Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 06-06-2020 Uruchomiony przez jerzy (16-06-2020 17:54:49) Run:1 Uruchomiony z C:\Users\jerzy\Downloads Załadowane profile: jerzy Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CreateRestorePoint: CMD: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /s ***************** Błąd: (0) Nie udało się utworzyć punktu przywracania. ========= reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe UseFilter REG_DWORD 0x1 DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe\615be030_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\adobe\acrobat reader dc\reader\acrord32.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32Info.exe DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe\3d65e696_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\client\appvlp.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\clview.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cnfnot32.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwgviewr.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\excel.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excelcnv.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ExtExport.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\graph.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ie4uinit.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieinstal.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ielowutil.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieUnatt.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe DisableExceptionChainValidation REG_DWORD 0x0 DisableUserModeCallbackFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MRT.exe CFGOptions REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msaccess.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvw.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe\54331c8f_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\microsoft\edge\application\msedge.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfeedssync.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshta.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe CFGOptions REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoadfsb.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoasb.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msohtmed.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msosrec.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msosync.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe\138c4634_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\msoxmled.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\mspub.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msqry32.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngen.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngentask.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\onenote.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenotem.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\orgchart.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\outlook.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\powerpnt.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PresentationHost.exe MitigationOptions REG_QWORD 0x111111 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintDialog.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintIsolationHost.exe MitigationOptions REG_QWORD 0x200000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RdrCEF.exe DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RdrServicesUpdater.exe DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runtimebroker.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanost.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpst.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sdxhelper.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\selfcert.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\setlang.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\splwow64.exe MitigationOptions REG_QWORD 0x200000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe MitigationOptions REG_QWORD 0x200000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe MinimumStackCommitInBytes REG_DWORD 0x8000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SystemSettings.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\winword.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wordconv.exe MitigationOptions REG_QWORD 0x100 ========= Koniec CMD: ========= ==== Koniec Fixlog 17:54:50 ====