: Dell Inc. 1.17.0 12/06/2021
placa-mãe: Dell Inc. 0T0MC0
Processador: Intel(R) Core(TM) i5-8265U CPU @ 1.60GHz
Percentagem de memória em uso: 69%
RAM física total: 8067.91 MB
RAM física disponível: 2484.89 MB
Virtual Total: 12419.91 MB
Virtual disponível: 5906.42 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.89 GB) (Free:849.46 GB) NTFS

\\?\Volume{ddf207b0-c81c-4791-967c-c60dceefc199}\ () (Fixed) (Total:0.51 GB) (Free:0.07 GB) NTFS
\\?\Volume{25d9dfac-38f2-4f0c-b149-a891c836ccdd}\ () (Fixed) (Total:0.09 GB) (Free:0.05 GB) FAT32

==================== MBR & Tabela de Partições ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Fim de Addition.txt =======================
Inspiron 3583 W10 Home Single Language - 64 bits / Intel(R) Core(TM) i5-8265U CPU @ 1.60GHz 1.80 GHz / HDD 1TB / 8GB / Claro Net 50 Mbps / Roteador Humax HGB10R - 02
PH
PH Cyber Highlander Registrado
61.3K Mensagens 10.7K Curtidas
#5 Por PH
24/02/2022 - 11:53
Bom dia!

Obrigado pelos logs.

O primeiro eu desinstalaria, pois esse tipo de programa, bagunça mais o Windows que ajusta, não precisa dele de forma alguma! O segunda está como uma tarefa agendada, precisa verificar se realmente da Dell, se for não tem com que se preocupar.

Anexo do post



Categoria: Software Potencialmente Indesejado
Caminho: file:_C:\Users\Dell\Downloads\Baixaki_Revo Uninstaller_v1.696.037.72.3.exe; webfile:_C:\Users\Dell\Downloads\Baixaki_Revo Uninstaller_v1.696.037.72.3.exe


Essa citação acima, deve está alertando devido ao instalador do Baixaki, aconselho sempre baixar um programa do site oficial, nunca de portais de downloads, até pela questão desses downloads personalizados e de estar sempre na última versão. O site para baixar seria Baixar o Revo Uninstaller Freeware - Download gratuito e completo. Na dúvida pergunta aqui.

Quando tiver dúvida sobre um arquivo, pode fazer o upload dele para o site VirusTotal - Home.

Anexos

Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
piresjam
piresjam Veterano Registrado
798 Mensagens 49 Curtidas
#6 Por piresjam
24/02/2022 - 15:48
Boa tarde, amigos!!

Enrique - RJ, realizei a limpeza do cachê do navegador e da lixeira. Além de desinstalar o Advanced, mas o problema dos avisos continua. Estaca 0.

PH disse:
Bom dia!

Obrigado pelos logs.

O primeiro eu desinstalaria, pois esse tipo de programa, bagunça mais o Windows que ajusta, não precisa dele de forma alguma! O segunda está como uma tarefa agendada, precisa verificar se realmente da Dell, se for não tem com que se preocupar.

Anexo do post

Boa tarde, PH!! Muito obob



Essa citação acima, deve está alertando devido ao instalador do Baixaki, aconselho sempre baixar um programa do site oficial, nunca de portais de downloads, até pela questão desses downloads personalizados e de estar sempre na última versão. O site para baixar seria Baixar o Revo Uninstaller Freeware - Download gratuito e completo. Na dúvida pergunta aqui.

Quando tiver dúvida sobre um arquivo, pode fazer o upload dele para o site VirusTotal - Home.


Olá, PH, boa tarde! Primeiramente, muito obrigado pela colaboração de vocês !

O problema dessas notificações de vírus começou depois que fui inventar de converter um vídeo do youtube em formato mp3 por meio de um site de conversão, embora nunca tivesse tido problema algum com o Advanced System Care e com o Revo até realizar essa "conversão do vídeo". Mas, de qualquer forma, certamente seguirei a recomendação:

1º Já desinstalei o Advanced System Care

2º Desinstalei o programa Revo e deletei o instalador

3º Verifiquei a pasta Windows 32 (vide imagem: Tasks.jpeg em anexo)e não vejo mais esse "Tasks\ASC_SkipUac_Dell..."

4º Ao desativar as notificações, cessam os alertas de vírus. Contudo, ao reativá-la, os alertas retornam (vide imagem: Alerta de vírus.jpeg em anexo) Ou seja, o problema ainda continua. E agora ??

Anexo do post Anexo do post

Anexos

Inspiron 3583 W10 Home Single Language - 64 bits / Intel(R) Core(TM) i5-8265U CPU @ 1.60GHz 1.80 GHz / HDD 1TB / 8GB / Claro Net 50 Mbps / Roteador Humax HGB10R - 02
PH
PH Cyber Highlander Registrado
61.3K Mensagens 10.7K Curtidas
#7 Por PH
24/02/2022 - 16:21
Boa tarde!

O Revo não precisava desinstalar, o aviso foi só para usar o site do fabricante, e não usar um portal de download.
Esse antivírus da McAfee pode desinstalar. Aconselho usar no lugar do Avira o Kaspersky Security Cloud – Free. Baixa ele, faz uma nova varredura e veja se ele encontra algo e se tem algum alerta, nos informa.
Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
piresjam
piresjam Veterano Registrado
798 Mensagens 49 Curtidas
#8 Por piresjam
25/02/2022 - 00:42


PH disse:
Boa tarde!

O Revo não precisava desinstalar, o aviso foi só para usar o site do fabricante, e não usar um portal de download.
Esse antivírus da McAfee pode desinstalar. Aconselho usar no lugar do Avira o Kaspersky Security Cloud – Free. Baixa ele, faz uma nova varredura e veja se ele encontra algo e se tem algum alerta, nos informa.


"Log Karpersky"

Ontem, 24/02/2022 21:25:34 C:\Users\cicer\Documents\Minhas Imagens Não processado Objeto não processado Acesso negado Arquivo C:\Users\cicer\Documents\Minhas Imagens

Não processado DESKTOP-S32LBR1\DellUsuário ativo

Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1694].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1694].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1697].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1697].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1700].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1700].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1713].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1713].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1702].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1702].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1718].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1718].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:24 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1719].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[1719].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[29].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[29].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[37].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[37].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[31].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[31].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[41].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[41].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[43].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[43].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[45].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[45].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[51].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[51].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:27 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[522].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[522].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:28 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[523].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[523].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:28 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[57].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[57].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 21:22:28 C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[63].pdf\data0000 Protegido por senha Arquivo compactado protegido por senha detectado Arquivo C:\Users\cicer\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\3\Attachments\Fatura Net[63].pdf// data0000 Protegido por senha DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 23:48:16 Tarefa concluída Tarefa concluída DESKTOP-S32LBR1\Dell Usuário ativo
Ontem, 24/02/2022 20:36:54 Tarefa iniciada Tarefa iniciada DESKTOP-S32LBR1\Dell Usuário ativo



O log saiu com formatação estranha. cap_triste.png Tirei também um print da tela (em anexo) do antivirus mostrando o resultado.

Anexos

Inspiron 3583 W10 Home Single Language - 64 bits / Intel(R) Core(TM) i5-8265U CPU @ 1.60GHz 1.80 GHz / HDD 1TB / 8GB / Claro Net 50 Mbps / Roteador Humax HGB10R - 02
PH
PH Cyber Highlander Registrado
61.3K Mensagens 10.7K Curtidas
#9 Por PH
25/02/2022 - 09:18
Bom dia!

Obrigado pelo print e pelo log!

Nem precisava, apenas se tivesse encontrado alguma praga. No log, informa que esse PDF é protegido por senha, nada mais foi encontrado. Na imagem que mandou, informa o evento realizado, essa área do Kaspersky é uma auditoria bem completa. Basta clicar em cada item e ver algum alerta.

Anexo do post

Anexos

Mas aquele que me negar diante dos homens, eu também o negarei diante do meu Pai que está nos céus.

Mateus 10:33
piresjam
piresjam Veterano Registrado
798 Mensagens 49 Curtidas
#10 Por piresjam
25/02/2022 - 11:58
PH disse:
Bom dia!

Obrigado pelo print e pelo log!

Nem precisava, apenas se tivesse encontrado alguma praga. No log, informa que esse PDF é protegido por senha, nada mais foi encontrado. Na imagem que mandou, informa o evento realizado, essa área do Kaspersky é uma auditoria bem completa. Basta clicar em cada item e ver algum alerta.

Anexo do post


Estava aparecendo novamente os alertas, apesar de tudo isso que nós já fizemos. Dei uma vasculhada nas configurações do Chrome >> Segurança e privacidade, na parte de "permitir o envio de notificações" (vide print Screen em anexo) onde fica uma lista de sites, removi o relacionado ao McAfee. Pronto, o alerta sumiu na hora da minha tela. De qualquer maneira, todas as orientações passadas foram cruciais para a minha segurança, além de todos os cuidados que até então eram desconhecidos por mim. Muito abrigado!!!

Anexos

Inspiron 3583 W10 Home Single Language - 64 bits / Intel(R) Core(TM) i5-8265U CPU @ 1.60GHz 1.80 GHz / HDD 1TB / 8GB / Claro Net 50 Mbps / Roteador Humax HGB10R - 02
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal