Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 23-08-2020 Uruchomiony przez NoNoNoNo (24-08-2020 22:35:24) Run:2 Uruchomiony z C:\Users\NoNoNoNo\Desktop\frst Załadowane profile: NoNoNoNo Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CreateRestorePoint: CMD: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /s ***************** Punkt przywracania został pomyślnie utworzony. ========= reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroExt.exe DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe\186e1b11_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\adobe\reader 11.0\reader\acrord32.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32Info.exe DisableExceptionChainValidation REG_DWORD 0x0 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bluestacks.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bluestacks.exe\cb5502d6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\programdata\bluestacks\client\bluestacks.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bookingDesktopAppUpdate.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe MaxLoaderThreads REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevicesFlow.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllhost.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drvinst.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvssysreport.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvssysreport.exe\22e62046_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\common files\dvdvideosoft\bin\dvssysreport.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ehexthost32.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ExtExport.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_32_0_0_414_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_32_0_0_414_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freestudiomanager.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freestudiomanager.exe\9bc7e0c4_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\common files\dvdvideosoft\lib\freestudiomanager.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freevideoeditor.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freevideoeditor.exe\69660af3_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\dvdvideosoft\free video editor\freevideoeditor.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hd-apkhandler.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hd-apkhandler.exe\d91a3db6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\bluestacks\hd-apkhandler.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hd-multiinstancemanager.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hd-multiinstancemanager.exe\d91a3db6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\bluestacks\hd-multiinstancemanager.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hd-runapp.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hd-runapp.exe\d91a3db6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\bluestacks\hd-runapp.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ie4uinit.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieinstal.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ielowutil.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieUnatt.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe DisableExceptionChainValidation REG_DWORD 0x0 DisableUserModeCallbackFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launcher.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\launcher.exe\f08de234_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\opera\launcher.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MiracastView.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MRT.exe CFGOptions REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvw.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfeedssync.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshta.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe CFGOptions REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngen.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngentask.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\premiummembershipoffer.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\premiummembershipoffer.exe\9bc7e0c4_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\common files\dvdvideosoft\lib\premiummembershipoffer.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PresentationHost.exe MitigationOptions REG_QWORD 0x111111 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintDialog.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintIsolationHost.exe MitigationOptions REG_QWORD 0x200000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runtimebroker.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotocolhost.exe DisableExceptionChainValidation REG_DWORD 0x3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\splwow64.exe MitigationOptions REG_QWORD 0x200000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe MitigationOptions REG_QWORD 0x200000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe\307c5ddc_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\steam\steam.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe MinimumStackCommitInBytes REG_DWORD 0x8000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SystemSettings.exe MitigationOptions REG_QWORD 0x100000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstall.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstall.exe\9bc7e0c4_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\common files\dvdvideosoft\lib\uninstall.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe DisableExceptionChainValidation REG_DWORD 0x3 ========= Koniec CMD: ========= ==== Koniec Fixlog 22:35:35 ====