Resultado do análise da Farbar Recovery Scan Tool (FRST) (x64) Versão: 13-03-2022 Executado por DVM (administrador) em DESKTOP-GQD1R8Q (LENOVO 81FD) (18-03-2022 07:55:57) Executando a partir de C:\Users\DVM\Desktop Perfis Carregados: DVM Plataforma: Microsoft Windows 10 Home Single Language Versão 20H2 19042.1586 (X64) Idioma: Português (Brasil) Navegador padrão: Edge Modo da Inicialização: Normal ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe ->) (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe (C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCopyAccelerator.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe ->) (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (DriverStore\FileRepository\cui_dch.inf_amd64_0d8dab4470c5524b\igfxCUIService.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0d8dab4470c5524b\igfxEM.exe (explorer.exe ->) (Adobe Inc. -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <9> (Google LLC -> Google LLC) C:\Users\DVM\AppData\Local\Temp\Rar$EXa3376.26262\Chrome-bin\chrome.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Windows\System32\dolbyaposvc\DAX3API.exe <2> (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_7c484f80872e1cd8\jhi_service.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0d8dab4470c5524b\igfxCUIService.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a9a2dde7124f013f\OneApp.IGCC.WinService.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_8f079a8a5c196b5d\IntelCpHDCPSvc.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_8f079a8a5c196b5d\IntelCpHeciSvc.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2> (services.exe ->) (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe (services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2202.10603.0_x64__8wekyb3d8bbwe\Cortana.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe ==================== Registro (Whitelisted) =================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [865568 2019-03-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645648 2019-10-05] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Run: [MicrosoftEdgeAutoLaunch_5460CE3DAE9ADC376A8F34F0B63AF70F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Run: [ut] => C:\Users\DVM\AppData\Roaming\uTorrent\uTorrent.exe [2103848 2022-02-19] (BitTorrent Inc -> BitTorrent Inc.) HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Run: [Google Update] => C:\Users\DVM\AppData\Local\Google\Update\1.3.36.122\GoogleUpdateCore.exe [223816 2022-03-16] (Google LLC -> Google LLC) HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Policies\Explorer: [NoResolveSearch] 1 HKU\S-1-5-21-3349755285-804529065-3594935135-1001\...\Policies\Explorer: [NoInternetOpenWith] 1 HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [65496 2020-10-22] (Adobe Inc. -> Adobe Systems Inc) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\99.0.4844.51\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel=stable HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{AC76BA86-0000-0000-7760-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat DC\Esl\Aiod.dll [2020-10-22] (Adobe Inc. -> Adobe Systems, Inc.) ==================== Tarefas Agendadas (Whitelisted) ============ (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {10A5F58D-3412-4879-A7BE-DDCB8DA9A09E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1438BA42-EC6C-4DD1-B226-2350F563AB73} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c (Nenhum Arquivo) Task: {203C5D70-3EF2-4344-9245-0B4183A7D393} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23549376 2020-08-28] (Microsoft Corporation -> Microsoft Corporation) Task: {39408801-8733-4D67-8B2C-5471CF815EC5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {44339E44-2A73-4560-A92C-EECB807E6D97} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2208208 2020-09-10] (Microsoft Corporation -> Microsoft Corporation) Task: {5C779D1E-C91D-4F50-A849-CC7F58BAA135} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3349755285-804529065-3594935135-1001Core{E3A78061-0DF5-4683-9BA6-E1B86B479BAF} => C:\Users\DVM\AppData\Local\Google\Update\GoogleUpdate.exe [156232 2022-03-16] (Google LLC -> Google LLC) Task: {6DDAE02F-4141-455C-8EA5-C620DC1126EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {79BAC13A-935E-4439-9E2E-E4E43923FD17} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {8615B089-EB76-4B2F-A278-3A46E3A86698} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (Nenhum Arquivo) Task: {864DBBC2-13AC-4FE3-81B1-1134BC4E473E} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {A02A8805-73D3-4CF0-BB21-FAC0124F5879} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2208208 2020-09-10] (Microsoft Corporation -> Microsoft Corporation) Task: {AA5193AC-1392-45CB-9483-96DACABFB866} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler => C:\Program Files\RUXIM\PLUGscheduler.exe [369512 2022-01-12] (Microsoft Windows -> Microsoft Corporation) Task: {BED82B41-DD91-44AE-8DB6-96C0ABCF2B84} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23549376 2020-08-28] (Microsoft Corporation -> Microsoft Corporation) Task: {CD18F9DE-823C-4465-A0F8-7F46BD050444} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3349755285-804529065-3594935135-1001UA{99A67289-CDAE-4B0B-965E-4FCE96259038} => C:\Users\DVM\AppData\Local\Google\Update\GoogleUpdate.exe [156232 2022-03-16] (Google LLC -> Google LLC) Task: {D9E1D2D0-A0D3-41E1-81D3-DE6154508071} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3509664 2020-09-10] (Microsoft Corporation -> Microsoft Corporation) Task: {F46E6F0A-D40D-403F-B401-5DD08215B8F0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCmdRun.exe [979568 2022-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F9838B85-F8AF-4F7E-B88D-EC9E257330A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [3509664 2020-09-10] (Microsoft Corporation -> Microsoft Corporation) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt Tcpip\Parameters: [DhcpNameServer] 181.213.132.2 181.213.132.3 Tcpip\..\Interfaces\{011b7d19-35ed-42d2-9bda-dbe3de1d735b}: [DhcpNameServer] 181.213.132.2 181.213.132.3 Tcpip\..\Interfaces\{1b36df7f-9a64-4a65-81d8-74018e0235cd}: [DhcpNameServer] 181.213.132.2 181.213.132.3 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\DVM\AppData\Local\Microsoft\Edge\User Data\Default [2022-03-18] Edge Notifications: Default -> hxxps://conta.olx.com.br; hxxps://www.meliuz.com.br Edge Extension: (Cuponomia - Cupom e Cashback) - C:\Users\DVM\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bpgniflghkfilpfdacibcpggobmldnlf [2022-03-17] Edge Extension: (Méliuz: Cashback e cupons em suas compras) - C:\Users\DVM\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jdcfmebflppkljibgpdlboifpcaalolg [2022-02-24] Edge Extension: (uBlock Origin) - C:\Users\DVM\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2022-03-03] FireFox: ======== FF DefaultProfile: 36ayqepd.default FF ProfilePath: C:\Users\DVM\AppData\Roaming\Mozilla\Firefox\Profiles\36ayqepd.default [2022-02-05] FF ProfilePath: C:\Users\DVM\AppData\Roaming\Mozilla\Firefox\Profiles\wv0uq6t4.default-release [2022-03-18] FF Extension: (Méliuz: Cashback e cupons em suas compras) - C:\Users\DVM\AppData\Roaming\Mozilla\Firefox\Profiles\wv0uq6t4.default-release\Extensions\jid1-NI2sWc3cvsAJsg@jetpack.xpi [2022-03-17] FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2020-10-22] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2020-09-10] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2020-09-10] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-09-10] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\PROGRAMAS\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-09-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\PROGRAMAS\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-09-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> D:\PROGRAMAS\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-09-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> D:\PROGRAMAS\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-09-23] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-09-10] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-10-22] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default [2022-03-18] CHR Notifications: Default -> hxxps://conta.olx.com.br; hxxps://drogaraia.soclminer.com.br; hxxps://meet.google.com; hxxps://pt.aliexpress.com; hxxps://push-decdbeb-5268.boustahe.com; hxxps://web.telegram.org; hxxps://web.whatsapp.com; hxxps://wp.aliexpress.com; hxxps://www.conselhosetruques.com; hxxps://www.cuponomia.com.br; hxxps://www.softonic.com.br CHR HomePage: Default -> hxxp://www.google.com/ CHR Extension: (Google Tradutor) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2022-03-09] CHR Extension: (Apresentações) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-09-10] CHR Extension: (Documentos) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-09-10] CHR Extension: (Google Drive) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-09] CHR Extension: (YouTube) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-09-10] CHR Extension: (Adobe Acrobat: ferramentas de edição, conversão e assinatura de PDFs) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-02-24] CHR Extension: (WA Web Plus for WhatsApp™) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekcgkejcjdcmonfpmnljobemcbpnkamh [2022-03-15] CHR Extension: (Planilhas) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-09-10] CHR Extension: (EditThisCookie) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2020-12-08] CHR Extension: (Documentos Google off-line) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-03-15] CHR Extension: (Cuponomia - Cupom e Cashback) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\gidejehfgombmkfflghejpncblgfkagj [2022-03-09] CHR Extension: (New Tab Redirect) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna [2020-09-11] CHR Extension: (Méliuz: Cashback e cupons em suas compras) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdcfmebflppkljibgpdlboifpcaalolg [2022-02-23] CHR Extension: (Social Video Downloader) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnnoammpigcglgbhcbbdpnekbcddahe [2021-02-17] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-09] CHR Extension: (Gmail) - C:\Users\DVM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-09] CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] ==================== Serviços (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Systems, Incorporated) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9482688 2020-08-28] (Microsoft Corporation -> Microsoft Corporation) R2 DolbyDAXAPI; C:\Windows\system32\dolbyaposvc\DAX3API.exe [1926600 2019-09-02] (Dolby Laboratories, Inc. -> ) R2 FMAPOService; C:\Windows\System32\FMService64.exe [394176 2019-07-08] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [260256 2022-01-29] (HP Inc. -> HP Inc.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13172752 2020-01-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2021-07-08] (Reason Software Company Inc. -> Reason Software Company Inc.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\NisSrv.exe [3046608 2022-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MsMpEng.exe [132504 2022-03-14] (Microsoft Windows Publisher -> Microsoft Corporation) S3 GoogleChromeElevationService; "C:\Program Files (x86)\Google\Chrome\Application\99.0.4844.51\elevation_service.exe" [X] S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] ===================== Drivers (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2021-09-15] (Microsoft Corporation) [Arquivo não assinado] S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 MpKslbb07ca86; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6510E1B1-3ECF-481E-ADF9-1DE8F4AEE14C}\MpKslDrv.sys [137464 2022-03-18] (Microsoft Windows -> Microsoft Corporation) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49600 2022-03-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [439544 2022-03-14] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [90360 2022-03-14] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um mês (criados) (Whitelisted) ========= (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2022-03-18 07:55 - 2022-03-18 07:58 - 000026911 _____ C:\Users\DVM\Desktop\FRST.txt 2022-03-18 07:52 - 2022-03-18 07:57 - 000000000 ____D C:\FRST 2022-03-18 07:47 - 2022-03-18 07:50 - 002364928 _____ (Farbar) C:\Users\DVM\Desktop\FRST64.exe 2022-03-16 14:20 - 2022-03-18 07:26 - 000000000 ____D C:\Program Files (x86)\Google 2022-03-16 14:20 - 2022-03-16 14:21 - 000003922 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-3349755285-804529065-3594935135-1001UA{99A67289-CDAE-4B0B-965E-4FCE96259038} 2022-03-16 14:20 - 2022-03-16 14:21 - 000003654 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-3349755285-804529065-3594935135-1001Core{E3A78061-0DF5-4683-9BA6-E1B86B479BAF} 2022-03-16 14:20 - 2022-03-16 14:20 - 000001732 _____ C:\Users\DVM\Desktop\chrome - Atalho.lnk 2022-03-15 21:00 - 2022-03-15 21:00 - 000054994 _____ C:\Users\DVM\Desktop\AUREA MARTINS TOUCEDO_105220973 PLANILHA INSS.pdf 2022-03-15 20:59 - 2022-03-15 20:59 - 000075334 _____ C:\Users\DVM\Desktop\extrato_informacao_do_beneficio inss roberto.pdf 2022-03-15 17:48 - 2022-03-15 17:48 - 000054994 _____ C:\Users\DVM\Desktop\AUREA MARTINS TOUCEDO_105220973.pdf 2022-03-15 14:41 - 2022-03-15 14:41 - 000000000 ____D C:\Windows\system32\Tasks\McAfee 2022-03-15 14:31 - 2022-03-15 14:31 - 011106632 _____ (McAfee, LLC) C:\Users\DVM\Desktop\MCPR.exe 2022-03-14 17:41 - 2022-03-15 14:43 - 000000000 ____D C:\Program Files\Mozilla Firefox 2022-03-09 15:34 - 2022-03-09 15:34 - 000011911 _____ C:\Windows\system32\DrtmAuthTxt.wim 2022-03-09 15:33 - 2022-03-09 15:33 - 002254336 _____ C:\Windows\system32\dwmscene.dll 2022-03-09 15:33 - 2022-03-09 15:33 - 000223744 _____ C:\Windows\SysWOW64\TpmTool.exe 2022-03-09 15:32 - 2022-03-09 15:32 - 002260992 _____ C:\Windows\system32\TextInputMethodFormatter.dll 2022-03-09 15:32 - 2022-03-09 15:32 - 000272896 _____ C:\Windows\system32\TpmTool.exe 2022-03-09 15:05 - 2022-03-09 15:05 - 000000000 ___HD C:\$WinREAgent 2022-03-08 10:46 - 2022-03-08 10:47 - 000016674 _____ C:\Users\DVM\Desktop\informe_rendimento_2021.pdf 2022-03-07 17:53 - 2022-03-07 17:53 - 000129473 _____ C:\Users\DVM\Desktop\Informederendimentosfinanceiro_2022.pdf 2022-03-07 13:37 - 2022-03-07 13:37 - 000520495 _____ C:\Users\DVM\Desktop\Declaração. Cristina Martins Toucedo 2018.pdf 2022-02-28 16:28 - 2022-02-28 16:28 - 000012415 _____ C:\Users\DVM\Desktop\nota fiscal torradeira carmen.pdf 2022-02-25 18:04 - 2021-10-05 07:48 - 002668811 _____ C:\Users\DVM\Desktop\Chiquinho Petshop (@chiquinhopets) • Fotos e vídeos do Instagram.mhtml 2022-02-23 12:23 - 2022-02-23 12:23 - 000384338 _____ C:\Users\DVM\Desktop\Declaração_ CRISTINA MARTINS TOUCEDO_janeiro_2022.pdf 2022-02-19 16:35 - 2022-03-12 04:08 - 000000000 ____D C:\Users\DVM\AppData\LocalLow\uTorrent 2022-02-19 16:15 - 2022-02-19 16:15 - 000000901 _____ C:\Users\DVM\Desktop\µTorrent.lnk 2022-02-16 12:37 - 2022-02-16 20:37 - 000000000 ____D C:\Program Files\RUXIM ==================== Um mês (modificados) ================== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2022-03-18 07:51 - 2019-12-07 06:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-03-18 07:43 - 2020-09-12 17:45 - 000000000 ____D C:\Users\DVM\AppData\LocalLow\Mozilla 2022-03-18 07:35 - 2020-09-10 13:59 - 000000000 ____D C:\Windows\system32\SleepStudy 2022-03-17 20:11 - 2021-06-08 18:13 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2022-03-16 18:22 - 2022-02-09 04:43 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2022-03-16 14:20 - 2020-09-10 15:37 - 000000000 ____D C:\Users\DVM\AppData\Local\Google 2022-03-16 13:14 - 2021-11-24 11:40 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla 2022-03-16 08:06 - 2020-09-10 16:01 - 000000000 __SHD C:\Users\DVM\IntelGraphicsProfiles 2022-03-16 08:05 - 2020-09-10 16:02 - 000000134 _____ C:\Windows\system32\regtest.txt 2022-03-16 08:05 - 2020-09-10 15:50 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2022-03-16 08:05 - 2020-09-10 14:32 - 000000000 ____D C:\Intel 2022-03-16 08:05 - 2020-09-10 13:59 - 000008192 ___SH C:\DumpStack.log.tmp 2022-03-16 08:05 - 2020-09-10 13:59 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2022-03-16 08:04 - 2019-12-07 06:03 - 000786432 _____ C:\Windows\system32\config\BBI 2022-03-15 16:57 - 2020-10-04 07:20 - 000000000 ____D C:\Users\DVM\Desktop\FOLHETOS DE MISSA 2022-03-15 14:43 - 2020-09-10 15:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2022-03-15 14:38 - 2019-12-07 06:13 - 000000000 ____D C:\Windows\INF 2022-03-15 10:29 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\AppReadiness 2022-03-15 08:41 - 2019-12-07 06:03 - 000000000 ____D C:\Windows\CbsTemp 2022-03-15 07:57 - 2020-11-05 16:38 - 000000000 ____D C:\Users\DVM\AppData\Roaming\uTorrent 2022-03-15 00:41 - 2020-09-10 15:48 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2022-03-14 20:14 - 2020-09-10 14:00 - 000000000 ____D C:\Windows\system32\Drivers\wd 2022-03-14 11:11 - 2020-11-05 16:39 - 000000000 ____D C:\Users\DVM\AppData\Local\BitTorrentHelper 2022-03-11 22:08 - 2019-12-07 06:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-03-11 21:38 - 2020-09-10 14:06 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-03-11 18:36 - 2021-12-10 21:02 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3349755285-804529065-3594935135-1001 2022-03-11 18:36 - 2021-08-20 19:25 - 000002386 _____ C:\Users\DVM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-03-11 18:36 - 2020-09-10 14:25 - 000003374 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3349755285-804529065-3594935135-1001 2022-03-10 05:29 - 2020-09-10 14:05 - 000003618 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2022-03-10 05:29 - 2020-09-10 14:05 - 000003494 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2022-03-09 20:10 - 2020-09-10 14:12 - 001741824 _____ C:\Windows\system32\PerfStringBackup.INI 2022-03-09 20:10 - 2019-12-07 11:54 - 000752646 _____ C:\Windows\system32\prfh0416.dat 2022-03-09 20:10 - 2019-12-07 11:54 - 000148760 _____ C:\Windows\system32\prfc0416.dat 2022-03-09 20:01 - 2020-09-10 13:59 - 000315648 _____ C:\Windows\system32\FNTCACHE.DAT 2022-03-09 19:57 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\SystemResources 2022-03-09 19:57 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns 2022-03-09 19:57 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\oobe 2022-03-09 19:57 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\system32\migwiz 2022-03-09 19:56 - 2019-12-07 06:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 2022-03-09 19:56 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\PolicyDefinitions 2022-03-09 19:56 - 2019-12-07 06:14 - 000000000 ____D C:\Windows\bcastdvr 2022-03-09 19:56 - 2019-12-07 06:03 - 000000000 ____D C:\Windows\servicing 2022-03-09 15:59 - 2021-02-19 15:32 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2022-03-09 15:31 - 2020-09-10 14:02 - 002877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll 2022-03-09 15:05 - 2020-09-10 14:37 - 000000000 ____D C:\Windows\system32\MRT 2022-03-09 14:52 - 2020-09-10 14:37 - 145666720 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2022-02-25 21:08 - 2020-09-25 08:48 - 000000000 ____D C:\Users\DVM\AppData\Local\D3DSCache 2022-02-24 17:50 - 2020-09-10 14:27 - 000000000 ____D C:\Users\DVM\AppData\Local\PlaceholderTileLogoFolder 2022-02-19 16:15 - 2020-11-05 16:38 - 000000881 _____ C:\Users\DVM\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk ==================== Arquivos na raiz de alguns diretórios ======== 2022-02-03 19:05 - 2022-02-03 19:06 - 091813968 _____ () C:\Program Files (x86)\360-total-security-10-8-0-1419.exe 2021-10-28 17:53 - 2021-10-28 17:53 - 011829472 _____ () C:\Program Files (x86)\HPPSdr.exe 2021-05-24 19:23 - 2021-05-24 19:23 - 000425304 _____ (Secure By Design Inc.) C:\Program Files (x86)\Ninite Foxit Reader Installer.exe 2021-11-17 19:00 - 2021-11-17 19:00 - 000425304 _____ (Secure By Design Inc.) C:\Program Files (x86)\Ninite Malwarebytes Installer.exe 2020-11-09 08:53 - 2020-11-09 08:53 - 000425304 _____ (Secure By Design Inc.) C:\Program Files (x86)\Ninite qBittorrent Installer.exe 2020-09-12 17:16 - 2020-09-12 17:16 - 000425304 _____ (Secure By Design Inc.) C:\Program Files (x86)\Ninite Thunderbird Installer.exe 2020-11-05 16:35 - 2020-11-05 16:36 - 005116976 _____ (BitTorrent Inc.) C:\Program Files (x86)\uTorrent.exe 2021-06-08 18:09 - 2021-06-08 18:09 - 000000410 _____ () C:\Users\DVM\AppData\Local\oobelibMkey.log ==================== SigCheck ============================ (Não há correção automática para arquivos que não passaram na verificação.) ==================== Fim de FRST.txt ========================