W logu widac sporo bledow:
Error: (10/05/2017 05:17:04 PM) (Source: ESENT) (EventID: 476) (User: )
Description: svchost (10112) Unistore: Weryfikacja odczytu strony bazy danych z pliku „C:\Users\zwn\AppData\Local\Comms\UnistoreDB\store.vol” na pozycji względnej 53346304 (0x00000000032e0000) (strona bazy danych: 13023 (0x32DF)) dla 4096 (0x00001000) bajtów nie powiodła się z powodu braku danych strony. Operacja odczytu zostanie zakończona z błędem -1019 (0xfffffc05). Jeśli ten stan będzie się utrzymywał, przywróć bazę danych z wcześniejszej kopii zapasowej. Ten problem jest prawdopodobnie spowodowany wadliwym sprzętem. Skontaktuj się z dostawcą sprzętu, aby uzyskać dalszą pomoc w diagnozowaniu problemu.
Plik C:\Users\zwn\AppData\Local\Comms\UnistoreDB\store.vol dodam do kasacji.
Odinstaluj Kasperskiego, z tego co widac w logach to nie dziala poprawnie.
Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
Task: {1D18800E-D0E7-4374-8389-FB372507567E} - System32\Tasks\WinThruster64-zwn-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe [2015-10-01] (Solvusoft Corporation) <==== UWAGA
Task: {2459093A-ECB6-4C4C-BF27-8009D7BEAB8B} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-05-24] ()
Task: {294707EA-F518-44DE-9D7C-45F2BFCAB1F9} - System32\Tasks\Opera scheduled Autoupdate 1457443830 => C:\Program Files (x86)\Opera\launcher.exe [2017-10-02] (Opera Software)
Task: {35199837-E441-4F4A-B5A1-25DD9EB951A4} - System32\Tasks\SoftwareInformerService => C:\Program Files\Software Informer\softinfo.exe [2015-06-26] (Informer Technologies, Inc.)
Task: {429B1750-1E7F-4F49-B1B6-8E9B3F915B17} - System32\Tasks\{4E9DDFD9-2949-4B6A-94B0-7588B15E15D8} => "c:\program files\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/6.3.73.105.457/pl/go/help.faq.installer?LastError=1603
Task: {4333F4B3-C4AF-43F9-A3CA-CE3781E8875F} - System32\Tasks\ASCTaskASC => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {84BE1EFB-8608-4E06-8D56-3A03F74B4144} - System32\Tasks\{5A2E8BEC-DD43-4704-8BB9-300CD0F1002A} => C:\Windows\system32\pcalua.exe -a "E:\Gry\Battlefield 1942\BF1942.exe" -d "E:\Gry\Battlefield 1942"
Task: {8C472DFB-CB39-4818-AD86-236F643A8E3D} - System32\Tasks\ASCU10_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe [2016-12-14] (IObit)
Task: {98527351-A22F-45DC-BD73-B78F716AC633} - System32\Tasks\ASCU10_SkipUac_zwn => C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASC.exe [2017-06-05] (IObit)
Task: {A8475453-6807-49A8-A61C-BF12CDCB05E6} - System32\Tasks\Driver Booster SkipUAC (zwn) => C:\Program Files (x86)\IObit\Driver Booster\5.0.3\DriverBooster.exe
Task: {CDACE7F9-5422-4A5E-805A-C404B0372855} - System32\Tasks\{40100D15-52A6-418F-B5A0-FB63B32C7C5D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Maxis\SimCity 4\Apps\SimCity 4.exe" -d "C:\Program Files (x86)\Maxis\SimCity 4"
Task: {DB7F6E46-E82B-4F9C-9E10-44A55C2539EB} - System32\Tasks\{B0155A39-159C-4E2C-ADFC-AC2B980A774F} => C:\Windows\system32\pcalua.exe -a C:\Users\zwn\Downloads\SE_Free_2D_POLISH_ST8.exe -d C:\Users\zwn\Downloads
Task: {E93BC34A-1CFF-4702-9395-3A0298A4AD8D} - System32\Tasks\{D5ADA104-9E55-4002-BC93-CBB0E7D4C3BB} => C:\Windows\system32\pcalua.exe -a "E:\Gry\SimCity 4\Apps\SimCity 4.exe" -d "E:\Gry\SimCity 4"
Task: {E9FECDCA-1C3A-413D-A962-9E6D38BFE548} - System32\Tasks\WinThruster64-zwn-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe [2015-10-01] (Solvusoft Corporation) <==== UWAGA
Task: {FB10C95A-26EB-43FD-B863-813C384F1C2D} - System32\Tasks\{6AA0F428-E005-4532-968D-3EA6B4A347E7} => "c:\program files\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/6.3.73.105.457/pl/go/help.faq.installer?LastError=1603
Task: C:\WINDOWS\Tasks\ASCU10_SkipUac_zwn.job => C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASC.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\WINDOWS\Tasks\Uninstaller_Install_zwn.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ActionCenterDownloader.exe
Task: C:\WINDOWS\Tasks\WinThruster64-zwn-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== UWAGA
Task: C:\WINDOWS\Tasks\WinThruster64-zwn-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== UWAGA
Hosts:
C:\Users\zwn\AppData\Local\Comms\UnistoreDB\store.vol
(Solvusoft Corporation) C:\Program Files (x86)\Solvusoft\Tray\SolvusoftTray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe
HKU\S-1-5-21-3535335620-720777125-1201934452-1002\...\MountPoints2: {db853015-819b-11e7-8832-10bf485ae8ec} - "F:\AutoRun.exe"
HKU\S-1-5-21-3535335620-720777125-1201934452-1002\...\MountPoints2: {db853096-819b-11e7-8832-10bf485ae8ec} - "F:\AutoRun.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-09-27]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe (McAfee, Inc.)
HKU\S-1-5-21-3535335620-720777125-1201934452-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll => Brak pliku
Edge Extension: (NAZWA) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => ścieżki nie znaleziono
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKU\S-1-5-21-3535335620-720777125-1201934452-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3535335620-720777125-1201934452-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3535335620-720777125-1201934452-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gebpdbfmpedcnopofelmhndhincfkhki] - hxxps://chrome.google.com/webstore/detail/gebpdbfmpedcnopofelmhndhincfkhki
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx
OPR Extension: (Tłumacz) - C:\Users\zwn\AppData\Roaming\Opera Software\Opera Stable\Extensions\ibnombjmjocaccigcefonnipcnlaeaed [2016-03-23]
C:\Users\zwn\AppData\Roaming\Opera Software\Opera Stable\Extensions\ibnombjmjocaccigcefonnipcnlaeaed
S3 UI0Detect; C:\WINDOWS\SysWOW64\UI0Detect.exe [0 2017-03-09] () <==== UWAGA (zerobajtowy plik/folder)
2017-10-04 13:34 - 2017-10-04 13:34 - 001838144 _____ (Solvusoft) C:\Users\zwn\Downloads\Setup_FileViewPro_2016(1).exe
2017-10-04 13:25 - 2017-10-04 13:35 - 000002122 _____ C:\Users\Public\Desktop\WinThruster.lnk
2017-10-04 13:25 - 2017-10-04 13:35 - 000000889 _____ C:\Users\Public\Desktop\FileViewPro.lnk
2017-10-04 13:25 - 2017-10-04 13:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft
2017-10-04 13:25 - 2017-10-04 13:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileViewPro
2017-10-04 13:25 - 2017-10-04 13:35 - 000000000 ____D C:\Program Files\FileViewPro
2017-10-04 13:25 - 2017-10-04 13:32 - 000000384 _____ C:\WINDOWS\Tasks\WinThruster64-zwn-Notification.job
2017-10-04 13:25 - 2017-10-04 13:32 - 000000376 _____ C:\WINDOWS\Tasks\WinThruster64-zwn-Startup.job
2017-10-04 13:25 - 2017-10-04 13:26 - 000003584 _____ C:\WINDOWS\System32\Tasks\WinThruster64-zwn-Notification
2017-10-04 13:25 - 2017-10-04 13:26 - 000002890 _____ C:\WINDOWS\System32\Tasks\WinThruster64-zwn-Startup
2017-10-04 13:25 - 2017-10-04 13:25 - 000000000 ___HD C:\ProgramData\{4B36989F-BE86-4A21-94B1-AC154A69EA65}
2017-10-04 13:25 - 2017-10-04 13:25 - 000000000 ____D C:\Users\zwn\AppData\Local\FileViewPro
2017-10-04 13:25 - 2017-10-04 13:25 - 000000000 ____D C:\Program Files\Solvusoft
2017-10-04 13:25 - 2017-10-04 13:25 - 000000000 ____D C:\Program Files (x86)\Solvusoft
2017-10-04 13:24 - 2017-10-04 13:24 - 001838144 _____ (Solvusoft) C:\Users\zwn\Downloads\Setup_FileViewPro_2016.exe
2017-10-04 13:24 - 2017-10-04 13:24 - 000000000 ____D C:\Spacekace
2017-10-02 16:04 - 2017-10-02 16:04 - 017901184 _____ (IObit ) C:\Users\zwn\Downloads\driver_booster_setup.exe
2017-10-02 15:56 - 2017-10-02 15:56 - 085754840 _____ (IObit ) C:\Users\zwn\Downloads\asc-ultimate-setup.exe
2017-09-27 15:16 - 2017-09-27 15:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-09-27 15:15 - 2017-09-27 15:15 - 000000000 ____D C:\ProgramData\McAfee Security Scan
2017-09-18 12:13 - 2017-09-27 15:16 - 000000000 ____D C:\Program Files\McAfee Security Scan
2017-09-18 11:43 - 2017-09-27 15:16 - 000002009 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
W FRST wybierz Napraw.
Po wykonaniu zamiesc nowe logi z FRST, ze skanowania.