Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 20.06.2018 Executado por rocha (14-07-2018 14:58:24) Executando a partir de C:\Users\rocha\Desktop Windows 10 Pro Versão 1803 17134.165 (X64) (2018-05-19 21:47:33) Modo da Inicialização: Normal ========================================================== ==================== Contas: ============================= Administrador (S-1-5-21-1828573999-3214088840-2664683546-500 - Administrator - Disabled) catir (S-1-5-21-1828573999-3214088840-2664683546-1003 - Limited - Disabled) chefm (S-1-5-21-1828573999-3214088840-2664683546-1002 - Limited - Disabled) Convidado (S-1-5-21-1828573999-3214088840-2664683546-501 - Limited - Disabled) DefaultAccount (S-1-5-21-1828573999-3214088840-2664683546-503 - Limited - Disabled) jucam (S-1-5-21-1828573999-3214088840-2664683546-1004 - Limited - Disabled) => C:\Users\jucam rocha (S-1-5-21-1828573999-3214088840-2664683546-1001 - Administrator - Enabled) => C:\Users\rocha WDAGUtilityAccount (S-1-5-21-1828573999-3214088840-2664683546-504 - Limited - Disabled) ==================== Central de Segurança ======================== (Se uma entrada for incluída na fixlist, será removida.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programas Instalados ====================== (Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.) µTorrent (HKU\S-1-5-21-1828573999-3214088840-2664683546-1001\...\uTorrent) (Version: 3.5.3.44494 - BitTorrent Inc.) Aplicativo Itaú (HKLM-x32\...\{32B2853B-43F6-4CEC-91D0-D41C83EEAE98}) (Version: 1.0.105 - Banco Itaú) Apple Mobile Device Support (HKLM\...\{C29B636B-9015-4ED1-A12F-6375A337F23B}) (Version: 11.4.1.46 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) Assassin's Creed 1 (HKLM-x32\...\Uplay Install 82) (Version: - Ubisoft) Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft) Atualizações da NVIDIA 31.1.10.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.1.10.0 - NVIDIA Corporation) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.42 - Piriform) CPUID CPU-Z 1.82.1 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.82.1 - ) <==== ATENÇÃO DBeaver Community 5.0.5 (HKLM-x32\...\DBeaver) (Version: 5.0.5 - Rider Soft LTD) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 390.77 - NVIDIA Corporation) Hidden Git version 2.16.2 (HKLM\...\Git_is1) (Version: 2.16.2 - The Git Development Community) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden iCloud (HKLM\...\{82FCC407-A0E5-4B80-9241-5ABA78B61090}) (Version: 7.6.0.15 - Apple Inc.) Intel Extreme Tuning Utility (HKLM-x32\...\{2b6ed4de-d92a-4e61-aa4f-5196a0ecee21}) (Version: 6.3.0.56 - Intel Corporation) Intel Extreme Tuning Utility (HKLM-x32\...\{AD9EAA1C-2EF5-4243-ACE5-7AB77047291D}) (Version: 6.3.0.56 - Intel Corporation) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4836 - Intel Corporation) iTunes (HKLM\...\{63895904-5266-45D1-A3C5-F61A3BAFA224}) (Version: 12.8.0.150 - Apple Inc.) Malwarebytes versão 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Microsoft Office 365 - pt-br (HKLM\...\O365HomePremRetail - pt-br) (Version: 16.0.10228.20080 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1828573999-3214088840-2664683546-1001\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) MSI Afterburner 4.4.2 (HKLM-x32\...\Afterburner) (Version: 4.4.2 - MSI Co., LTD) Node.js (HKLM\...\{F69C1A4C-0402-462C-B95D-6BEAED881FA1}) (Version: 8.11.1 - Node.js Foundation) NVIDIA Driver de controle do 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA Driver de gráficos 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 390.77 - NVIDIA Corporation) NVIDIA Driver do 3D Vision 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 390.77 - NVIDIA Corporation) NVIDIA GeForce Experience 3.13.1.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.13.1.30 - NVIDIA Corporation) NVIDIA Software do sistema PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) NVM for Windows 1.1.6 (HKLM\...\40078385-F676-4C61-9A9C-F9028599D6D3_is1) (Version: 1.1.6 - Ecor Ventures LLC) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0416-0000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden OpenOffice 4.1.5 (HKLM-x32\...\{F139E0D0-7B4E-41AB-B47D-D456032057C3}) (Version: 4.15.9789 - Apache Software Foundation) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Painel de controle da NVIDIA 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 390.77 - NVIDIA Corporation) Hidden Priston Tale Brasil (HKLM-x32\...\Priston Tale Brasil ) (Version: - ) RivaTuner Statistics Server 7.0.2 (HKLM-x32\...\RTSS) (Version: 7.0.2 - Unwinder) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Sublime Text Build 3143 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) Suporte para Aplicativos Apple (32-bit) (HKLM-x32\...\{E5347310-C82F-4833-AA36-8D11E5A8A86A}) (Version: 6.6 - Apple Inc.) Suporte para Aplicativos Apple Apple (64-bit) (HKLM\...\{D745E014-74DD-43A3-98DF-E7D38164B681}) (Version: 6.6 - Apple Inc.) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.6 - TeamSpeak Systems GmbH) Uplay (HKLM-x32\...\Uplay) (Version: 46.0 - Ubisoft) Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) ==================== Exame Personalizado CLSID (Whitelisted): ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2018-06-26] (Apple Inc.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> Nenhum Arquivo ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-01-23] (NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ==================== Tarefas Agendadas (Whitelisted) ============= (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {088441A9-CA84-46BB-921D-7B837D98462A} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation) Task: {0B51C5F1-5CCA-4300-8FD3-1C346D151E13} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-12] (Google Inc.) Task: {0C22E9CE-FA33-4426-882A-4D5F0B81D863} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation) Task: {112C3CD7-6B1C-46AE-9857-57F288488FAB} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-03-14] (NVIDIA Corporation) Task: {11CD07CE-29C7-4830-A885-AD97D859A8D0} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2017-12-15] () Task: {1B6D59E0-50C1-4C6E-8A68-71B8470D0118} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-20] (Microsoft Corporation) Task: {269601A4-3F61-479B-803F-4E3370A1E7D5} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation) Task: {2B48E6D9-7F22-42DA-96C1-97A0DC425DA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-12] (Google Inc.) Task: {2C473CF3-36BF-4916-9065-D25F5476519D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation) Task: {3453A629-3362-485B-83C5-4ACC54C4F8BC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation) Task: {50AC9166-E6E6-4268-A443-0C8E40147BF2} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-06] (Microsoft Corporation) Task: {5269327B-4C6E-4F46-A3EF-76AB54958E08} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-03-14] (NVIDIA Corporation) Task: {552084F5-6A17-44E8-A4B0-1B819E8C0F93} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-03-14] (NVIDIA Corporation) Task: {583C88C6-E007-444A-9DED-39B4C75BD90A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] () Task: {679AA5A5-53E0-4E44-B499-E94C353F4BA7} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation) Task: {904AAFD8-2E0E-4A60-B7E1-E9CC5589123A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-06] (Microsoft Corporation) Task: {9858965C-BF4E-4E1D-94D6-1DBF19EFD14C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-03-14] (NVIDIA Corporation) Task: {99611A8A-AE24-46BE-9AFA-56D8189796A4} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.) Task: {A3EA6CC8-5140-4306-9B7A-F17A44545F64} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation) Task: {BAAEF2E4-BE78-4AEC-8B11-E9531451014E} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-20] (Microsoft Corporation) Task: {BC8816AC-AB82-4D55-B21C-CEDF6B07F7C7} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-07-06] (Microsoft Corporation) Task: {CB6465DC-304B-4ADF-B283-8B20E661EF77} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-04-12] (Piriform Ltd) Task: {DAF4CE84-BD70-4B84-BBC4-3D0FEAFB19DF} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-07-06] (Microsoft Corporation) Task: {F63EAB4F-A393-4B00-967F-0BB6861CA620} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-04-12] (Piriform Ltd) Task: {F8DDB4AE-ECA1-4364-BC18-7428B89CE99C} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) ==================== Atalhos & WMI ======================== (As entradas podem ser listadas para serem restauradas ou removidas.) ShortcutWithArgument: C:\Users\rocha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativos do Google Chrome\Postman.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fhbjgbiflinjbdggehcddcbncdddomop ==================== Módulos Carregados (Whitelisted) ============== 2018-01-27 11:26 - 2018-01-23 21:23 - 000544240 _____ () C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\DisplayDriverAnalyzer\_DisplayDriverCrashAnalyzer64.dll 2017-11-30 17:54 - 2017-11-30 17:54 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2018-06-23 06:56 - 2018-06-23 06:56 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2018-07-13 07:37 - 2018-06-18 13:32 - 002433744 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-07-13 07:37 - 2018-07-03 12:59 - 002535120 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-12-15 19:31 - 2018-01-23 19:57 - 000133704 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2018-04-11 20:34 - 2018-04-11 20:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll 2018-04-11 20:34 - 2018-04-11 20:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-11 20:34 - 2018-04-11 20:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-07-10 20:10 - 2018-07-06 03:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-05-22 08:03 - 2018-05-22 08:03 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-05-22 08:03 - 2018-05-22 08:03 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-05-22 08:03 - 2018-05-22 08:03 - 022374400 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-05-22 08:03 - 2018-05-22 08:03 - 002610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\skypert.dll 2018-05-22 08:03 - 2018-05-22 08:03 - 000654848 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-07-06 02:00 - 2018-07-06 02:00 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll 2018-07-06 02:00 - 2018-07-06 02:00 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll 2018-03-24 12:56 - 2018-03-20 03:00 - 004435288 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libglesv2.dll 2018-03-24 12:56 - 2018-03-20 03:00 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll 2018-06-08 09:40 - 2018-06-08 09:41 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2018-06-08 09:40 - 2018-06-08 09:41 - 067232256 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2017-10-01 16:02 - 2017-10-01 16:02 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 004214784 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll 2018-04-26 21:33 - 2018-04-26 21:34 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll 2018-03-30 07:28 - 2018-03-30 07:29 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll 2018-06-08 09:40 - 2018-06-08 09:41 - 014851072 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 004058624 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2018-06-08 09:40 - 2018-06-08 09:40 - 003266048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 001393664 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 004218080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-05-28 19:56 - 2018-05-28 19:56 - 000872448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll 2018-06-08 09:40 - 2018-06-08 09:41 - 000165376 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\SKU.dll 2017-08-13 17:33 - 2018-06-08 18:38 - 000788256 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2017-08-13 17:33 - 2018-06-08 20:39 - 002632992 _____ () C:\Program Files (x86)\Steam\video.dll 2017-08-13 17:33 - 2018-06-08 18:42 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll 2017-12-15 19:25 - 2018-06-08 18:40 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll 2017-12-15 19:25 - 2018-06-08 18:40 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll 2017-12-15 19:25 - 2018-06-08 18:40 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll 2017-12-15 19:25 - 2018-06-08 18:40 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll 2017-08-13 17:33 - 2018-06-08 18:40 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2017-08-13 17:33 - 2018-06-08 18:40 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2017-12-15 19:25 - 2018-06-08 18:40 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll 2017-08-13 17:33 - 2018-06-08 20:38 - 000979744 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2017-08-13 17:33 - 2018-06-08 18:40 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2018-06-23 06:56 - 2018-06-23 06:56 - 001042232 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2017-11-30 17:55 - 2017-11-30 17:55 - 000076088 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2018-06-23 06:56 - 2018-06-23 06:56 - 000189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2017-08-13 17:34 - 2018-06-08 18:39 - 000788256 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll 2017-08-13 17:34 - 2018-06-08 18:39 - 083524384 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll 2017-08-13 17:33 - 2018-06-08 18:42 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll 2017-08-13 17:34 - 2018-06-08 18:39 - 002253600 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\swiftshader\libglesv2.dll 2017-08-13 17:34 - 2018-06-08 18:39 - 000109856 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\swiftshader\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (Se uma entrada for incluída na fixlist, somente o ADS será removido.) AlternateDataStreams: C:\Users\rocha\OneDrive\Documentos\Modelos Personalizados do Office:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] ==================== Modo de Segurança (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Associação (Whitelisted) =============== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.) ==================== Internet Explorer confiável/restrito =============== (Se uma entrada for incluída na fixlist, será removida do Registro.) ==================== Hosts Conteúdo: =============================== (Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.) 2017-03-18 18:03 - 2017-03-18 18:01 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Outras Áreas ============================ (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-1828573999-3214088840-2664683546-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\rocha\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 192.168.15.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Firewall do Windows está habilitado. ==================== MSCONFIG/TASK MANAGER ítens desabilitados == MSCONFIG\Services: Apple Mobile Device Service => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: cplspcon => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: igfxCUIService2.0.0.0 => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: NvContainerLocalSystem => 2 MSCONFIG\Services: NvContainerNetworkService => 3 MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2 MSCONFIG\Services: NvTelemetryContainer => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: XTU3SERVICE => 2 ==================== Regras do Firewall (Whitelisted) =============== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) FirewallRules: [{CF4CA03B-1A21-445F-A429-F9EC78409DB8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6C9BF5D1-329C-47D6-9DFA-958649083292}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{DE00BC98-8C58-4585-8FEA-72DFBCFE21B8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{E5941300-D29D-425C-9EB1-CCC32760493E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{DC0F2C3B-3482-4A1C-A185-E7135CF992C9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{113AFCEB-8154-49C5-B8A9-A4243D3568E4}] => (Allow) C:\Users\rocha\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{636A1FA8-757E-4BF7-9A2B-C32CBA8442B8}] => (Allow) C:\Users\rocha\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B7E8CF59-C72B-41E2-8579-2007780EA69C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [UDP Query User{12227AA8-FF41-4B07-91D2-05DC4A9DB226}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe FirewallRules: [TCP Query User{256D251C-C34C-4DD7-BADD-B2522183F737}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe FirewallRules: [{82035E7C-54AE-4BA8-A45A-C55490021150}] => (Allow) D:\jogos\Watch_Dogs\bin\watch_dogs.exe FirewallRules: [{748AF7B9-F573-4606-94E3-463AE59038A4}] => (Allow) D:\jogos\Watch_Dogs\bin\watch_dogs.exe FirewallRules: [{60468292-D379-4ED2-86C4-DD27AA9FB41D}] => (Allow) D:\jogos\steamapps\common\A Lenda do Herói - O Jogo\DumaLegend.exe FirewallRules: [{DAD95392-937E-4D25-BB59-0DF312E0AAA6}] => (Allow) D:\jogos\steamapps\common\A Lenda do Herói - O Jogo\DumaLegend.exe FirewallRules: [{12D1B32A-79C0-4A02-ABB0-DC1839B449DA}] => (Allow) D:\jogos\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{867EED3A-973D-4129-8221-C28E65FC032A}] => (Allow) D:\jogos\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{B8253469-B887-429B-937F-E2D1861745EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{BD4E4D88-4A03-422A-B440-C204A5F12C22}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{D0949F24-D404-44EB-AE2D-CEEC4F2DACA5}] => (Allow) D:\jogos\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{B7D3A623-85CD-4978-A1F8-A38B5610B8BC}] => (Allow) D:\jogos\Assassin's Creed IV Black Flag\AC4BFMP.exe FirewallRules: [{5D7CD2AA-C328-4B7B-A8F7-5969FF73D9B8}] => (Allow) D:\jogos\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [{C0E47C94-80F7-4045-A7F9-64BC81FA0E06}] => (Allow) D:\jogos\Assassin's Creed IV Black Flag\AC4BFSP.exe FirewallRules: [UDP Query User{D14E535D-82B3-447C-AF05-9516B55C16DE}D:\jogos\overwatch\overwatch.exe] => (Allow) D:\jogos\overwatch\overwatch.exe FirewallRules: [TCP Query User{58883A50-1E68-4821-870A-5FBC101B3C46}D:\jogos\overwatch\overwatch.exe] => (Allow) D:\jogos\overwatch\overwatch.exe FirewallRules: [{5C233773-D768-4A06-A4D3-D78CF90CCBB3}] => (Allow) D:\jogos\Assassin's Creed 1\AssassinsCreed_Dx10.exe FirewallRules: [{DDD0D442-A31F-43F5-9D7C-67713A834F65}] => (Allow) D:\jogos\Assassin's Creed 1\AssassinsCreed_Dx10.exe FirewallRules: [{D45C06C0-EC04-47D8-825F-2E7783AA04F4}] => (Allow) D:\jogos\Assassin's Creed 1\AssassinsCreed_Dx9.exe FirewallRules: [{D641D638-2858-49D7-A2CC-C047D58C6215}] => (Allow) D:\jogos\Assassin's Creed 1\AssassinsCreed_Dx9.exe FirewallRules: [{A8AF62B3-523C-497F-BDBF-9BDC3E36FD15}] => (Allow) D:\jogos\Assassin's Creed 1\AssassinsCreed_Game.exe FirewallRules: [{DE6A8036-FCD9-4FA7-B0CC-40D3E7F936AC}] => (Allow) D:\jogos\Assassin's Creed 1\AssassinsCreed_Game.exe FirewallRules: [{61E9ABC6-EAC6-43A3-945E-6BCE5536359F}] => (Allow) D:\jogos\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{500F3956-AE49-4974-A453-5E90AD34F57C}] => (Allow) D:\jogos\steamapps\common\Tomb Raider\TombRaider.exe FirewallRules: [{56CAB0AF-AF34-456E-B690-E498C4C0D4B4}] => (Allow) D:\jogos\steamapps\common\Rise of the Tomb Raider\ROTTR.exe FirewallRules: [{4833C8D5-5A4B-43E1-A639-D873F49D45B9}] => (Allow) D:\jogos\steamapps\common\Rise of the Tomb Raider\ROTTR.exe FirewallRules: [{1D4D3660-4067-4BAD-AE00-A3FC9D0732FF}] => (Allow) D:\jogos\steamapps\common\Cuphead\Cuphead.exe FirewallRules: [{9BA9DF90-281F-4111-9147-E5D06C121BFA}] => (Allow) D:\jogos\steamapps\common\Cuphead\Cuphead.exe FirewallRules: [{2C414FA4-BFC3-4AE8-AEE1-0F13BD180E74}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe FirewallRules: [TCP Query User{4CD90B25-69BC-4E95-893D-A85F108F5BC0}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{28D7FFD1-E077-4014-BC7D-F1A8E48840EB}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [{15D58A61-6DA4-4A60-B8C1-AB01E7B8BB75}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{B4DF0EB5-67C0-4F9B-8A76-71035DBA48F6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{CBD8192F-2255-42C8-A4B7-AF91D4A405F8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{DC232AF9-7BC6-437E-B154-D30932C427CA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{2A2487F5-B6CC-4F7E-B186-9E8758D79585}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe FirewallRules: [UDP Query User{DF50F28D-609D-4C62-8233-F5AB8821192B}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe FirewallRules: [TCP Query User{5F69BFBA-4339-4A4C-BD9C-CC59599FC06C}C:\program files\dbeaver\dbeaver.exe] => (Allow) C:\program files\dbeaver\dbeaver.exe FirewallRules: [UDP Query User{8BDBA838-E3C9-428E-B277-670BACA5C493}C:\program files\dbeaver\dbeaver.exe] => (Allow) C:\program files\dbeaver\dbeaver.exe FirewallRules: [{7F1DC6E8-AE60-4468-A6DC-11914D5A8E4E}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Pontos de Restauração ========================= ATENÇÃO: A Restauração do Sistema está desabilitada ==================== Dispositivos Apresentando Falhas No Gerenciador ============= ==================== Erros no Log de eventos: ========================= Erros em Aplicativos: ================== Error: (07/14/2018 07:43:00 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Falha na Ativação de Licença (slui.exe). Código de erro: hr=0xC004C003 Argumento de linha de comando: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable Error: (07/14/2018 07:43:00 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: Falha na aquisição da Licença de Usuário Final. hr=0xC004C003 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (07/14/2018 07:43:00 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Detalhes da falha na aquisição de licença. hr=0xC004C003 Error: (07/14/2018 07:42:58 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: Falha na aquisição da Licença de Usuário Final. hr=0xC004C003 Sku Id=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (07/14/2018 07:42:58 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Detalhes da falha na aquisição de licença. hr=0xC004C003 Error: (07/14/2018 07:42:57 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Falha na Ativação de Licença (slui.exe). Código de erro: hr=0xC004E028 Argumento de linha de comando: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=3 Error: (07/13/2018 08:04:24 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 Error: (07/13/2018 08:01:43 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Falha na Ativação de Licença (slui.exe). Código de erro: hr=0xC004C003 Argumento de linha de comando: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable Erros de Sistema: ============= Error: (07/14/2018 11:23:38 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-KKCS1F5) Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820} e APPID {8BC3F05E-D86B-11D0-A075-00C04FB68820} ao usuário DESKTOP-KKCS1F5\rocha SID (S-1-5-21-1828573999-3214088840-2664683546-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes. Error: (07/14/2018 07:43:27 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-KKCS1F5) Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} e APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} ao usuário DESKTOP-KKCS1F5\rocha SID (S-1-5-21-1828573999-3214088840-2664683546-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes. Error: (07/14/2018 07:43:17 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-KKCS1F5) Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} e APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} ao usuário DESKTOP-KKCS1F5\rocha SID (S-1-5-21-1828573999-3214088840-2664683546-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes. Error: (07/14/2018 07:43:17 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-KKCS1F5) Description: O servidor {D63B10C5-BB46-4990-A94F-E40B9D520160} não se registrou no DCOM dentro do tempo limite necessário. Error: (07/13/2018 09:54:43 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-KKCS1F5) Description: O servidor Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy!App.AppX9s1cz53zc86xn39kwrb02jyft9ecn62r.mca não se registrou no DCOM dentro do tempo limite necessário. Error: (07/13/2018 08:03:26 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-KKCS1F5) Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820} e APPID {8BC3F05E-D86B-11D0-A075-00C04FB68820} ao usuário DESKTOP-KKCS1F5\rocha SID (S-1-5-21-1828573999-3214088840-2664683546-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes. Error: (07/13/2018 08:02:08 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-KKCS1F5) Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} e APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} ao usuário DESKTOP-KKCS1F5\rocha SID (S-1-5-21-1828573999-3214088840-2664683546-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Não Disponível SID (Não Disponível). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes. Error: (07/13/2018 08:01:55 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-KKCS1F5) Description: As configurações de permissão específico do aplicativo não concedem permissão Local Ativação para o aplicativo de Servidor COM com CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820} e APPID {8BC3F05E-D86B-11D0-A075-00C04FB68820} ao usuário DESKTOP-KKCS1F5\rocha SID (S-1-5-21-1828573999-3214088840-2664683546-1001) do endereço LocalHost (Usando LRPC) que está sendo executado no contêiner de aplicativos Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Essa permissão de segurança pode ser modificada com a ferramenta administrativa Serviços de Componentes. Windows Defender: =================================== Date: 2018-07-12 21:29:47.474 Description: O Windows Defender Antivirus detectou um comportamento suspeito. Nome: Behavior:Win32/ModifiedBootRecord ID: 3783054940 Severidade: Baixo Categoria: Comportamento Suspeito Caminho Encontrado: file:_C:\Users\rocha\AppData\Local\Temp\bootsect.exe;process:_12100 Origem da Detecção: Computador local Tipo de Detecção: Suspeito Origem da Detecção: Proteção em Tempo Real Status: Executando Usuário: DESKTOP-KKCS1F5\rocha Nome do Processo: C:\Users\rocha\AppData\Local\Temp\bootsect.exe ID da Assinatura: 23858570787236 Versão da Assinatura: AV: 1.271.903.0, AS: 1.271.903.0 Versão do Mecanismo: 1.1.15000.2 Rótulo de Fidelidade: Médio Nome do Arquivo de Destino: Date: 2018-05-21 08:48:57.231 Description: O exame do Windows Defender Antivirus foi interrompido antes da conclusão. ID do Exame: {4349A6EC-DDF0-4AC5-ABA4-860BAC8DD1BC} Tipo de Exame: Antimalware Parâmetros do Exame: Verificação Rápida Usuário: AUTORIDADE NT\SISTEMA Date: 2018-05-21 08:29:28.482 Description: O exame do Windows Defender Antivirus foi interrompido antes da conclusão. ID do Exame: {FC575B53-7001-48DF-A3B7-82E0EE4C702C} Tipo de Exame: Antimalware Parâmetros do Exame: Verificação Rápida Usuário: AUTORIDADE NT\SISTEMA Date: 2018-05-22 21:13:39.152 Description: O Windows Defender Antivirus encontrou um erro ao tentar carregar assinaturas e tentará reverter para um conjunto conhecido de assinaturas válidas. Tentativas de Assinaturas: Atual Código do Erro: 0x80070002 Descrição do erro: O sistema não pode encontrar o arquivo especificado. Versão da assinatura: 0.0.0.0;0.0.0.0 Versão do mecanismo: 0.0.0.0 Date: 2018-05-21 08:14:23.655 Description: O Windows Defender Antivirus encontrou um erro ao atualizar assinaturas. Versão da Nova Assinatura: Versão da Assinatura Anterior: 1.267.1736.0 Origem da Atualização: Servidor do Microsoft Update Tipo de Assinatura: Antivírus Tipo de Atualização: Completa Usuário: AUTORIDADE NT\SISTEMA Versão do Mecanismo Atual: Versão do Mecanismo Anterior: 1.1.14800.3 Código de erro: 0x80070643 Descrição do erro: Erro fatal durante a instalação. CodeIntegrity: =================================== Date: 2018-07-13 07:37:45.865 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2018-07-13 07:18:20.481 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. Date: 2018-07-13 07:01:06.489 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftPdfReader.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. Date: 2018-07-13 07:00:41.956 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftPdfReader.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. Date: 2018-07-13 06:57:19.050 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftPdfReader.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. Date: 2018-07-13 06:56:22.938 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftPdfReader.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. Date: 2018-07-13 06:53:57.220 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftPdfReader.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. Date: 2018-07-13 06:48:23.625 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftPdfReader.exe) attempted to load \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Store signing level requirements. ==================== Informações da Memória =========================== Processador: Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz Percentagem de memória em uso: 21% RAM física total: 16314.62 MB RAM física disponível: 12734.55 MB Virtual Total: 18746.62 MB Virtual disponível: 13891.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.24 GB) (Free:56.04 GB) NTFS Drive d: (Novo volume) (Fixed) (Total:223.45 GB) (Free:91.38 GB) NTFS \\?\Volume{4ea0691a-4a74-423c-bfd3-cc153c518f3d}\ (Recuperação) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS \\?\Volume{1c55a171-6eb4-4f4f-b348-108fd2736aa2}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Tabela de Partições ================== ======================================================== Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000) Partition: GPT. ==================== Fim de Addition.txt ============================