Inactive PC infected for Virus.Neshta/Hijack.exeFile and Trojan.Agent.SVC.Generic in svchost.exe

08c64d5b-9e27-4104-8e8c-e23354714783.jpg
Recently, I used programs like "Malware bytes, Reimage" to try to remove these viruses, but when I restart the pc they immediately come back, I need help, this virus is blocking me from running programs, and also deleting some like Google

If someone can help me, thanks.
 
Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
 
PS 1: I'm brasilian, but I'm using google translator...
PS 2: Can I do this in safe mode?
PS 3: Can I install Avast while scanning?

Edited:
There, I sent FRST.txt and Addition.txt

Edited 2: This message is awaiting moderator approval, and is invisible to normal visitors.
 
Last edited:
Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 04-06-2020
Executado por Murilo (administrador) em MURILO-PC (MEGAWARE MW-H61M-2H) (05-06-2020 19:31:59)
Executando a partir de C:\Users\Murilo\Desktop\Downloads
Perfis Carregados: Murilo
Platform: Windows 7 Ultimate Service Pack 1 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Safe Mode (with Networking)
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <16>
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\regedit.exe
(Reimage LTD. -> reimage) C:\Program Files\Reimage\Reimage Protector\ReimageApp.exe
(Reimage LTD. -> reimage) C:\Program Files\Reimage\Reimage Repair\Reimage.exe

==================== Registro (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [Reimage] => C:\Program Files\Reimage\Reimage Protector\ReimageApp.exe [275168 2020-05-18] (Reimage LTD. -> reimage)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [770576 2020-06-04] (Oracle America, Inc. -> Oracle Corporation) [Arquivo não assinado]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.97\Installer\chrmstp.exe [2020-06-05] (Google LLC -> Google LLC)
GroupPolicy: Restrição ? <==== ATENÇÃO

==================== Tarefas Agendadas (Whitelisted) ============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

Task: {0136E1C1-3A49-40C2-94AD-BC6B2F19D1BB} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628672 2020-01-30] (Advanced Micro Devices, Inc.) [Arquivo não assinado]
Task: {48C3AA0C-CEFA-4BF2-8F31-4A1D3C736AD0} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {4DA965FB-5EF3-4D02-BBB1-EA6704350B76} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [67688 2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {5E9D792C-3C5D-44D8-BA76-9858CEDF39FB} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: {759113E0-A8EE-4C0F-929B-CFA19B2FEB85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-05] (Google LLC -> Google LLC)
Task: {855ABA56-ACBB-45DD-9DCC-2DF9815F42F9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {8E78AA7F-3EA6-4D82-8716-A8B06C90836A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-05] (Google LLC -> Google LLC)
Task: {962BB193-713D-4098-B701-3ED44D600708} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [60008 2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {A6040B1A-676C-4A1C-8BC2-1ADFBBEB252D} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628672 2020-01-30] (Advanced Micro Devices, Inc.) [Arquivo não assinado]

(Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.)

Task: C:\Windows\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\..\Interfaces\{3612A4ED-3D8C-43D7-814F-1942347C3B7E}: [NameServer] 189.45.192.3,177.200.200.20

Internet Explorer:
==================
HKU\S-1-5-21-2095121090-2903240913-2782640044-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_241\bin\ssv.dll [2020-01-18] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_241\bin\jp2ssv.dll [2020-01-18] (Oracle America, Inc. -> Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Windows -> Microsoft Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-01-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-01-18] (Oracle America, Inc. -> Oracle Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default [2020-06-05]
CHR Notifications: Default -> hxxps://web.whatsapp.com; hxxps://www1a.bethanyharrell.pro; hxxps://www1a.lucienmann.pro
CHR HomePage: Default -> hxxps://www.facebook.com/
CHR StartupUrls: Default -> "hxxps://www.facebook.com/"
CHR Extension: (Apresentações) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-10-05]
CHR Extension: (YouTube) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-10-05]
CHR Extension: (High Contrast Colorful) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfdkmklcjlnnnlnplffpdiekfhkpbme [2020-04-14]
CHR Extension: (Documentos Google off-line) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-05-28]
CHR Extension: (Roblox+) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbnmfgkohlfclfnplnlenbalpppohkm [2020-05-21]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-05]
CHR Extension: (Chrome Media Router) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-06-05]
CHR Profile: C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-04-14]
CHR Extension: (Apresentações) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-14]
CHR Extension: (Documentos) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-14]
CHR Extension: (Google Drive) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-14]
CHR Extension: (YouTube) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-14]
CHR Extension: (Planilhas) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-14]
CHR Extension: (Documentos Google off-line) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-14]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-14]
CHR Extension: (Gmail) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-14]
CHR Extension: (Chrome Media Router) - C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-14]
CHR Profile: C:\Users\Murilo\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-14]

==================== Serviços (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [513640 2020-01-30] (Advanced Micro Devices, Inc. -> AMD)
S2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [190464 2020-01-30] () [Arquivo não assinado]
S2 gupdate1d63b7b3deb961e; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-05] (Google LLC -> Google LLC)
S3 gupdatem1d63b7b3e10f8fa; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-06-05] (Google LLC -> Google LLC)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-11] (Malwarebytes Inc -> Malwarebytes)
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [9073504 2020-02-19] (Reimage LTD. -> Reimage®)
S4 uncheater_bgl; C:\Program Files\Common Files\Uncheater\uncheater_bgl.exe [2097008 2020-02-05] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Windows -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [26728 2020-01-30] (Advanced Micro Devices, Inc. -> )
S3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [65731176 2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [581224 2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2019-12-03] (Disc Soft Ltd -> Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [214496 2020-06-05] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-06-05] (Malwarebytes Inc -> Malwarebytes)
S3 RvNetMP60; C:\Windows\System32\DRIVERS\RvNetMP60.sys [69048 2019-11-20] (Famatech Corp. -> Famatech Corp.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tesrsdt; C:\Windows\system32\drivers\tesrsdt.sys [432840 2019-10-06] (Tencent Technology(Shenzhen) Company Limited -> TENCENT)
S3 TesSafe; C:\Windows\system32\TesSafe.sys [545568 2020-02-25] (Tencent Technology(Shenzhen) Company Limited -> TENCENT)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S1 TBoxDrv; \??\C:\Program Files\AndroidTbox\TBoxDrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um mês (criados) ===================

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2020-06-05 19:33 - 2020-06-05 19:33 - 000000000 ____D C:\Program Files\AVAST Software
2020-06-05 19:30 - 2020-06-05 19:32 - 000000000 ____D C:\FRST
2020-06-05 18:24 - 2020-06-05 18:24 - 000000344 _____ C:\Windows\Tasks\ReimageUpdater.job
2020-06-05 18:23 - 2020-06-05 18:26 - 000000000 ____D C:\Users\Todos os Usuários\Reimage Protector
2020-06-05 18:23 - 2020-06-05 18:26 - 000000000 ____D C:\ProgramData\Reimage Protector
2020-06-05 18:23 - 2020-06-05 18:24 - 000000000 ____D C:\rei
2020-06-05 18:23 - 2020-06-05 18:24 - 000000000 ____D C:\Program Files\Reimage
2020-06-05 18:23 - 2020-06-05 18:23 - 000001877 _____ C:\Users\Todos os Usuários\Desktop\PC Scan & Repair by Reimage.lnk
2020-06-05 18:23 - 2020-06-05 18:23 - 000001877 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2020-06-05 18:23 - 2020-06-05 18:23 - 000001877 _____ C:\ProgramData\Desktop\PC Scan & Repair by Reimage.lnk
2020-06-05 18:23 - 2020-06-05 18:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2020-06-05 18:22 - 2020-06-05 18:24 - 000000140 _____ C:\Windows\Reimage.ini
2020-06-05 18:13 - 2020-06-05 18:14 - 000053790 _____ C:\Windows\ntbtlog.txt
2020-06-05 18:13 - 2020-06-05 18:13 - 000214496 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-06-05 17:56 - 2020-06-05 18:13 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-06-05 17:54 - 2020-06-05 17:54 - 000002298 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-06-05 17:54 - 2020-06-05 17:54 - 000002257 _____ C:\Users\Todos os Usuários\Desktop\Google Chrome.lnk
2020-06-05 17:54 - 2020-06-05 17:54 - 000002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-05 17:54 - 2020-06-05 17:54 - 000002257 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-06-05 17:52 - 2020-06-05 17:52 - 000003444 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-06-05 17:52 - 2020-06-05 17:52 - 000003316 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-06-05 17:39 - 2020-06-05 17:56 - 000003116 _____ C:\Windows\system32\Tasks\AMDInstallLauncher

==================== Um mês (modificados) ==================

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2020-06-05 19:32 - 2019-10-05 20:12 - 000000000 ____D C:\Users\Todos os Usuários\AVAST Software
2020-06-05 19:32 - 2019-10-05 20:12 - 000000000 ____D C:\ProgramData\AVAST Software
2020-06-05 18:34 - 2019-10-11 23:33 - 000000000 ____D C:\Users\Murilo\AppData\Local\ElevatedDiagnostics
2020-06-05 18:12 - 2019-10-05 20:53 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2020-06-05 18:11 - 2019-10-06 15:40 - 000000000 ____D C:\Users\Murilo\AppData\Roaming\Discord
2020-06-05 18:06 - 2009-07-14 01:45 - 000026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-06-05 18:06 - 2009-07-14 01:45 - 000026544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-06-05 18:05 - 2020-02-15 13:39 - 000000079 _____ C:\Windows\directx.sys
2020-06-05 18:02 - 2019-12-23 17:00 - 000000000 ____D C:\Users\Murilo\AppData\Local\CrashDumps
2020-06-05 17:55 - 2009-07-14 02:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-05 13:48 - 2019-10-05 20:50 - 000007625 _____ C:\Users\Murilo\AppData\Local\Resmon.ResmonCfg
2020-06-04 19:40 - 2010-11-21 06:37 - 000706108 _____ C:\Windows\system32\prfh0416.dat
2020-06-04 19:40 - 2010-11-21 06:37 - 000147446 _____ C:\Windows\system32\prfc0416.dat
2020-06-04 19:40 - 2009-07-14 02:13 - 001636956 _____ C:\Windows\system32\PerfStringBackup.INI
2020-06-04 19:40 - 2009-07-14 00:20 - 000000000 ____D C:\Windows\inf
2020-06-04 18:06 - 2020-03-11 14:35 - 000000000 ____D C:\Users\Murilo\AppData\Local\Discord

==================== Arquivos na raiz de alguns diretórios ========

2019-10-05 20:50 - 2020-06-05 13:48 - 000007625 _____ () C:\Users\Murilo\AppData\Local\Resmon.ResmonCfg
2019-10-08 20:04 - 2019-10-08 20:04 - 000000003 _____ () C:\Users\Murilo\AppData\Local\updater.log
2019-10-08 20:04 - 2019-10-08 20:04 - 000000424 _____ () C:\Users\Murilo\AppData\Local\UserProducts.xml

==================== SigCheck ============================

(Não há correção automática para arquivos que não passaram na verificação.)


LastRegBack: 2020-03-11 14:15
==================== Fim de FRST.txt ========================
 
Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 04-06-2020
Executado por Murilo (05-06-2020 19:33:45)
Executando a partir de C:\Users\Murilo\Desktop\Downloads
Windows 7 Ultimate Service Pack 1 (X64) (2019-10-05 22:08:42)
Modo da Inicialização: Safe Mode (with Networking)
==========================================================


==================== Contas: =============================

Administrador (S-1-5-21-2095121090-2903240913-2782640044-500 - Administrator - Disabled)
Convidado (S-1-5-21-2095121090-2903240913-2782640044-501 - Limited - Disabled)
Murilo (S-1-5-21-2095121090-2903240913-2782640044-1000 - Administrator - Enabled) => C:\Users\Murilo

==================== Central de Segurança ========================

(Se uma entrada for incluída na fixlist, será removida.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas Instalados ======================

(Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.)

ACP Application (HKLM\...\{EB371F79-8A61-430A-BDCF-866B73F524A5}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden
Age of Empires III - The Asian Dynasties (HKLM-x32\...\{C43C1415-3DFC-4089-9A32-0BECF28A6046}) (Version: 1.00.0000 - Microsoft Game Studios) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 20.2.1 - Advanced Micro Devices, Inc.)
Branding64 (HKLM\...\{133E6274-9FD4-4ABD-80A8-2A954E89EAD6}) (Version: 1.00.0002 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform)
DriverUpdate (HKLM\...\{D7FB714F-E3D0-4C5C-BA88-A55211EA5CD7}) (Version: 5.8.8 - Slimware Utilities Holdings, Inc.) Hidden <==== ATENÇÃO
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.97 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Java 8 Update 241 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7464 - Realtek Semiconductor Corp.)
Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.9.5.1 - Reimage) <==== ATENÇÃO
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)

==================== Exame Personalizado CLSID (Whitelisted): ==============

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-03-11] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-03-11] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Atalhos & WMI ========================

(As entradas podem ser listadas para serem restauradas ou removidas.)

WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]

==================== Módulos Carregados (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

(Se uma entrada for incluída na fixlist, somente o ADS será removido.)

AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [180]
AlternateDataStreams: C:\Windows\System32:tdsrset.gfc [5846]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [180]
AlternateDataStreams: C:\Users\Murilo:Heroes & Generals [38]
AlternateDataStreams: C:\Users\Todos os Usuários:NT [40]
AlternateDataStreams: C:\Users\Todos os Usuários:NT2 [180]
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [180]
AlternateDataStreams: C:\ProgramData\Dados de aplicativos:NT [40]
AlternateDataStreams: C:\ProgramData\Dados de aplicativos:NT2 [180]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [180]
AlternateDataStreams: C:\Users\Murilo\Dados de aplicativos:33968ec9ed0abde4ce703a532c809fc9 [394]
AlternateDataStreams: C:\Users\Murilo\Dados de aplicativos:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
AlternateDataStreams: C:\Users\Murilo\Dados de aplicativos:NT [40]
AlternateDataStreams: C:\Users\Murilo\Dados de aplicativos:NT2 [180]
AlternateDataStreams: C:\Users\Murilo\AppData\Roaming:33968ec9ed0abde4ce703a532c809fc9 [394]
AlternateDataStreams: C:\Users\Murilo\AppData\Roaming:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
AlternateDataStreams: C:\Users\Murilo\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\Murilo\AppData\Roaming:NT2 [180]
AlternateDataStreams: C:\Users\Todos os Usuários\Application Data:NT [40]
AlternateDataStreams: C:\Users\Todos os Usuários\Application Data:NT2 [180]
AlternateDataStreams: C:\Users\Todos os Usuários\Dados de aplicativos:NT [40]
AlternateDataStreams: C:\Users\Todos os Usuários\Dados de aplicativos:NT2 [180]
AlternateDataStreams: C:\Users\Todos os Usuários\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\Users\Todos os Usuários\MTA San Andreas All:NT2 [180]

==================== Modo de Segurança (Whitelisted) ==================

(Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Associação (Whitelisted) =================

==================== Internet Explorer confiável/restrito ==========

==================== Hosts Conteúdo: =========================

(Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.)

2009-07-13 23:34 - 2009-06-10 18:00 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Outras Áreas ===========================

(Atualmente não há nenhuma correção automática para esta seção.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
HKU\S-1-5-21-2095121090-2903240913-2782640044-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Murilo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 189.45.192.3 - 177.200.200.20
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Firewall do Windows está habilitado.

==================== MSCONFIG/TASK MANAGER ítens desabilitados ==

(Se uma entrada for incluída na fixlist, será removida.)

MSCONFIG\Services: BEService => 3
MSCONFIG\Services: Disc Soft Lite Bus Service => 3
MSCONFIG\Services: EasyAntiCheat => 3
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 3
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: Origin Client Service => 3
MSCONFIG\Services: Origin Web Helper Service => 2
MSCONFIG\Services: QMEmulatorService => 2
MSCONFIG\Services: Rockstar Service => 3
MSCONFIG\Services: SlimWareServices => 3
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: TeamViewer => 2
MSCONFIG\Services: uncheater_bgl => 3
MSCONFIG\startupfolder: C:^Users^Murilo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GameRanger.lnk => C:\Windows\pss\GameRanger.lnk.Startup
MSCONFIG\startupreg: CCleaner Smart Cleaning => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\PROGRA~1\DAEMON~1\DTLite.exe" -autorun
MSCONFIG\startupreg: Discord => C:\Users\Murilo\AppData\Local\Discord\app-0.0.306\Discord.exe
MSCONFIG\startupreg: DriverUpdate => "C:\Program Files\DriverUpdate\DriverUpdate.exe" -boot
MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: EpicGamesLauncher => "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
MSCONFIG\startupreg: IAStorIcon => "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: Lightshot => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Spotify => C:\Users\Murilo\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: uTorrent => "C:\Users\Murilo\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED

==================== Regras do Firewall (Whitelisted) ================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

FirewallRules: [{AC6CB7E5-D039-4F80-876A-77DDEB5E8A9F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Pontos de Restauração =========================

05-04-2020 20:58:51 Backup do Windows
12-04-2020 20:31:17 Windows Update
12-04-2020 20:37:47 Windows Update
12-04-2020 20:49:17 Backup do Windows
12-04-2020 21:40:55 DriverPack 17.11.28
19-04-2020 20:38:28 Backup do Windows
26-04-2020 20:06:49 Backup do Windows
04-05-2020 14:04:57 Backup do Windows
11-05-2020 13:25:06 Backup do Windows
17-05-2020 21:10:40 Backup do Windows
25-05-2020 12:51:35 Backup do Windows
01-06-2020 13:53:37 Backup do Windows

==================== Dispositivos Apresentando Falhas No Gerenciador ============

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Erros no Log de eventos: ========================

Erros em Aplicativos:
==================
Error: (06/05/2020 06:14:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (06/05/2020 06:01:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome de aplicativo com falha: jucheck.exe, versão: 2.8.241.7, carimbo de hora: 0x5df0d8ad
Nome do módulo de falhas: jucheck.exe, versão: 2.8.241.7, carimbo de hora: 0x5df0d8ad
Código de exceção: 0xc0000005
Deslocamento com falha: 0x000038f5
Identificação do processo com falha: 0xad4
Hora de início do aplicativo com falha: 0x01d63b7c8982406d
Caminho do aplicativo com falha: C:\Users\Murilo\AppData\Local\Temp\3582-490\jucheck.exe
FCaminho do módulo de falhas: C:\Users\Murilo\AppData\Local\Temp\3582-490\jucheck.exe
Identificação do Relatório: c7cc55c4-a76f-11ea-806d-902b34f8ee2f

Error: (06/05/2020 06:01:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome de aplicativo com falha: mbamtray.exe, versão: 4.0.0.666, carimbo de hora: 0x5ebed6d2
Nome do módulo de falhas: Qt5Core.dll, versão: 5.14.1.0, carimbo de hora: 0x5e8272e4
Código de exceção: 0xc0000005
Deslocamento com falha: 0x0000000000219d05
Identificação do processo com falha: 0xa54
Hora de início do aplicativo com falha: 0x01d63b7bc23e5aef
Caminho do aplicativo com falha: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
FCaminho do módulo de falhas: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
Identificação do Relatório: b0985bea-a76f-11ea-806d-902b34f8ee2f

Error: (06/05/2020 05:57:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (06/05/2020 05:44:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome de aplicativo com falha: jucheck.exe, versão: 2.8.241.7, carimbo de hora: 0x5df0d8ad
Nome do módulo de falhas: jucheck.exe, versão: 2.8.241.7, carimbo de hora: 0x5df0d8ad
Código de exceção: 0xc0000005
Deslocamento com falha: 0x000038f5
Identificação do processo com falha: 0x1274
Hora de início do aplicativo com falha: 0x01d63b7a247f84a8
Caminho do aplicativo com falha: C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jucheck.exe
FCaminho do módulo de falhas: C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jucheck.exe
Identificação do Relatório: 64d0bc3a-a76d-11ea-aa18-902b34f8ee2f

Error: (06/05/2020 05:40:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (06/05/2020 02:26:33 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: Um problema impediu que os dados do Programa de Aperfeiçoamento da Experiência do Usuário fossem enviados para a Microsoft, (Erro 80004005).

Error: (06/05/2020 01:46:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome de aplicativo com falha: jucheck.exe, versão: 2.8.241.7, carimbo de hora: 0x5df0d8ad
Nome do módulo de falhas: jucheck.exe, versão: 2.8.241.7, carimbo de hora: 0x5df0d8ad
Código de exceção: 0xc0000005
Deslocamento com falha: 0x000038f5
Identificação do processo com falha: 0xb7c
Hora de início do aplicativo com falha: 0x01d63b58e43e4903
Caminho do aplicativo com falha: C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jucheck.exe
FCaminho do módulo de falhas: C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jucheck.exe
Identificação do Relatório: 28c1a13f-a74c-11ea-82ec-902b34f8ee2f


Erros de Sistema:
=============
Error: (06/05/2020 07:30:16 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: O DCOM obteve o erro "1084" ao tentar iniciar o serviço VSS com argumentos "" para executar o servidor:
{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}

Error: (06/05/2020 06:25:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: O serviço Pesquisador de Computadores depende do serviço Server, mas não foi possível iniciá-lo devido ao seguinte erro:
Não foi possível iniciar o serviço ou grupo de dependência.

Error: (06/05/2020 06:25:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: O serviço Pesquisador de Computadores depende do serviço Server, mas não foi possível iniciá-lo devido ao seguinte erro:
Não foi possível iniciar o serviço ou grupo de dependência.

Error: (06/05/2020 06:25:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: O serviço Pesquisador de Computadores depende do serviço Server, mas não foi possível iniciá-lo devido ao seguinte erro:
Não foi possível iniciar o serviço ou grupo de dependência.

Error: (06/05/2020 06:25:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: O serviço Pesquisador de Computadores depende do serviço Server, mas não foi possível iniciá-lo devido ao seguinte erro:
Não foi possível iniciar o serviço ou grupo de dependência.

Error: (06/05/2020 06:25:30 PM) (Source: Schannel) (EventID: 4119) (User: AUTORIDADE NT)
Description: O seguinte alerta fatal foi recebido: 40.

Error: (06/05/2020 06:25:30 PM) (Source: Schannel) (EventID: 4119) (User: AUTORIDADE NT)
Description: O seguinte alerta fatal foi recebido: 70.

Error: (06/05/2020 06:25:30 PM) (Source: Schannel) (EventID: 4119) (User: AUTORIDADE NT)
Description: O seguinte alerta fatal foi recebido: 40.


Windows Defender:
===================================
Date: 2020-02-23 01:17:27.714
Description:
Digitalização de Windows Defender interrompida antes da conclusão.
ID da Digitalização:{13B6E2C8-E7FD-4503-94B7-CE364927CC91}
Tipo da Digitalização:Anti-spyware
Parâmetros da Digitalização:Verificação Rápida
Usuário:Murilo-PC\Murilo

Date: 2019-11-29 21:17:25.744
Description:
Digitalização de Windows Defender interrompida antes da conclusão.
ID da Digitalização:{C1CBA55B-0C74-4444-A1EC-C6FA9AF8EE87}
Tipo da Digitalização:Anti-spyware
Parâmetros da Digitalização:Verificação Rápida
Usuário:Murilo-PC\Murilo

Date: 2020-02-27 16:30:35.390
Description:
Windows Defender encontrou um erro ao tentar atualizar o mecanismo.
Versão do Mecanismo Novo:1.1.16800.2
Versão do Mecanismo Anterior:1.1.6402.0
Origem da Atualização:Usuário
Usuário:AUTORIDADE NT\SISTEMA
Código de Erro:0x8050800c
Descrição do erro:problema inesperado. Instale todas as atualizações disponíveis e tente iniciar o programa novamente. Para obter informações sobre como instalar atualizações, consulte Ajuda e Suporte.

Date: 2019-10-22 19:10:34.065
Description:
Windows Defender encontrou um erro ao atualizar assinaturas.
Versão da Nova Assinatura:1.305.400.0
Versão da Assinatura Anterior:1.95.191.0
Origem da Atualização:Usuário
Tipo de Assinatura:Anti-spyware
Tipo de Atualização:Completa
Usuário:AUTORIDADE NT\SERVIÇO DE REDE
Versão do Mecanismo Atual:1.1.16500.1
Versão do Mecanismo Anterior:1.1.6402.0
Código de erro:0x8050a005
Descrição do erro:O programa não pode localizar arquivos de definição que ajudam a detectar software indesejado. Verifique se há atualizações de arquivos de definição e tente novamente. Para obter informações sobre como instalar atualizações, consulte Ajuda e Suporte.

Date: 2019-10-22 19:10:34.065
Description:
Windows Defender encontrou um erro ao tentar atualizar o mecanismo.
Versão do Mecanismo Novo:1.1.16500.1
Versão do Mecanismo Anterior:1.1.6402.0
Origem da Atualização:Usuário
Usuário:AUTORIDADE NT\SERVIÇO DE REDE
Código de Erro:0x8050a005
Descrição do erro:O programa não pode localizar arquivos de definição que ajudam a detectar software indesejado. Verifique se há atualizações de arquivos de definição e tente novamente. Para obter informações sobre como instalar atualizações, consulte Ajuda e Suporte.

Date: 2019-10-22 19:10:33.103
Description:
Windows Defender encontrou um erro ao atualizar assinaturas.
Versão da Nova Assinatura:1.305.400.0
Versão da Assinatura Anterior:1.95.191.0
Origem da Atualização:Usuário
Tipo de Assinatura:Anti-spyware
Tipo de Atualização:Completa
Usuário:AUTORIDADE NT\SERVIÇO DE REDE
Versão do Mecanismo Atual:1.1.16500.1
Versão do Mecanismo Anterior:1.1.6402.0
Código de erro:0x8050a005
Descrição do erro:O programa não pode localizar arquivos de definição que ajudam a detectar software indesejado. Verifique se há atualizações de arquivos de definição e tente novamente. Para obter informações sobre como instalar atualizações, consulte Ajuda e Suporte.

Date: 2019-10-22 19:10:33.102
Description:
Windows Defender encontrou um erro ao tentar atualizar o mecanismo.
Versão do Mecanismo Novo:1.1.16500.1
Versão do Mecanismo Anterior:1.1.6402.0
Origem da Atualização:Usuário
Usuário:AUTORIDADE NT\SERVIÇO DE REDE
Código de Erro:0x8050a005
Descrição do erro:O programa não pode localizar arquivos de definição que ajudam a detectar software indesejado. Verifique se há atualizações de arquivos de definição e tente novamente. Para obter informações sobre como instalar atualizações, consulte Ajuda e Suporte.

CodeIntegrity:
===================================

Date: 2020-04-12 20:26:50.658
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-12 20:26:50.658
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-10 13:36:08.674
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-10 13:36:08.658
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-05 20:46:09.483
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-05 20:46:09.483
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-01 13:37:40.490
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-04-01 13:37:40.490
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Informações da Memória ===========================

BIOS: American Megatrends Inc. F5 MW 08/28/2012
placa-mãe: MEGAWARE MW-H61M-2H
Processador: Intel(R) Core(TM) i3-3240 CPU @ 3.40GHz
Percentagem de memória em uso: 96%
RAM física total: 4059.85 MB
RAM física disponível: 128.3 MB
Virtual Total: 8117.88 MB
Virtual disponível: 3981.87 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:395.9 GB) NTFS
Drive e: (LAZESOFT) (Removable) (Total:3.65 GB) (Free:3.64 GB) FAT32

\\?\Volume{5a83d2c5-e7bb-11e9-9005-806e6f6e6963}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Tabela de Partições ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 6478A865)
Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0B)

==================== Fim de Addition.txt =======================
 
1. Uninstall following unwanted programs:

DriverUpdate
Reimage Repair


2. Install some antivirus program like Avast.

3. Re-run FRST in normal mode and post new logs.
 
Hello Broni!
I'm sorry for not replying

I don't need any more help because I ended up formatting the PC with anxiety, but I thank you for your work and dedication, anything that comes here (Ps): With that I learned new things about windows, how to format the PC, update drivers, use programs, thank you. <3
 
Back