W logu widac:
Error: (01/7/2023 08:49:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Usługa WaaSMedicSvc zakończyła działanie; wystąpił następujący błąd:
Nie można odnaleźć określonego modułu.
Do okna FRST wklej:
WaasMedicSvc.dll
Nacisnij Szukaj Plikow. Log, ktory sie utworzy zamiesc w zalaczniku.
Uruchom okno cmd z prawami administratora i tam:
sc query wuauserv
I zamiesc wynik.
Fixlist.txt dla FRST:
CloseProcesses:
AlternateDataStreams: C:\ProgramData:err [1542]
AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [690]
AlternateDataStreams: C:\Users\All Users:err [1542]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [690]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:err [1542]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT [40]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2 [690]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [690]
AlternateDataStreams: C:\Users\ogfge\Dane aplikacji:NT [40]
AlternateDataStreams: C:\Users\ogfge\Dane aplikacji:NT2 [690]
AlternateDataStreams: C:\Users\ogfge\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\ogfge\AppData\Roaming:NT2 [690]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [9502]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [711328 2022-06-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ograniczenia <==== UWAGA
HKU\S-1-5-21-4209249715-2137800222-4004383135-1001\...\Run: [Opera GX Stable] => C:\Users\ogfge\AppData\Local\Programs\Opera GX\launcher.exe [2566600 2022-12-20] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-4209249715-2137800222-4004383135-1001\...\Run: [Opera GX Browser Assistant] => C:\Users\ogfge\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-4209249715-2137800222-4004383135-1001\...\Run: [MicrosoftEdgeAutoLaunch_EEC07DDD1AFBCA1A0BCEF43EAE9073F2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3879368 2023-01-05] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4209249715-2137800222-4004383135-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38916432 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-4209249715-2137800222-4004383135-1001\...\MountPoints2: {d0df5ef8-1e8d-11ed-bd41-001a7dda7113} - "D:\HiSuiteDownLoader.exe"
Task: {2828F4BC-23DA-4481-A344-9A8CA9E0CEA0} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1656601952 => C:\Users\ogfge\AppData\Local\Programs\Opera GX\launcher.exe [2566600 2022-12-20] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\ogfge\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {4F2BE887-CD01-4447-B077-4EF56FCF8E13} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-12-09] (Piriform Software Ltd -> Piriform)
Task: {862021CF-64BB-4D61-B720-14BD82FC5EDD} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "c28c69bf-418b-4e7f-ade5-d7e88ca58123" --version "6.07.10191" --silent
Task: {99258CB2-60CC-4D97-9E70-7A8B0097BB1F} - System32\Tasks\CCleanerSkipUAC - ogfge => C:\Program Files\CCleaner\CCleaner.exe [32602448 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {B1D90EAA-D48E-4F55-8494-3EC5F3BCEFC9} - System32\Tasks\Opera GX scheduled Autoupdate 1656323547 => C:\Users\ogfge\AppData\Local\Programs\Opera GX\launcher.exe [2566600 2022-12-20] (Opera Norway AS -> Opera Software)
ProxyServer: [S-1-5-21-4209249715-2137800222-4004383135-1001] => 127.0.0.1:14458
RemoveProxy:
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
R2 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1003344 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
S2 Eaqefryr; C:\Users\ogfge\AppData\Local\Temp\Eaqefryr.dll [X] <==== UWAGA
S3 GENERICDRV; \??\C:\Users\ogfge\OneDrive\Desktop\GRINX64v2\amifldrv64.sys [X]
U0 Partizan; system32\drivers\Partizan.sys [X]
2023-01-07 21:00 - 2023-01-07 21:00 - 000000000 ____D C:\Users\ogfge\Downloads\FRST-OlderVersion
2023-01-06 16:14 - 2023-01-06 16:15 - 000000000 ____D C:\Users\ogfge\AppData\Local\Adaware
2023-01-06 16:14 - 2023-01-06 16:15 - 003295384 _____ (DT001) C:\Users\ogfge\AppData\Local\setup29765.exe