/!\ Boa Noite! Marc2008 /!\
> Copie estas informações que estão em destaque,para o Bloco de Notas.
> Começa em "Start" e termina em "End".
> Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite!
> Salve-as ao desktop! ( Área de trabalho ... )
start::
CloseProcesses:
Task: {147EA221-1E41-46E6-8975-EDC47B5C303E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Nenhum Arquivo <==== ATENÇÃO
Task: {27FD38BF-F084-4C0B-B0EB-55172C889968} - \Lenovo\ImController\Lenovo iM Controller Monitor -> Nenhum Arquivo <==== ATENÇÃO
Task: {5C92DBED-1E7A-4F3F-BCB0-BD47B89DEC0B} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> Nenhum Arquivo <==== ATENÇÃO
Task: {617FCE02-B511-4C01-8EDA-8B49B135E580} - não caminho do arquivo. <==== ATENÇÃO
Task: {677519A0-88C1-4F73-8FE2-705A2682C9A4} - \Microsoft\Windows\UNP\RunCampaignManager -> Nenhum Arquivo <==== ATENÇÃO
Task: {AE4D08F2-98CA-46A5-9DB6-B427C6EB29E7} - não caminho do arquivo. <==== ATENÇÃO
Task: {CD7B0C0D-6225-4437-B55E-65986E71D82D} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> Nenhum Arquivo <==== ATENÇÃO
Task: {E1884E4C-6D72-4AB5-AE0D-5717842F0E27} - não caminho do arquivo. <==== ATENÇÃO
Task: {F3ABF62A-84BF-4150-B84F-740F11BE971B} - System32\Tasks\CyberLink\Photo Master Gadget startup => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMasterWorker.exe backgroundagent (Nenhum Arquivo)
Task: {66E7E0E2-F7EE-4A28-A8B6-C40C33F92154} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Marcbon2008\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe LOGON (Nenhum Arquivo)
Task: {D090C198-6C9C-4D1C-A0EA-69D7340FDF69} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Marcbon2008\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe SCHED (Nenhum Arquivo)
Task: {F3ABF62A-84BF-4150-B84F-740F11BE971B} - System32\Tasks\CyberLink\Photo Master Gadget startup => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMasterWorker.exe backgroundagent (Nenhum Arquivo)
Task: {66E7E0E2-F7EE-4A28-A8B6-C40C33F92154} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Marcbon2008\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe LOGON (Nenhum Arquivo)
Task: {D090C198-6C9C-4D1C-A0EA-69D7340FDF69} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Marcbon2008\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe SCHED (Nenhum Arquivo)
Task: {3AA160E3-E5E5-4293-A200-9E7400B05784} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.UpdateStatusService.exe UpdateStatus (Nenhum Arquivo)
Task: {03D627D0-09D1-4429-A10D-7719BA8DFA3C} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe /show (Nenhum Arquivo)
Task: {4E4CB35D-3363-4DEC-8344-D4A6B0566F2C} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => "C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe" -diag HWScan (Nenhum Arquivo)
Task: {D1CB85C3-535B-4F43-B411-ADF55A295308} - System32\Tasks\Lenovo\REACHit Agent Startup => "C:\Program Files (x86)\Lenovo\REACHit\REACHitAgent.exe" /nobrowser (Nenhum Arquivo)
Task: {1175024D-AC6A-45BC-B015-23841B052CD7} - System32\Tasks\Lenovo\REACHit Agent Update => "C:\Program Files (x86)\Lenovo\REACHit\REACHitAgent.exe" -update (Nenhum Arquivo)
Task: {F760854E-11CF-4E3A-B507-6FDDBCE78F32} - System32\Tasks\Microsoft\Windows\rempl\shell => %ProgramFiles%\rempl\sedlauncher.exe (Nenhum Arquivo)
Task: {0EDCD359-5E10-4723-97F2-B063BAB2865F} - System32\Tasks\Rerun Warsaw's CoreFixer => C:\WINDOWS\TEMP\is-IPQM7.tmp\corefixer.exe /norerun (Nenhum Arquivo) <==== ATENÇÃO
Task: {A7F733D9-1BDF-4515-A85A-044066350063} - System32\Tasks\TVT\TVSUUpdateTask => "C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe" /CM -search R -action INSTALL -includerebootpackages 1,3,4,5 -noicon -noreboot -nolicense -defaultupdate -schtask (Nenhum Arquivo)
Task: {563F8E3E-B8B3-4839-B3C0-85466B5AA836} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => "C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe" PendingTask (Nenhum Arquivo)
Task: {7F59B877-D970-4ED5-BAB4-820C58605A4C} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "4ecdd687-3d53-420c-a047-d1adc196f6f9" --version "6.18.10838" --silent
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrição <==== ATENÇÃO
HKU\S-1-5-21-3961797726-2345694949-454076703-1001\...\Run: [BlueMail] => C:\WINDOWS\explorer.exe me.blueone.win:noopt:hidden (Nenhum Arquivo) <==== ATENÇÃO
HKU\S-1-5-21-3961797726-2345694949-454076703-1001\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-default-browser-check --no-displaying-insecure-content --no-first-run --user-data-dir="C:\ProgramData\Kaspersky Lab\SafeBrowser\Common (a entrada de dados tem 77 mais caracteres). [2680608 2023-11-27] (Google LLC -> Google LLC)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ContextMenuHandlers1: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> Nenhum Arquivo
ContextMenuHandlers4: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> Nenhum Arquivo
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo
AlternateDataStreams: C:\ProgramData:chnpbmzkyg [370]
AlternateDataStreams: C:\ProgramData:YXVtLmh6aQ [5426]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wsddfac.sys:X5ZN8aDXs4 [3506]
AlternateDataStreams: C:\Users\All Users:chnpbmzkyg [370]
AlternateDataStreams: C:\Users\All Users:YXVtLmh6aQ [5426]
AlternateDataStreams: C:\Users\Todos os Usuários:chnpbmzkyg [370]
AlternateDataStreams: C:\Users\Todos os Usuários:YXVtLmh6aQ [5426]
AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:chnpbmzkyg [370]
AlternateDataStreams: C:\ProgramData\Dados de Aplicativos:YXVtLmh6aQ [5426]
Toolbar: HKLM - Sem Nome - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - Nenhum Arquivo
2016-09-15 18:08 - 2016-08-25 06:22 - 002685216 _____ (COMODO) C:\Users\Marcbon2008\AppData\Roaming\temp~ccavstart.exe
StartPowershell:
DISM /Online /Cleanup-image /Restorehealth
sfc /scannow
EndPowershell:
CreateRestorePoint:
EmptyTemp:
Reboot:
Hosts:
end::

> Execute FRST/FRST64
> Clique "Corrigir" < Aguarde!
> Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool". (Fixlog.txt)
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! >
A+