Advertisement
Guest User

Untitled

a guest
Sep 5th, 2022
41
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 15.60 KB | None | 0 0
  1. Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 30-08-2022
  2. Uruchomiony przez user (04-09-2022 22:05:45) Run:1
  3. Uruchomiony z C:\Users\user\Desktop\FRST
  4. Załadowane profile: defaultuser0 & user & postgres
  5. Tryb startu: Normal
  6. ==============================================
  7.  
  8. fixlist - zawartość:
  9. *****************
  10. CreateRestorePoint:
  11. CloseProcesses:
  12. EmptyTemp:
  13. HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 0
  14. HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
  15. HKLM\...\Policies\Explorer: [NoInstrumentation] 1
  16. HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Ograniczenia <==== UWAGA
  17. HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ograniczenia <==== UWAGA
  18. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\system: [NoDispAppearancePage] 0
  19. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
  20. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoPreviewPane] 0
  21. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
  22. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoSetTaskbar] 0
  23. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoViewContextMenu] 0
  24. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoWinkeys] 0
  25. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0
  26. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [HideClock] 0
  27. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [HideSCANetwork] 0
  28. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [HideSCAVolume] 0
  29. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Policies\...\system: [DisableCMD] 0
  30. GroupPolicy: Ograniczenia ? <==== UWAGA
  31. GroupPolicy\User: Ograniczenia ? <==== UWAGA
  32. Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA
  33. HKLM\SOFTWARE\Policies\Microsoft\Edge: Ograniczenia <==== UWAGA
  34. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Policies\Microsoft\Edge: Ograniczenia <==== UWAGA
  35. Task: {B1B662D3-7489-4DEF-9208-1142A0F39392} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
  36. Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
  37. Edge DefaultSearchURL: Default -> hxxps://www.wp.pl/favicon2-48x48.png
  38. FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.3\FFExt\light_plugin_firefox\addon.xpi => nie znaleziono
  39. FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.3\FFExt\light_plugin_firefox\addon.xpi => nie znaleziono
  40. U4 DiagTrack; Brak ImagePath
  41. R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-10-04] (Zemana Ltd. -> Zemana Ltd.)
  42. CustomCLSID: HKU\S-1-5-21-1259440541-1541188897-2945871715-1001_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Brak pliku
  43. ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
  44. ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
  45. ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
  46. ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
  47. ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
  48. ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
  49. ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
  50. ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
  51. ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
  52. ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
  53. ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
  54. ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
  55. ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
  56. ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
  57. FirewallRules: [TCP Query User{1D574556-CCA4-44E4-B3DB-35628971F602}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe] => (Allow) C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe => Brak pliku
  58. FirewallRules: [UDP Query User{06220162-7F55-45A5-A89F-818ACAC2FB73}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe] => (Allow) C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe => Brak pliku
  59. FirewallRules: [{C9CA50E2-13CF-4DA0-82E7-9EBAE4C484CC}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\on1capture.exe => Brak pliku
  60. FirewallRules: [{4D9C16F4-AF7A-4019-BB7F-03BD7899F1B0}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\on1capture.exe => Brak pliku
  61. FirewallRules: [{9CB93C9A-B3EB-4109-A877-F717F23D27C5}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\ON1 Photoshop Emulator.exe => Brak pliku
  62. FirewallRules: [{96D695C2-9354-4069-BFC7-8FBF60BE928B}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\ON1 Photoshop Emulator.exe => Brak pliku
  63. FirewallRules: [TCP Query User{85E752E2-FC0D-4863-B2B0-9B05AC0AB0C5}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light] => (Allow) C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light => Brak pliku
  64. FirewallRules: [UDP Query User{2638A34A-EA15-4E6E-8F7F-249414B496AF}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light] => (Allow) C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light => Brak pliku
  65. RemoveProxy:
  66.  
  67. *****************
  68.  
  69. Punkt przywracania został pomyślnie utworzony.
  70. Procesy zostały pomyślnie zamknięte.
  71. "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRecentDocsNetHood" => pomyślnie usunięto
  72. "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu" => pomyślnie usunięto
  73. "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation" => pomyślnie usunięto
  74. HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => Wartość pomyślnie przywrócono
  75. HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => pomyślnie usunięto
  76. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage" => pomyślnie usunięto
  77. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks" => pomyślnie usunięto
  78. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoPreviewPane" => pomyślnie usunięto
  79. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu" => pomyślnie usunięto
  80. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar" => pomyślnie usunięto
  81. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu" => pomyślnie usunięto
  82. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWinkeys" => pomyślnie usunięto
  83. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay" => pomyślnie usunięto
  84. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock" => pomyślnie usunięto
  85. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCANetwork" => pomyślnie usunięto
  86. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAVolume" => pomyślnie usunięto
  87. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Policies\Microsoft\Windows\System\\DisableCMD" => pomyślnie usunięto
  88. C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono
  89. C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
  90. C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono
  91. C:\WINDOWS\system32\GroupPolicy\User => pomyślnie przeniesiono
  92. C:\ProgramData\NTUSER.pol => pomyślnie przeniesiono
  93. HKLM\SOFTWARE\Policies\Microsoft\Edge => pomyślnie usunięto
  94. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Policies\Microsoft\Edge => pomyślnie usunięto
  95. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B1B662D3-7489-4DEF-9208-1142A0F39392}" => pomyślnie usunięto
  96. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1B662D3-7489-4DEF-9208-1142A0F39392}" => pomyślnie usunięto
  97. C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask => pomyślnie przeniesiono
  98. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateExplorerShellUnelevatedTask" => pomyślnie usunięto
  99. C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => pomyślnie przeniesiono
  100. "Edge DefaultSearchURL" => pomyślnie usunięto
  101. "HKLM\Software\Mozilla\Firefox\Extensions\\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com" => pomyślnie usunięto
  102. "HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com" => pomyślnie usunięto
  103. HKLM\System\CurrentControlSet\Services\DiagTrack => pomyślnie usunięto
  104. DiagTrack => serwis pomyślnie usunięto
  105. ZAM_Guard => Usługa pomyślnie zatrzymana.
  106. HKLM\System\CurrentControlSet\Services\ZAM_Guard => pomyślnie usunięto
  107. ZAM_Guard => serwis pomyślnie usunięto
  108. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4} => pomyślnie usunięto
  109. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => pomyślnie usunięto
  110. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => pomyślnie usunięto
  111. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => pomyślnie usunięto
  112. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => pomyślnie usunięto
  113. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => pomyślnie usunięto
  114. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => pomyślnie usunięto
  115. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => pomyślnie usunięto
  116. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => pomyślnie usunięto
  117. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => pomyślnie usunięto
  118. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => pomyślnie usunięto
  119. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => pomyślnie usunięto
  120. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => pomyślnie usunięto
  121. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => pomyślnie usunięto
  122. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => pomyślnie usunięto
  123. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1D574556-CCA4-44E4-B3DB-35628971F602}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe" => nie znaleziono
  124. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{06220162-7F55-45A5-A89F-818ACAC2FB73}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe" => nie znaleziono
  125. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C9CA50E2-13CF-4DA0-82E7-9EBAE4C484CC}" => pomyślnie usunięto
  126. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4D9C16F4-AF7A-4019-BB7F-03BD7899F1B0}" => pomyślnie usunięto
  127. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9CB93C9A-B3EB-4109-A877-F717F23D27C5}" => pomyślnie usunięto
  128. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{96D695C2-9354-4069-BFC7-8FBF60BE928B}" => pomyślnie usunięto
  129. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{85E752E2-FC0D-4863-B2B0-9B05AC0AB0C5}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light" => nie znaleziono
  130. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2638A34A-EA15-4E6E-8F7F-249414B496AF}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light" => nie znaleziono
  131.  
  132. ========= RemoveProxy: =========
  133.  
  134. HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => pomyślnie usunięto
  135. HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => pomyślnie usunięto
  136. "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
  137. "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
  138. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
  139. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
  140. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
  141. "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
  142.  
  143.  
  144. ========= Koniec RemoveProxy: =========
  145.  
  146.  
  147. =========== EmptyTemp: ==========
  148.  
  149. FlushDNS => ukończone
  150. BITS transfer queue => 1572864 B
  151. DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 331606569 B
  152. Java, Discord, Steam htmlcache => 0 B
  153. Windows/system/drivers => 33058890 B
  154. Edge => 24576 B
  155. Brave => 184320 B
  156. Firefox => 186509469 B
  157. Opera => 0 B
  158.  
  159. Temp, IE cache, history, cookies, recent:
  160. Default => 0 B
  161. ProgramData => 0 B
  162. Public => 0 B
  163. systemprofile => 0 B
  164. systemprofile32 => 0 B
  165. LocalService => 3286294 B
  166. NetworkService => 3286294 B
  167. defaultuser0 => 3286294 B
  168. user => 817947393 B
  169. postgres => 817947393 B
  170.  
  171. RecycleBin => 1503133047 B
  172. EmptyTemp: => 3.4 GB danych tymczasowych Usunięto.
  173.  
  174. ================================
  175.  
  176.  
  177. System wymagał restartu.
  178.  
  179. ==== Koniec Fixlog 22:06:23 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement