Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-05-2021 Ran by [removed] (21-05-2021 12:27:54) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 2004 19041.985 (X64) (2020-10-06 16:01:08) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-3661222335-3224273436-2019648677-500 - Administrator - Disabled) Convidado (S-1-5-21-3661222335-3224273436-2019648677-501 - Limited - Disabled) DefaultAccount (S-1-5-21-3661222335-3224273436-2019648677-503 - Limited - Disabled) PC (S-1-5-21-3661222335-3224273436-2019648677-1002 - Administrator - Enabled) => C:\Users\PC WDAGUtilityAccount (S-1-5-21-3661222335-3224273436-2019648677-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Emsisoft Anti-Malware (Enabled - Up to date) {5FD8BF8F-F242-6153-61B5-8FF333E8736B} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\uTorrent) (Version: 3.5.5.45988 - BitTorrent Inc.) 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 6.2.3 - philandro Software GmbH) DroidCam Client (HKLM-x32\...\DroidCam) (Version: 6.3.3 - Dev47apps) DroidCam OBS Plugin (HKLM-x32\...\OBSDroidCam) (Version: 1.2.0 - Dev47apps) Emsisoft Anti-Malware (HKLM\...\{CA975286-D816-410C-B6C9-F7213CA84695}) (Version: 21.5.0.10896 - Emsisoft Ltd.) FontBase 2.13.2 (HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\ffc1e284-e25b-515d-b453-93eb9fe955eb) (Version: 2.13.2 - Dominik Levitsky Studio, LLC) Google Chrome (HKLM\...\{566A834D-2DDD-3376-B265-20E45991EB23}) (Version: 90.0.4430.212 - Google LLC) GridinSoft Anti-Malware (HKLM\...\GridinSoft Anti-Malware) (Version: 4.1.94 - Gridinsoft LLC) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.5166 - Intel Corporation) IPTV Smarters Player 3.0.0 (HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\fee38e36-bd5c-5f8c-a4c4-29d7f942a22c) (Version: 3.0.0 - IPTV Smarters Player) K-Lite Codec Pack 13.7.5 Basic (HKLM-x32\...\KLiteCodecPack_is1) (Version: 13.7.5 - KLCP) Malwarebytes version 4.3.3.116 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.3.3.116 - Malwarebytes) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 90.0.818.62 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{A0E1B43D-5F4A-46AF-9925-ABA3423325DC}) (Version: 2.77.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2019 (HKLM-x32\...\{1edcd8d2-905a-4e93-bfdf-92ed5601528a}) (Version: 16.0.28801 - Microsoft Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 26.0.2 - OBS Project) PSD Viewer (HKLM-x32\...\{D8EEDC94-EE82-46A0-A7DB-812E3C6A0A6E}_is1) (Version: - IdeaMK) RaiDrive (HKLM\...\{30C75A78-A84E-41B2-877C-13D43B348A5D}) (Version: 2020.11.38 - OpenBoxLab Inc.) Hidden RaiDrive (HKLM\...\RaiDrive 2020.11.38) (Version: 2020.11.38 - OpenBoxLab Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7841 - Realtek Semiconductor Corp.) ReaPlugs/x64 (HKLM\...\ReaPlugs) (Version: - ) Stellar Data Recovery (HKLM\...\Stellar Data Recovery_is1) (Version: 10.1.0.0 - Stellar Information Technology Pvt Ltd.) TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.17.6 - TeamViewer) Telegram Desktop version 2.7.1 (HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 2.7.1 - Telegram FZ-LLC) VLC media player (HKLM\...\VLC media player) (Version: 3.0.11 - VideoLAN) WhatsApp (HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\WhatsApp) (Version: 2.2117.5 - WhatsApp) WinFsp 2020.2 (HKLM-x32\...\{2CF61E4B-7E9B-42AC-86B7-051EFDEE312D}) (Version: 1.8.20304 - Navimatics LLC) WinRAR 5.70 beta 2 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.2 - win.rar GmbH) WiperSoft 1.1.1157.64 (HKLM\...\{AB1C8C91-4D8E-4C28-80E7-FD135FB90515}}_is1) (Version: 1.1.1157.64 - WiperSoft) Zoom (HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\ZoomUMX) (Version: 5.4.7 (59784.1220) - Zoom Video Communications, Inc.) Packages: ========= ColorNote Notepad Notes -> C:\Program Files\WindowsApps\DBA41F73.ColorNoteNotepadNotes_1.1.0.20_neutral__3jn8vbmxrzmj2 [2021-05-20] (Social & Mobile, Inc.) Deezer Music -> C:\Program Files\WindowsApps\Deezer.62021768415AF_5.0.0.0_x86__q7m17pa7q8kj0 [2021-05-20] (Deezer SA) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-05-20] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-05-20] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.5060.0_x64__8wekyb3d8bbwe [2021-05-20] (Microsoft Studios) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3661222335-3224273436-2019648677-1002_Classes\CLSID\{272D2E65-05FB-4500-BD7B-5905D5B0A1B8}\localserver32 -> C:\Users\PC\AppData\Roaming\Nelogica\XPTrader\profitchart.exe => No File SSODL: EldosMountNotificator-cbfs6 - {48B6FAC0-51A3-44BA-8412-74035E98DA9F} - C:\Windows\system32\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) SSODL-x32: EldosMountNotificator-cbfs6 - {48B6FAC0-51A3-44BA-8412-74035E98DA9F} - C:\Windows\SysWOW64\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) ShellServiceObjects: Virtual Storage Mount Notification -> {48B6FAC0-51A3-44BA-8412-74035E98DA9F} => C:\Windows\system32\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ShellServiceObjects-x32: Virtual Storage Mount Notification -> {48B6FAC0-51A3-44BA-8412-74035E98DA9F} => C:\Windows\SysWOW64\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs6] -> {386811EF-2FB4-4A60-AADF-BCE83D78B13D} => C:\Windows\system32\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs6] -> {386811EF-2FB4-4A60-AADF-BCE83D78B13D} => C:\Windows\system32\cbfsMntNtf6.dll [2016-09-21] (EldoS Corporation -> /n software, Inc.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ContextMenuHandlers1: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => C:\Program Files\GridinSoft Anti-Malware\shellext.dll [2021-05-20] (GridinSoft, LLC -> Gridinsoft LLC) ContextMenuHandlers1: [RaiDrive.CopyMove] -> {7031db56-aef0-4a42-b4c9-bfdf2abe4765} => C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.ShellExtension.x64.dll [2021-01-18] (OpenBoxLab -> OpenBoxLab Inc.) ContextMenuHandlers1: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll -> No File ContextMenuHandlers2-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU.DLL [2021-05-20] (Emsisoft Ltd -> Emsisoft Ltd) ContextMenuHandlers2: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU64.DLL [2021-05-20] (Emsisoft Ltd -> Emsisoft Ltd) ContextMenuHandlers2: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => C:\Program Files\GridinSoft Anti-Malware\shellext.dll [2021-05-20] (GridinSoft, LLC -> Gridinsoft LLC) ContextMenuHandlers2: [RaiDrive.CopyMove] -> {7031db56-aef0-4a42-b4c9-bfdf2abe4765} => C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.ShellExtension.x64.dll [2021-01-18] (OpenBoxLab -> OpenBoxLab Inc.) ContextMenuHandlers3-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU.DLL [2021-05-20] (Emsisoft Ltd -> Emsisoft Ltd) ContextMenuHandlers3: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU64.DLL [2021-05-20] (Emsisoft Ltd -> Emsisoft Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-05-20] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => C:\Program Files\GridinSoft Anti-Malware\shellext.dll [2021-05-20] (GridinSoft, LLC -> Gridinsoft LLC) ContextMenuHandlers4: [RaiDrive.CopyMove] -> {7031db56-aef0-4a42-b4c9-bfdf2abe4765} => C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.ShellExtension.x64.dll [2021-01-18] (OpenBoxLab -> OpenBoxLab Inc.) ContextMenuHandlers4: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2020-12-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [RaiDrive.CopyMove] -> {7031db56-aef0-4a42-b4c9-bfdf2abe4765} => C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.ShellExtension.x64.dll [2021-01-18] (OpenBoxLab -> OpenBoxLab Inc.) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ContextMenuHandlers6-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU.DLL [2021-05-20] (Emsisoft Ltd -> Emsisoft Ltd) ContextMenuHandlers6: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU64.DLL [2021-05-20] (Emsisoft Ltd -> Emsisoft Ltd) ContextMenuHandlers6: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => C:\Program Files\GridinSoft Anti-Malware\shellext.dll [2021-05-20] (GridinSoft, LLC -> Gridinsoft LLC) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-05-20] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [RaiDrive.CopyMove] -> {7031db56-aef0-4a42-b4c9-bfdf2abe4765} => C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.ShellExtension.x64.dll [2021-01-18] (OpenBoxLab -> OpenBoxLab Inc.) ContextMenuHandlers6: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll -> No File ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\PC\Desktop\Camila - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2" ShortcutWithArgument: C:\Users\PC\Desktop\Condor (Condor Veiculos) - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 18" ShortcutWithArgument: C:\Users\PC\Desktop\disk (disk Fossa) - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 17" ShortcutWithArgument: C:\Users\PC\Desktop\Dornel - Optimo Assessoria - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 12" ShortcutWithArgument: C:\Users\PC\Desktop\G (Gabriel) - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 7" ShortcutWithArgument: C:\Users\PC\Desktop\Kaio - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default" ShortcutWithArgument: C:\Users\PC\Desktop\teste - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 16" ShortcutWithArgument: C:\Users\PC\Desktop\Tv (Sat Tv Valparaiso de Goias) - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 3" ==================== Loaded Modules (Whitelisted) ============= 2012-01-19 23:00 - 2012-01-19 23:00 - 000059392 _____ () [File not signed] C:\Program Files\Stellar Data Recovery\DR\ArmAccess64.dll 2007-03-08 00:33 - 2007-03-08 00:33 - 000009216 _____ () [File not signed] C:\Program Files\Stellar Data Recovery\DR\Rockey2.dll 2021-02-27 16:23 - 2021-05-21 10:47 - 000319488 _____ (/n software, Inc.) [File not signed] [File is in use] C:\Windows\TEMP\b0494a1f-4bd3-owMQN5swJPTJH+ixLIcd2g==\CBFS6Net.dll 2021-02-23 13:02 - 2019-02-21 13:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2020-10-30 14:04 - 2020-10-30 14:04 - 000160768 _____ (Navimatics LLC) [File not signed] C:\Program Files (x86)\WinFsp\bin\winfsp-x64.dll 2021-05-21 01:31 - 2020-08-02 16:27 - 000330240 _____ (Software Security System) [File not signed] C:\Program Files\Stellar Data Recovery\DR\EKC6420.DLL 2016-09-26 09:21 - 2016-09-26 09:21 - 002088448 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Stellar Data Recovery\DR\LIBEAY32.dll 2016-09-26 09:21 - 2016-09-26 09:21 - 000352256 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Stellar Data Recovery\DR\SSLEAY32.dll 2020-04-27 20:41 - 2020-04-27 20:41 - 000046080 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\bearer\qgenericbearer.dll 2020-04-27 22:08 - 2020-04-27 22:08 - 000032256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qgif.dll 2020-04-27 22:11 - 2020-04-27 22:11 - 000036864 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qicns.dll 2020-04-27 22:08 - 2020-04-27 22:08 - 000031232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qico.dll 2020-04-27 22:08 - 2020-04-27 22:08 - 000413184 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qjpeg.dll 2020-04-27 22:12 - 2020-04-27 22:12 - 000025088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qsvg.dll 2020-04-27 22:10 - 2020-04-27 22:10 - 000024064 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qtga.dll 2020-04-27 22:10 - 2020-04-27 22:10 - 000382464 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qtiff.dll 2020-04-27 22:10 - 2020-04-27 22:10 - 000022528 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qwbmp.dll 2020-04-27 22:11 - 2020-04-27 22:11 - 000502272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\imageformats\qwebp.dll 2020-04-28 08:52 - 2020-04-28 08:52 - 000292352 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\mediaservice\dsengine.dll 2020-04-28 08:53 - 2020-04-28 08:53 - 000201216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\mediaservice\wmfengine.dll 2020-04-27 22:06 - 2020-04-27 22:06 - 001432576 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\platforms\qwindows.dll 2020-04-27 20:19 - 2020-04-27 20:19 - 005909504 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5Core.dll 2020-04-27 20:33 - 2020-04-27 20:33 - 006658048 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5Gui.dll 2020-04-28 08:48 - 2020-04-28 08:48 - 000732672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5Multimedia.dll 2020-04-28 08:49 - 2020-04-28 08:49 - 000095232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5MultimediaWidgets.dll 2020-04-27 20:20 - 2020-04-27 20:20 - 001262592 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5Network.dll 2020-04-27 20:41 - 2020-04-27 20:41 - 000313856 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5OpenGL.dll 2020-04-27 22:12 - 2020-04-27 22:12 - 000317952 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5Svg.dll 2020-04-27 20:38 - 2020-04-27 20:38 - 005472256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\Qt5Widgets.dll 2020-04-27 22:09 - 2020-04-27 22:09 - 000135680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Stellar Data Recovery\DR\styles\qwindowsvistastyle.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData:chnpbmzkyg [370] AlternateDataStreams: C:\ProgramData:YXVtLmh6aQ [3634] AlternateDataStreams: C:\Users\All Users:chnpbmzkyg [370] AlternateDataStreams: C:\Users\All Users:YXVtLmh6aQ [3634] AlternateDataStreams: C:\Users\Todos os Usuários:chnpbmzkyg [370] AlternateDataStreams: C:\Users\Todos os Usuários:YXVtLmh6aQ [3634] AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:chnpbmzkyg [370] AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:YXVtLmh6aQ [3634] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-12-07 06:14 - 2019-12-07 06:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 10.1.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) MSCONFIG\Services: asComSvc => 2 MSCONFIG\Services: cphs => 2 MSCONFIG\Services: FoxitReaderUpdateService => 2 MSCONFIG\Services: GoogleChromeElevationService => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: igfxCUIService2.0.0.0 => 2 MSCONFIG\Services: wuauserv => 2 HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "Reflect UI" HKLM\...\StartupApproved\Run: => "Emsisoft Anti-Malware" HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\StartupApproved\StartupFolder: => "IQTray.lnk" HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\StartupApproved\Run: => "CCXProcess" HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\StartupApproved\Run: => "RaiDrive" HKU\S-1-5-21-3661222335-3224273436-2019648677-1002\...\StartupApproved\Run: => "ZoomIt" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{892C2F0D-8620-414C-B4DA-DF0C12BEA90F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe => No File FirewallRules: [{47988DF6-73F7-49BF-B512-629C8AF8E7C8}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe => No File FirewallRules: [{98910D60-9C87-490C-9002-CA27A889D735}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{AA738DBF-A3F1-41C6-92B3-0A195F05EA60}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{7CCC0F4B-ABC4-438A-A1CF-FCE809739E65}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{96E6A24E-03A0-49E8-A9E5-AAE72BAE7629}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{F52B440C-D9DC-45F6-8540-24494750C48A}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [TCP Query User{80F7F372-2276-4795-BFEA-7866A56AF087}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe => No File FirewallRules: [UDP Query User{BA6E7F53-DCD3-4376-8A71-00568A7E8F96}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe => No File FirewallRules: [TCP Query User{0D25A1A0-620E-46A9-AA64-02CFA6DA0D40}C:\program files (x86)\droidcam\droidcamapp.exe] => (Allow) C:\program files (x86)\droidcam\droidcamapp.exe (DEV47 APPS -> ) FirewallRules: [UDP Query User{946C85F3-AC34-4C05-80BC-0ECBCCCD5B91}C:\program files (x86)\droidcam\droidcamapp.exe] => (Allow) C:\program files (x86)\droidcam\droidcamapp.exe (DEV47 APPS -> ) FirewallRules: [TCP Query User{25FA6407-5838-42F3-A935-2F89C1119D97}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [UDP Query User{883F6105-BD0B-4652-A85F-BBE9CCE5B7EF}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{5FA4823E-E658-4216-81BD-A7D54662DE9C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{4D0EBA60-F308-42CF-A925-E5C710442C20}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{F0D8BE60-DE74-4F3B-BCDD-1CEBC27F5001}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{04FCA7FC-16BC-416F-8224-22BC82AF4EE3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{46FF7D1C-0F01-4615-93A2-72AD0E02F8F2}] => (Allow) C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.exe (OpenBoxLab -> OpenBoxLab Inc.) FirewallRules: [{F41DC92F-578E-480C-880D-4BA0F65930B1}] => (Allow) C:\Program Files\OpenBoxLab Inc\RaiDrive\RaiDrive.Service.x64.exe (OpenBoxLab -> OpenBoxLab Inc.) FirewallRules: [{116CDCA9-D570-4254-9FD0-D285D9079491}] => (Allow) C:\Program Files\FBS MetaTrader 5\metatester64.exe => No File FirewallRules: [TCP Query User{72712F74-43EF-4818-995C-C6B286D50D7C}C:\users\pc\downloads\anydesk.exe] => (Allow) C:\users\pc\downloads\anydesk.exe => No File FirewallRules: [UDP Query User{38F187CB-6B74-4C1B-A4B4-ED0F8FE4FD53}C:\users\pc\downloads\anydesk.exe] => (Allow) C:\users\pc\downloads\anydesk.exe => No File FirewallRules: [TCP Query User{FB5580B7-8CC5-439F-81D9-5AED91924DFC}C:\program files\ldplayerbox\ldvboxheadless.exe] => (Allow) C:\program files\ldplayerbox\ldvboxheadless.exe => No File FirewallRules: [UDP Query User{F7F07900-DA0B-462F-8A52-34EC9A58135F}C:\program files\ldplayerbox\ldvboxheadless.exe] => (Allow) C:\program files\ldplayerbox\ldvboxheadless.exe => No File FirewallRules: [TCP Query User{406927C7-312C-4DF6-A114-C3D1C2DE01B0}C:\users\pc\downloads\anydesk (2).exe] => (Allow) C:\users\pc\downloads\anydesk (2).exe => No File FirewallRules: [UDP Query User{8B810B24-EBDD-4988-9C3C-6198CB60348D}C:\users\pc\downloads\anydesk (2).exe] => (Allow) C:\users\pc\downloads\anydesk (2).exe => No File FirewallRules: [{A43FC00A-0C8C-4306-A80C-12CFCC9D617A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{FA5689CD-278A-4D57-A5DF-88C26F5EB9E2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{6AE7DE3D-19A2-4502-A8F9-EFDF868B56C1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [{740356B7-4D64-484A-9B10-9DA66094CF84}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) FirewallRules: [TCP Query User{38022DA4-7CF0-4C92-9F65-793A950F2B71}C:\users\pc\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\pc\appdata\roaming\spotify\spotify.exe => No File FirewallRules: [UDP Query User{379E9C50-AF1D-4E97-8105-40584442E649}C:\users\pc\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\pc\appdata\roaming\spotify\spotify.exe => No File FirewallRules: [{8224643A-0797-4099-8209-6E87D885BD56}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{2FB2698C-DFCD-459F-926C-A2EB53BA810F}] => (Allow) C:\Users\PC\Downloads\any-data-recovery.exe (Tenorshare Co.,Ltd. -> UltFone Co., Ltd.) FirewallRules: [{5DD419FE-A3FC-4F5F-97A6-28AF73DEB18A}] => (Allow) C:\Users\PC\Downloads\any-data-recovery.exe (Tenorshare Co.,Ltd. -> UltFone Co., Ltd.) FirewallRules: [{CBD66EAE-DCFC-4495-8592-F243A53939A2}] => (Allow) C:\Users\PC\Downloads\tenorshare-4ddig-for-windows.exe (Tenorshare Co.,Ltd. -> Tenorshare Co., Ltd.) FirewallRules: [{984E3DDE-1641-452D-8757-D933968EADE7}] => (Allow) C:\Users\PC\Downloads\tenorshare-4ddig-for-windows.exe (Tenorshare Co.,Ltd. -> Tenorshare Co., Ltd.) FirewallRules: [{5D13904D-6BA8-4D36-853D-1A34952DE9EF}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{A746A736-3A86-47FC-B5E2-359875D8791F}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{E08F7768-5BE3-4768-BA58-0B749648099D}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{6F82219A-A654-4059-B982-C64041B0B245}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{463289BE-8201-42BD-9C8B-3CE044F0B8EB}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{589F1F9B-3531-456F-B200-FDEB2C3637A3}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (05/21/2021 11:56:57 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (05/21/2021 11:51:29 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (05/21/2021 11:50:00 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbamtray.exe, version: 4.0.0.987, time stamp: 0x60894603 Faulting module name: Qt5Core.dll, version: 5.14.1.0, time stamp: 0x603971ce Exception code: 0xc0000005 Fault offset: 0x0000000000219dc5 Faulting process id: 0x81c Faulting application start time: 0x01d74e50163ad378 Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll Report Id: 46e3ebd3-bdca-4916-8153-566dbcb6868a Faulting package full name: Faulting package-relative application ID: Error: (05/21/2021 11:49:44 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (05/21/2021 11:46:35 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (05/21/2021 10:51:19 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (05/21/2021 10:49:41 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Security Center failed to validate caller with error %1. Error: (05/21/2021 10:47:42 AM) (Source: nssm) (EventID: 1010) (User: ) Description: Failed to start service Rclone B. Program C:\rclone\rclone.exe couldn't be launched. CreateProcess() failed: Esta versão de Rclone B não é compatível com a versão do Windows sendo executada. Verifique as informações de sistema do computador e contate o fornecedor do software. System errors: ============= Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Rclone B service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Rclone B service terminated with the following service-specific error: O sistema não pode encontrar o caminho especificado. Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Rclone C service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Rclone C service terminated with the following service-specific error: O sistema não pode encontrar o caminho especificado. Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Teste service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Teste service terminated with the following service-specific error: O sistema não pode encontrar o caminho especificado. Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The rclone L service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2021 10:47:42 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The rclone L service terminated with the following service-specific error: O sistema não pode encontrar o caminho especificado. Windows Defender: ================ Date: 2021-05-20 13:41:31 Description: Microsoft Defender Antivírus scan has been stopped before completion. Scan Type: Antimalware Scan Parameters: Verificação Rápida Date: 2021-05-20 00:58:52 Description: Microsoft Defender Antivírus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Glupteba&threatid=2147718257&enterprise=0 Name: Trojan:Win32/Glupteba Severity: Grave Category: Cavalo de Tróia Path: process:_pid:5236,ProcessStart:132659561350183724 Detection Origin: Desconhecido Detection Type: Concreto Detection Source: Sistema Process Name: C:\Users\PC\AppData\Local\de2902e5-7245-4c21-8562-4e5f60f304ec\4FC6.exe Security intelligence Version: AV: 1.339.1070.0, AS: 1.339.1070.0, NIS: 1.339.1070.0 Engine Version: AM: 1.1.18100.6, NIS: 1.1.18100.6 Date: 2021-05-20 00:53:01 Description: Microsoft Defender Antivírus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=PWS:Win32/Racealer.GKM!MTB&threatid=2147774296&enterprise=0 Name: PWS:Win32/Racealer.GKM!MTB Severity: Grave Category: Password Stealer Path: file:_C:\Users\PC\AppData\Local\ef58a811-5930-4445-8d5a-3b676b475848\5.exe Detection Origin: Computador local Detection Type: Concreto Detection Source: Sistema Process Name: Unknown Security intelligence Version: AV: 1.339.1068.0, AS: 1.339.1068.0, NIS: 1.339.1068.0 Engine Version: AM: 1.1.18100.6, NIS: 1.1.18100.6 Date: 2021-05-20 00:53:01 Description: Microsoft Defender Antivírus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Tilevn.A&threatid=2147760578&enterprise=0 Name: Trojan:Win32/Tilevn.A Severity: Grave Category: Cavalo de Tróia Path: amsiuac:_pid:000037E4 Detection Origin: Desconhecido Detection Type: Concreto Detection Source: Sistema Process Name: Unknown Security intelligence Version: AV: 1.339.1068.0, AS: 1.339.1068.0, NIS: 1.339.1068.0 Engine Version: AM: 1.1.18100.6, NIS: 1.1.18100.6 Date: 2021-05-20 00:53:01 Description: Microsoft Defender Antivírus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Fareit.V!MTB&threatid=2147743811&enterprise=0 Name: Trojan:Win32/Fareit.V!MTB Severity: Grave Category: Cavalo de Tróia Path: file:_C:\Users\PC\AppData\Local\ef58a811-5930-4445-8d5a-3b676b475848\updatewin2.exe Detection Origin: Computador local Detection Type: Concreto Detection Source: Sistema Process Name: Unknown Security intelligence Version: AV: 1.339.1068.0, AS: 1.339.1068.0, NIS: 1.339.1068.0 Engine Version: AM: 1.1.18100.6, NIS: 1.1.18100.6 Date: 2021-05-20 02:07:56 Description: Microsoft Defender Antivírus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version. Security intelligence Attempted: Atual Error Code: 0x80070003 Error description: O sistema não pode encontrar o caminho especificado. Security intelligence version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0 Date: 2021-05-06 09:30:50 Description: Microsoft Defender Antivírus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.337.671.0 Update Source: Servidor do Microsoft Update Security intelligence Type: Antivírus Update Type: Completa Current Engine Version: Previous Engine Version: 1.1.18100.5 Error code: 0x80070643 Error description: Erro fatal durante a instalação. Date: 2021-05-06 09:30:48 Description: Microsoft Defender Antivírus has encountered an error trying to update security intelligence. New security intelligence Version: 1.339.61.0 Previous security intelligence Version: 1.337.671.0 Update Source: Usuário Security intelligence Type: Anti-spyware Update Type: Delta Current Engine Version: 1.1.18100.6 Previous Engine Version: 1.1.18100.5 Error code: 0x80070666 Error description: Outra versão deste produto já está instalada. A instalação desta versão não pode continuar. Para configurar ou remover a versão existente deste produto, use 'Adicionar ou remover programas' no Painel de Controle. Date: 2021-05-06 09:30:48 Description: Microsoft Defender Antivírus has encountered an error trying to update security intelligence. New security intelligence Version: 1.339.61.0 Previous security intelligence Version: 1.337.671.0 Update Source: Usuário Security intelligence Type: Antivírus Update Type: Delta Current Engine Version: 1.1.18100.6 Previous Engine Version: 1.1.18100.5 Error code: 0x80070666 Error description: Outra versão deste produto já está instalada. A instalação desta versão não pode continuar. Para configurar ou remover a versão existente deste produto, use 'Adicionar ou remover programas' no Painel de Controle. Date: 2021-05-06 09:30:48 Description: Microsoft Defender Antivírus has encountered an error trying to update the engine. New Engine Version: 1.1.18100.6 Previous Engine Version: 1.1.18100.5 Error Code: 0x80070666 Error description: Outra versão deste produto já está instalada. A instalação desta versão não pode continuar. Para configurar ou remover a versão existente deste produto, use 'Adicionar ou remover programas' no Painel de Controle. CodeIntegrity: =============== Date: 2021-05-21 11:56:57 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume9\Program Files\Emsisoft Anti-Malware\eppcom64.dll that did not meet the Microsoft signing level requirements. Date: 2021-05-21 11:55:37 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume9\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2021-05-21 11:55:37 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume9\Program Files\Emsisoft Anti-Malware\eppcom64.dll that did not meet the Windows signing level requirements. Date: 2021-05-21 11:55:37 Description: Code Integrity determined that a process (\Device\HarddiskVolume9\Program Files\Emsisoft Anti-Malware\eppwsc.exe) attempted to load \Device\HarddiskVolume9\Program Files\Emsisoft Anti-Malware\eppcom64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2021-05-21 11:51:29 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume9\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== BIOS: American Megatrends Inc. 2201 03/09/2015 Motherboard: ASUSTeK COMPUTER INC. H81M-A/BR Processor: Intel(R) Pentium(R) CPU G3250 @ 3.20GHz Percentage of memory in use: 68% Total physical RAM: 8063.86 MB Available physical RAM: 2549.04 MB Total Virtual: 16255.86 MB Available Virtual: 9649.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.14 GB) (Free:48.7 GB) NTFS Drive d: (HD) (Fixed) (Total:148.41 GB) (Free:147.92 GB) NTFS \\?\Volume{4e40dd27-2f4d-406d-a603-bba482a3128d}\ () (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS \\?\Volume{0ddd15fc-24e0-48ba-9b0d-f6db04457a3c}\ () (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS \\?\Volume{27ac568f-d511-476b-99d9-8cc711d3bdb1}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 \\?\Volume{27b3ed9b-beb6-4083-8c22-bb0776f0478f}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 149.1 GB) (Disk ID: 85B585B5) Partition: GPT. ========================================================== Disk: 1 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt =======================