Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 19.02.2024 02
- Uruchomiony przez MC (21-02-2024 18:00:50) Run:1
- Uruchomiony z C:\Users\MC\Desktop\diagnostyka
- Załadowane profile: MC
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- CreateRestorePoint:
- CloseProcesses:
- EmptyTemp:
- File: C:\ProgramData\vxnylktj.vfa
- HKU\S-1-5-21-2868302559-654204484-3205365010-1002\...\Run: [MC] => cmd.exe /c start www.dinoraptzor.org (Brak pliku) <==== UWAGA
- Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA
- Task: {22BA633A-52EC-4D27-9A54-5A3DDA816BBC} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\Explorer.exe [5356504 2024-02-16] (Microsoft Windows -> Microsoft Corporation)
- Task: {09E87DE1-7952-46C5-9513-A0CE168ED263} - System32\Tasks\MC => C:\WINDOWS\system32\cmd.exe [323584 2023-11-17] (Microsoft Windows -> Microsoft Corporation) -> /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v MC /t REG_SZ /d "cmd.exe /c start www.dinoraptzor.org" <==== UWAGA
- Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (Brak pliku)
- Task: {78831357-786A-406C-9347-34552E1D5E30} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (Brak pliku)
- Task: {7AA0BE6C-DC93-42A7-9E31-C7ED51EE5D90} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC ReadyToReboot (Brak pliku)
- Task: {A3BB74F3-D8E1-4920-B4B5-6E6429F99E37} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Brak pliku)
- Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Brak pliku)
- Tcpip\..\Interfaces\{60bed0f3-0d72-45e3-9350-7b7aa73836da}: [DhcpNameServer] 192.168.0.1
- Tcpip\..\Interfaces\{60bed0f3-0d72-45e3-9350-7b7aa73836da}: [DhcpDomain] home
- S3 VBAudioVACMME; \SystemRoot\System32\drivers\vbaudio_cable64_win7.sys [X]
- S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
- 2024-02-14 12:25 - 2024-02-14 12:25 - 000012792 _____ C:\ProgramData\vxnylktj.vfa
- 2023-06-24 11:40 - 2019-05-25 02:55 - 000064461 _____ () C:\ProgramData\Online_KMS_Activation.cmd
- CustomCLSID: HKU\S-1-5-21-2868302559-654204484-3205365010-1002_Classes\CLSID\{E3D57E77-FE71-4D06-BD34-D48820074909}\InprocServer32 -> C:\Users\MC\AppData\Local\Microsoft\EdgeUpdate\1.3.181.5\psuser_64.dll => Brak pliku
- ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> Brak pliku
- HKU\S-1-5-21-2868302559-654204484-3205365010-1002\Software\Classes\regfile: regedit.exe "%1" <==== UWAGA
- HKU\S-1-5-21-2868302559-654204484-3205365010-1002\...\StartupApproved\Run: => "InstMP_Service"
- FirewallRules: [TCP Query User{BB6C1001-7481-4DCA-9826-CA3DE124F110}C:\users\mc\downloads\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe] => (Allow) C:\users\mc\downloads\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe => Brak pliku
- FirewallRules: [UDP Query User{75B2D569-72C5-43C8-A1CC-4E2B59B599CB}C:\users\mc\downloads\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe] => (Allow) C:\users\mc\downloads\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe => Brak pliku
- FirewallRules: [TCP Query User{0B86D127-B082-4C16-B0D2-67942C4E03C8}C:\users\mc\desktop\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe] => (Allow) C:\users\mc\desktop\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe => Brak pliku
- FirewallRules: [UDP Query User{85E58613-2159-4B60-ACA9-1811EDA9EB92}C:\users\mc\desktop\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe] => (Allow) C:\users\mc\desktop\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe => Brak pliku
- FirewallRules: [TCP Query User{FEA56A36-FA97-4436-8F38-5EEC4045CC93}C:\program files\outlast 2\binaries\win64\outlast2.exe] => (Allow) C:\program files\outlast 2\binaries\win64\outlast2.exe => Brak pliku
- FirewallRules: [UDP Query User{219AAE1D-08E3-443D-80FE-94E3A7018100}C:\program files\outlast 2\binaries\win64\outlast2.exe] => (Allow) C:\program files\outlast 2\binaries\win64\outlast2.exe => Brak pliku
- FirewallRules: [TCP Query User{44E42EC5-22A4-41EC-9B4B-F283CF02E5E6}C:\program files\dirt rally\drt.exe] => (Allow) C:\program files\dirt rally\drt.exe => Brak pliku
- FirewallRules: [UDP Query User{777DA8CB-5748-41D6-B459-B66D0864FE50}C:\program files\dirt rally\drt.exe] => (Allow) C:\program files\dirt rally\drt.exe => Brak pliku
- FirewallRules: [TCP Query User{DA6D5144-CC55-4F4D-9C86-46F2AACD7058}C:\program files (x86)\sebastien loeb rally evo\slrx64.exe] => (Allow) C:\program files (x86)\sebastien loeb rally evo\slrx64.exe => Brak pliku
- FirewallRules: [UDP Query User{98203517-F7C1-4B7F-8F08-FDD0EC7E1932}C:\program files (x86)\sebastien loeb rally evo\slrx64.exe] => (Allow) C:\program files (x86)\sebastien loeb rally evo\slrx64.exe => Brak pliku
- FirewallRules: [TCP Query User{74DCDEEF-5A1B-4AFE-9CE6-D4FB74520868}C:\users\mc\desktop\wrc 4\wrc4.exe] => (Allow) C:\users\mc\desktop\wrc 4\wrc4.exe => Brak pliku
- FirewallRules: [UDP Query User{56EC1DA1-FB43-4AEA-8178-C01725D29565}C:\users\mc\desktop\wrc 4\wrc4.exe] => (Allow) C:\users\mc\desktop\wrc 4\wrc4.exe => Brak pliku
- FirewallRules: [TCP Query User{EA9A5B47-884F-4DC2-A387-ED07F272404E}C:\program files\wrc 5 fia world rally championship\wrc5.exe] => (Allow) C:\program files\wrc 5 fia world rally championship\wrc5.exe => Brak pliku
- FirewallRules: [UDP Query User{DBFA206B-FB2B-44B2-812C-1F2FDE32AB9A}C:\program files\wrc 5 fia world rally championship\wrc5.exe] => (Allow) C:\program files\wrc 5 fia world rally championship\wrc5.exe => Brak pliku
- FirewallRules: [TCP Query User{27E3A3C8-28C5-46C3-932C-3E3B74E3BED1}C:\users\mc\desktop\wrc generations-insaneramzes\wrcg.exe] => (Allow) C:\users\mc\desktop\wrc generations-insaneramzes\wrcg.exe => Brak pliku
- FirewallRules: [UDP Query User{3FC507AE-CAD9-4285-B878-AC1F20135F69}C:\users\mc\desktop\wrc generations-insaneramzes\wrcg.exe] => (Allow) C:\users\mc\desktop\wrc generations-insaneramzes\wrcg.exe => Brak pliku
- FirewallRules: [TCP Query User{77324252-3882-4514-A577-B7FCE2DD6774}C:\users\mc\desktop\wrc\wrc 4\wrc4.exe] => (Allow) C:\users\mc\desktop\wrc\wrc 4\wrc4.exe => Brak pliku
- FirewallRules: [UDP Query User{746C9E1E-B1BC-4C7E-B23E-8CE87ABE0CB9}C:\users\mc\desktop\wrc\wrc 4\wrc4.exe] => (Allow) C:\users\mc\desktop\wrc\wrc 4\wrc4.exe => Brak pliku
- *****************
- Punkt przywracania został pomyślnie utworzony.
- Procesy zostały pomyślnie zamknięte.
- ========================= File: C:\ProgramData\vxnylktj.vfa ========================
- C:\ProgramData\vxnylktj.vfa
- Brak podpisu cyfrowego
- MD5: 35C431C12D982CFEDB99E2B7CC52F3D5
- Data utworzenia i modyfikacji: 2024-02-14 12:25 - 2024-02-14 12:25
- Rozmiar: 000012792
- Atrybuty: ----A
- Firma:
- Wewnętrzna nazwa:
- Oryginalna nazwa:
- Produkt:
- Opis:
- Plik Wersja:
- Produkt Wersja:
- Prawa autorskie:
- ====== Koniec File: ======
- "HKU\S-1-5-21-2868302559-654204484-3205365010-1002\Software\Microsoft\Windows\CurrentVersion\Run\\MC" => pomyślnie usunięto
- C:\ProgramData\NTUSER.pol => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{22BA633A-52EC-4D27-9A54-5A3DDA816BBC}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22BA633A-52EC-4D27-9A54-5A3DDA816BBC}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateExplorerShellUnelevatedTask" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{09E87DE1-7952-46C5-9513-A0CE168ED263}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09E87DE1-7952-46C5-9513-A0CE168ED263}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\MC => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MC" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78831357-786A-406C-9347-34552E1D5E30}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78831357-786A-406C-9347-34552E1D5E30}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7AA0BE6C-DC93-42A7-9E31-C7ED51EE5D90}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AA0BE6C-DC93-42A7-9E31-C7ED51EE5D90}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3BB74F3-D8E1-4920-B4B5-6E6429F99E37}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3BB74F3-D8E1-4920-B4B5-6E6429F99E37}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{60bed0f3-0d72-45e3-9350-7b7aa73836da}\\DhcpNameServer" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{60bed0f3-0d72-45e3-9350-7b7aa73836da}\\DhcpDomain" => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\VBAudioVACMME => pomyślnie usunięto
- VBAudioVACMME => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\WinSetupMon => pomyślnie usunięto
- WinSetupMon => serwis pomyślnie usunięto
- C:\ProgramData\vxnylktj.vfa => pomyślnie przeniesiono
- C:\ProgramData\Online_KMS_Activation.cmd => pomyślnie przeniesiono
- HKU\S-1-5-21-2868302559-654204484-3205365010-1002_Classes\CLSID\{E3D57E77-FE71-4D06-BD34-D48820074909} => pomyślnie usunięto
- HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ACE => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} => pomyślnie usunięto
- HKU\S-1-5-21-2868302559-654204484-3205365010-1002\Software\Classes\regfile => pomyślnie usunięto
- "HKU\S-1-5-21-2868302559-654204484-3205365010-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\InstMP_Service" => pomyślnie usunięto
- "HKU\S-1-5-21-2868302559-654204484-3205365010-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\InstMP_Service" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{BB6C1001-7481-4DCA-9826-CA3DE124F110}C:\users\mc\downloads\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{75B2D569-72C5-43C8-A1CC-4E2B59B599CB}C:\users\mc\downloads\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0B86D127-B082-4C16-B0D2-67942C4E03C8}C:\users\mc\desktop\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{85E58613-2159-4B60-ACA9-1811EDA9EB92}C:\users\mc\desktop\remnant2\remnant2\binaries\win64\remnant2-win64-shipping.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FEA56A36-FA97-4436-8F38-5EEC4045CC93}C:\program files\outlast 2\binaries\win64\outlast2.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{219AAE1D-08E3-443D-80FE-94E3A7018100}C:\program files\outlast 2\binaries\win64\outlast2.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{44E42EC5-22A4-41EC-9B4B-F283CF02E5E6}C:\program files\dirt rally\drt.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{777DA8CB-5748-41D6-B459-B66D0864FE50}C:\program files\dirt rally\drt.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{DA6D5144-CC55-4F4D-9C86-46F2AACD7058}C:\program files (x86)\sebastien loeb rally evo\slrx64.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{98203517-F7C1-4B7F-8F08-FDD0EC7E1932}C:\program files (x86)\sebastien loeb rally evo\slrx64.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{74DCDEEF-5A1B-4AFE-9CE6-D4FB74520868}C:\users\mc\desktop\wrc 4\wrc4.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{56EC1DA1-FB43-4AEA-8178-C01725D29565}C:\users\mc\desktop\wrc 4\wrc4.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{EA9A5B47-884F-4DC2-A387-ED07F272404E}C:\program files\wrc 5 fia world rally championship\wrc5.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DBFA206B-FB2B-44B2-812C-1F2FDE32AB9A}C:\program files\wrc 5 fia world rally championship\wrc5.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{27E3A3C8-28C5-46C3-932C-3E3B74E3BED1}C:\users\mc\desktop\wrc generations-insaneramzes\wrcg.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3FC507AE-CAD9-4285-B878-AC1F20135F69}C:\users\mc\desktop\wrc generations-insaneramzes\wrcg.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{77324252-3882-4514-A577-B7FCE2DD6774}C:\users\mc\desktop\wrc\wrc 4\wrc4.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{746C9E1E-B1BC-4C7E-B23E-8CE87ABE0CB9}C:\users\mc\desktop\wrc\wrc 4\wrc4.exe" => pomyślnie usunięto
- =========== EmptyTemp: ==========
- FlushDNS => ukończone
- BITS transfer queue => 1572864 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 25475474 B
- Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
- Windows/system/drivers => 31724364 B
- Edge => 0 B
- Firefox => 2361557175 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Default => 0 B
- ProgramData => 0 B
- Public => 0 B
- systemprofile => 0 B
- systemprofile32 => 0 B
- LocalService => 0 B
- NetworkService => 25900 B
- MC => 143300182 B
- RecycleBin => 3045371945 B
- EmptyTemp: => 5.2 GB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 18:01:34 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement