Segue o FIXLOG
Resultado da Correção pela Farbar Recovery Scan Tool (x64) Versão: 28-08-2023
Executado por renan (30-08-2023 16:38:32) Run:4
Executando a partir de C:\Users\renan\OneDrive\Área de Trabalho
Perfis Carregados: renan
Modo da Inicialização: Normal
==============================================
fixlist Conteúdo:
*****************
Start::
CloseProcesses:
SearchScopes: HKU\S-1-5-21-928680254-1069769107-2511021147-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-928680254-1069769107-2511021147-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
AlternateDataStreams: C:\ProgramData:YXVtLmh6aQ
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wsddfac.sys:X5ZN8aDXs4
AlternateDataStreams: C:\Users\All Users:YXVtLmh6aQ
AlternateDataStreams: C:\Users\Todos os Usuários:YXVtLmh6aQ
AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:YXVtLmh6aQ
C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2070_none_6ec11d2a87fe200c.manifest.
HKLM\...\RunOnce: => C:\WINDOWS\Temp\MUBSTemp\BGAUpsell.EXE (Microsoft Corporation -> Microsoft Corporation) <==== ATENÇÃO
HKU\S-1-5-21-928680254-1069769107-2511021147-1001\...\RunOnce: => C:\Windows\Temp\MUBSTemp\BGAUpsell.exe (Microsoft Corporation -> Microsoft Corporation) <==== ATENÇÃO
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (Nenhum Arquivo)
Task: {5AF97E4C-2387-4713-84ED-C7931361E9F9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (Nenhum Arquivo)
Task: {DFF788D7-2647-4C8F-AB73-DE699655D8B8} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (Nenhum Arquivo)
Task: {0B598B54-5497-43B7-A5C3-7721A589DF4A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC ReadyToReboot (Nenhum Arquivo)
Task: {8EEE7A94-D3AC-4C70-909B-F8499BCF6574} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Nenhum Arquivo)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Nenhum Arquivo)
Task: {D87F59B4-CC85-460F-B353-22B9B8FBA8C3} - System32\Tasks\SecurityScannerScheduler => C:\Program Files (x86)\McAfee Security Scan\4.1.375\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
R3 ALSysIO; C:\Users\renan\AppData\Local\Temp\ALSysIO64.sys (ALCPU (Arthur Liberman) -> Arthur Liberman) <==== ATENÇÃO
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys
StartPowershell:
DISM /Online /Cleanup-image /Restorehealth
EndPowershell:
CreateRestorePoint:
EmptyTemp:
Reboot:
Hosts:
end::
*****************
Processos fechados com sucesso.
"HKU\S-1-5-21-928680254-1069769107-2511021147-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removido (a) com sucesso.
HKU\S-1-5-21-928680254-1069769107-2511021147-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removido (a) com sucesso.
C:\ProgramData => "AlternateDataStreams: C:\ProgramData:YXVtLmh6aQ" ADS Não pode ser removido.
C:\WINDOWS\system32\Drivers\wsddfac.sys => "AlternateDataStreams: C:\WINDOWS\system32\Drivers\wsddfac.sys:X5ZN8aDXs4" ADS Não pode ser removido.
C:\Users\All Users => "AlternateDataStreams: C:\Users\All Users:YXVtLmh6aQ" ADS Não pode ser removido.
"C:\Users\Todos os Usuários" => "AlternateDataStreams: C:\Users\Todos os Usuários:YXVtLmh6aQ" ADS não encontrado (a).
C:\ProgramData\Dados de Aplicativos => "AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:YXVtLmh6aQ" ADS Não pode ser removido.
"C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2070_none_6ec11d2a87fe200c.manifest." => não encontrado (a)
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKLM\...\RunOnce: => C:\WINDOWS\Temp\MUBSTemp\BGAUpsell.EXE (Microsoft Corporation -> Microsoft Corporation) <==== ATENÇÃO" => não encontrado (a)
"HKU\S-1-5-21-928680254-1069769107-2511021147-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\S-1-5-21-928680254-1069769107-2511021147-1001\...\RunOnce: => C:\Windows\Temp\MUBSTemp\BGAUpsell.exe (Microsoft Corporation -> Microsoft Corporation) <==== ATENÇÃO" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5AF97E4C-2387-4713-84ED-C7931361E9F9}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5AF97E4C-2387-4713-84ED-C7931361E9F9}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DFF788D7-2647-4C8F-AB73-DE699655D8B8}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFF788D7-2647-4C8F-AB73-DE699655D8B8}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0B598B54-5497-43B7-A5C3-7721A589DF4A}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B598B54-5497-43B7-A5C3-7721A589DF4A}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8EEE7A94-D3AC-4C70-909B-F8499BCF6574}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EEE7A94-D3AC-4C70-909B-F8499BCF6574}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => movido com sucesso
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removido (a) com sucesso.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D87F59B4-CC85-460F-B353-22B9B8FBA8C3}" => não encontrado (a)
"C:\WINDOWS\System32\Tasks\SecurityScannerScheduler" => não encontrado (a)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SecurityScannerScheduler" => não encontrado (a)
ALSysIO => Serviço finalizado com sucesso.
HKLM\System\CurrentControlSet\Services\ALSysIO => removido (a) com sucesso.
ALSysIO => o serviço removido (a) com sucesso.
HKLM\System\CurrentControlSet\Services\WinSetupMon => removido (a) com sucesso.
WinSetupMon => o serviço removido (a) com sucesso.
========= Powershell: =========
Ferramenta de Gerenciamento e Manutenção de Imagens de Implantação
Versão: 10.0.22621.1
Versão da Imagem: 10.0.22621.2134
{== 3.8% }
{== 4.2% }
{== 5.1% }
{=== 5.5% }
{=== 6.1% }
{==== 7.1% }
{==== 7.8% }
{===== 8.8% }
{===== 9.8% }
{====== 10.8% }
{====== 11.5% }
{======= 12.5% }
{======= 13.4% }
{======== 14.4% }
{======== 15.4% }
{========= 16.4% }
{========= 17.2% }
{========== 17.6% }
{========== 18.2% }
{========== 18.6% }
{========== 18.6% }
{========== 18.8% }
{=========== 19.8% }
{============ 20.8% }
{============ 21.7% }
{============= 22.7% }
{============= 23.4% }
{============== 24.4% }
{============== 25.4% }
{=============== 26.3% }
{=============== 27.3% }
{================ 28.3% }
{================ 29.3% }
{================= 30.3% }
{================== 31.2% }
{================== 31.8% }
{================== 32.2% }
{================== 32.3% }
{================== 32.8% }
{=================== 33.0% }
{=================== 33.4% }
{=================== 33.4% }
{=================== 34.4% }
{==================== 35.4% }
{===================== 36.4% }
{===================== 37.1% }
{===================== 37.4% }
{====================== 38.0% }
{====================== 38.6% }
{====================== 39.2% }
{======================= 40.1% }
{======================= 41.0% }
{======================== 42.0% }
{======================== 42.9% }
{========================= 43.9% }
{========================== 44.9% }
{========================== 45.9% }
{===========================46.9% }
{===========================47.8% }
{===========================48.8% }
{===========================49.8% }
{===========================50.8% }
{===========================51.8% }
{===========================52.2% }
{===========================52.3% }
{===========================52.3% }
{===========================52.4% }
{===========================52.5% }
{===========================52.6% }
{===========================52.7% }
{===========================52.8% }
{===========================52.8% }
{===========================52.8% }
{===========================52.9% }
{===========================53.0% }
{===========================53.0% }
{===========================53.1% }
{===========================53.1% }
{===========================53.1% }
{===========================53.2% }
{===========================53.2% }
{===========================53.4% }
{===========================53.4% }
{===========================53.5% }
{===========================53.5% }
{===========================53.6% }
{===========================53.7% }
{===========================53.8% }
{===========================54.0% }
{===========================54.1% }
{===========================54.1% }
{===========================54.2% }
{===========================54.3% }
{===========================54.3% }
{===========================54.3% }
{===========================54.3% }
{===========================54.4% }
{===========================54.5% }
{===========================54.5% }
{===========================54.6% }
{===========================54.6% }
{===========================54.6% }
{===========================54.6% }
{===========================54.6% }
{===========================54.7% }
{===========================54.8% }
{===========================54.8% }
{===========================54.9% }
{===========================54.9% }
{===========================54.9% }
{===========================55.0% }
{===========================55.1% }
{===========================55.2% }
{===========================55.4% }
{===========================55.5% }
{===========================55.6% }
{===========================55.7% }
{===========================55.8% }
{===========================55.8% }
{===========================55.9% }
{===========================56.2% }
{===========================56.2% }
{===========================56.2% }
{===========================56.5% }
{===========================57.5%= }
{===========================58.5%= }
{===========================59.1%== }
{===========================59.1%== }
{===========================60.1%== }
{===========================62.3%==== }
{===========================84.9%================= }
{==========================100.0%==========================}
Operação de restauração concluída com êxito.
A operação foi concluída com êxito.
========= Fim de Powershell: =========
Ponto de Restauração criado com sucesso.
C:\Windows\System32\Drivers\etc\hosts => movido com sucesso
Hosts restaurado com sucesso.
=========== EmptyTemp: ==========
FlushDNS => completado
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 49853813 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 29679951 B
Edge => 0 B
Chrome => 1522041525 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 513006 B
systemprofile32 => 513006 B
LocalService => 569348 B
NetworkService => 704954 B
renan => 196728477 B
RecycleBin => 1148564330 B
EmptyTemp: => 2.7 GB de dados temporários Removidos.
================================
O sistema precisou ser reiniciado.
==== Fim de Fixlog 16:43:06 ====