Fixlist.txt dla FRST:
CloseProcesses:
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer1.log:F107EE40EF [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer1.log_backup1:2DD1EC5C91 [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer2.log:CCB2353F35 [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer2.log_backup1:0544EFE2DB [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer3.log:8A1F56CED6 [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer3.log_backup1:A473474DD2 [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer4.log:3B2EC2BDEF [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer4.log_backup1:DC5D04D24A [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer5.log:84BD5AAA09 [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer5.log_backup1:038079845B [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer6.log:4C1811BCCA [3442]
AlternateDataStreams: C:\ProgramData\DisplaySessionContainer6.log_backup1:AC11A713EE [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk:5465085A2F [10]
AlternateDataStreams: C:\Users\pikus\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\pikus\Application Data:671890e017d8a4fb26004192461213ff [394]
AlternateDataStreams: C:\Users\pikus\Application Data:eb92b835a834003ac00ee2632de0e925 [394]
AlternateDataStreams: C:\Users\pikus\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\pikus\AppData\Roaming:671890e017d8a4fb26004192461213ff [394]
AlternateDataStreams: C:\Users\pikus\AppData\Roaming:eb92b835a834003ac00ee2632de0e925 [394]
AlternateDataStreams: C:\Users\pikus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Asphalt 9: Legends.lnk [3512]
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
HKU\S-1-5-21-2261020369-2839936883-3009663517-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [38916432 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-2261020369-2839936883-3009663517-1001\...\Run: [Opera GX Browser Assistant] => C:\Users\pikus\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2261020369-2839936883-3009663517-1001\...\MountPoints2: {3105b36f-74c6-11ec-9c4b-d45d645a7451} - "D:\HiSuiteDownLoader.exe"
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {2E57D08D-D3E5-4D2D-882E-4BFAA8D410D2} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4669264 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "f4a31aa4-b8b1-412c-bdc8-b3ae0c9c2277" --version "6.07.10191" --silent
Task: {31FC95EA-7B6B-4B0D-B201-D10FF94D15A6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-12-09] (Piriform Software Ltd -> Piriform)
Task: {6E66C89C-F6E1-40EA-9C4A-A879CE2A0B54} - System32\Tasks\Opera scheduled Autoupdate 1604174972 => C:\Users\pikus\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {88279DFD-09F7-4A78-A2B4-6ED7226C8FA2} - System32\Tasks\Opera GX scheduled Autoupdate 1664369409 => C:\Users\pikus\AppData\Local\Programs\Opera GX\launcher.exe [2542536 2023-01-14] (Opera Norway AS -> Opera Software)
Task: {8F7D9213-F6C4-4BD0-A884-006218BD8EAC} - System32\Tasks\Opera scheduled assistant Autoupdate 1604174983 => C:\Users\pikus\AppData\Local\Programs\Opera\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\pikus\AppData\Local\Programs\Opera\assistant" $(Arg0)
Task: {AE3BF573-F379-40EB-9CD1-43D22B03C582} - System32\Tasks\CCleanerSkipUAC - pikus => C:\Program Files\CCleaner\CCleaner.exe [32602448 2022-12-09] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
TTask: {D526BF66-1B8E-41F5-BD30-E0D12509D5F7} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1664484458 => C:\Users\pikus\AppData\Local\Programs\Opera GX\launcher.exe [2542536 2023-01-14] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\pikus\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
CHR Extension: (Web Safety) - C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp [2021-08-25]
C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
CHR Extension: (Web Safety) - C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp [2021-11-06]
C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
CHR Extension: (Web Safety) - C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp [2022-01-19]
C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
CHR Extension: (Web Safety) - C:\Users\pikus\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp [2022-11-07]
CHR HKLM-x32\...\Chrome\Extension: [makcojoppodhcgmmchohadhpkicoafka]
CHR HKLM-x32\...\Chrome\Extension: [mfhcmdonhekjhfbjmeacdjbhlfgpjabp]
S3 0100031592676859mcinstcleanup; C:\ProgramData\McInstTemp0100031592676859\McInst.exe [839392 2020-06-08] (McAfee, LLC -> McAfee, LLC)
S3 bomebus; \SystemRoot\System32\drivers\bomebus.sys [X]
S3 uvtap; \SystemRoot\System32\drivers\uvtap.sys [X]
S3 wtbt; \??\c:\program files (x86)\steam\steamapps\common\super people playtest\engine\binaries\thirdparty\wondertrust\wtdrv64.sys [X]
Gdyby po wykonaniu nic sie nie zmienilo to sprawdz po wykonaniu czystego rozruchu:
https://support.microsoft.com/pl-pl/topic/jak...-windows-da2f9573-6eec-00ad-2f8a-a97a1807f3dd