Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 30-08-2022
- Uruchomiony przez user (04-09-2022 22:05:45) Run:1
- Uruchomiony z C:\Users\user\Desktop\FRST
- Załadowane profile: defaultuser0 & user & postgres
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- CreateRestorePoint:
- CloseProcesses:
- EmptyTemp:
- HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 0
- HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
- HKLM\...\Policies\Explorer: [NoInstrumentation] 1
- HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Ograniczenia <==== UWAGA
- HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ograniczenia <==== UWAGA
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\system: [NoDispAppearancePage] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoPreviewPane] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoSetTaskbar] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoViewContextMenu] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoWinkeys] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [HideClock] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [HideSCANetwork] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\...\Policies\Explorer: [HideSCAVolume] 0
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Policies\...\system: [DisableCMD] 0
- GroupPolicy: Ograniczenia ? <==== UWAGA
- GroupPolicy\User: Ograniczenia ? <==== UWAGA
- Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA
- HKLM\SOFTWARE\Policies\Microsoft\Edge: Ograniczenia <==== UWAGA
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Policies\Microsoft\Edge: Ograniczenia <==== UWAGA
- Task: {B1B662D3-7489-4DEF-9208-1142A0F39392} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
- Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
- Edge DefaultSearchURL: Default -> hxxps://www.wp.pl/favicon2-48x48.png
- FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.3\FFExt\light_plugin_firefox\addon.xpi => nie znaleziono
- FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 21.3\FFExt\light_plugin_firefox\addon.xpi => nie znaleziono
- U4 DiagTrack; Brak ImagePath
- R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-10-04] (Zemana Ltd. -> Zemana Ltd.)
- CustomCLSID: HKU\S-1-5-21-1259440541-1541188897-2945871715-1001_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
- FirewallRules: [TCP Query User{1D574556-CCA4-44E4-B3DB-35628971F602}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe] => (Allow) C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe => Brak pliku
- FirewallRules: [UDP Query User{06220162-7F55-45A5-A89F-818ACAC2FB73}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe] => (Allow) C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe => Brak pliku
- FirewallRules: [{C9CA50E2-13CF-4DA0-82E7-9EBAE4C484CC}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\on1capture.exe => Brak pliku
- FirewallRules: [{4D9C16F4-AF7A-4019-BB7F-03BD7899F1B0}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\on1capture.exe => Brak pliku
- FirewallRules: [{9CB93C9A-B3EB-4109-A877-F717F23D27C5}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\ON1 Photoshop Emulator.exe => Brak pliku
- FirewallRules: [{96D695C2-9354-4069-BFC7-8FBF60BE928B}] => (Allow) C:\Program Files\ON1\ON1 NoNoise AI 2022\ON1 Photoshop Emulator.exe => Brak pliku
- FirewallRules: [TCP Query User{85E752E2-FC0D-4863-B2B0-9B05AC0AB0C5}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light] => (Allow) C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light => Brak pliku
- FirewallRules: [UDP Query User{2638A34A-EA15-4E6E-8F7F-249414B496AF}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light] => (Allow) C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light => Brak pliku
- RemoveProxy:
- *****************
- Punkt przywracania został pomyślnie utworzony.
- Procesy zostały pomyślnie zamknięte.
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRecentDocsNetHood" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation" => pomyślnie usunięto
- HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => Wartość pomyślnie przywrócono
- HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoPreviewPane" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWinkeys" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCANetwork" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAVolume" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\Software\Policies\Microsoft\Windows\System\\DisableCMD" => pomyślnie usunięto
- C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono
- C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
- C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono
- C:\WINDOWS\system32\GroupPolicy\User => pomyślnie przeniesiono
- C:\ProgramData\NTUSER.pol => pomyślnie przeniesiono
- HKLM\SOFTWARE\Policies\Microsoft\Edge => pomyślnie usunięto
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Policies\Microsoft\Edge => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B1B662D3-7489-4DEF-9208-1142A0F39392}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1B662D3-7489-4DEF-9208-1142A0F39392}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateExplorerShellUnelevatedTask" => pomyślnie usunięto
- C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => pomyślnie przeniesiono
- "Edge DefaultSearchURL" => pomyślnie usunięto
- "HKLM\Software\Mozilla\Firefox\Extensions\\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com" => pomyślnie usunięto
- "HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com" => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\DiagTrack => pomyślnie usunięto
- DiagTrack => serwis pomyślnie usunięto
- ZAM_Guard => Usługa pomyślnie zatrzymana.
- HKLM\System\CurrentControlSet\Services\ZAM_Guard => pomyślnie usunięto
- ZAM_Guard => serwis pomyślnie usunięto
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4} => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => pomyślnie usunięto
- HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1D574556-CCA4-44E4-B3DB-35628971F602}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe" => nie znaleziono
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{06220162-7F55-45A5-A89F-818ACAC2FB73}C:\users\user\appdata\roaming\dvdfab\streamfab\youtubetomp3\youtubetomp3service.exe" => nie znaleziono
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C9CA50E2-13CF-4DA0-82E7-9EBAE4C484CC}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4D9C16F4-AF7A-4019-BB7F-03BD7899F1B0}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9CB93C9A-B3EB-4109-A877-F717F23D27C5}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{96D695C2-9354-4069-BFC7-8FBF60BE928B}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{85E752E2-FC0D-4863-B2B0-9B05AC0AB0C5}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light" => nie znaleziono
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2638A34A-EA15-4E6E-8F7F-249414B496AF}C:\users\user\appdata\local\temp\jivexviewer\jre\bin\jivex[dv] light" => nie znaleziono
- ========= RemoveProxy: =========
- HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => pomyślnie usunięto
- HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => pomyślnie usunięto
- "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
- "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
- "HKU\S-1-5-21-1259440541-1541188897-2945871715-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
- ========= Koniec RemoveProxy: =========
- =========== EmptyTemp: ==========
- FlushDNS => ukończone
- BITS transfer queue => 1572864 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 331606569 B
- Java, Discord, Steam htmlcache => 0 B
- Windows/system/drivers => 33058890 B
- Edge => 24576 B
- Brave => 184320 B
- Firefox => 186509469 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Default => 0 B
- ProgramData => 0 B
- Public => 0 B
- systemprofile => 0 B
- systemprofile32 => 0 B
- LocalService => 3286294 B
- NetworkService => 3286294 B
- defaultuser0 => 3286294 B
- user => 817947393 B
- postgres => 817947393 B
- RecycleBin => 1503133047 B
- EmptyTemp: => 3.4 GB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 22:06:23 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement