Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 15.07.2018
- Uruchomiony przez norbi (18-07-2018 21:44:26) Run:4
- Uruchomiony z C:\Users\norbi\Desktop
- Załadowane profile: norbi (Dostępne profile: norbi & Administrator)
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- CloseProcesses:
- CreateRestorePoint:
- EmptyTemp:
- VirusTotal: C:\Program Files (x86)\LKvaHIuaGFsrl.exe
- VirusTotal: C:\Program Files (x86)\mpOE.exe
- VirusTotal: C:\Users\norbi\AppData\Roaming\cexplorer.exe
- VirusTotal: C:\Users\norbi\AppData\Local\Kaykix.exe
- HKU\S-1-5-21-1127345323-2592640102-239408248-1001\...\MountPoints2: {31f92ed6-6e49-11e8-a5ea-9822ef706bbe} - "D:\SISetup.exe"
- GroupPolicy: Ograniczenia - Chrome <==== UWAGA
- Tcpip\..\Interfaces\{2fa46e70-352c-4210-b3e6-52dd18a8fd10}: [NameServer] 62.179.1.62,62.179.1.63
- Tcpip\..\Interfaces\{7e0fc2c7-a2fb-4ec8-873f-697f8f5763c7}: [DhcpNameServer] 192.168.0.1 192.168.0.2
- SearchScopes: HKU\S-1-5-21-1127345323-2592640102-239408248-1001 -> DefaultScope {93723AF5-3686-4284-8D3D-F0062176FB1E} URL =
- FF NewTab: Mozilla\Firefox\Profiles\cuq6ogzb.default -> C:\\ProgramData\\Quoteexs\\ff.NT
- CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
- CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
- S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
- 2018-07-16 19:38 - 2018-07-16 19:38 - 000000008 __RSH C:\Users\norbi\ntuser.pol
- 2018-07-16 19:37 - 2018-07-16 19:37 - 000000008 __RSH C:\Users\Administrator\ntuser.pol
- 2018-07-16 19:31 - 2018-07-16 19:31 - 000000008 __RSH C:\ProgramData\ntuser.pol
- 2018-04-12 01:34 - 2018-04-12 01:34 - 000059904 ____N (Microsoft Corporation) C:\Program Files (x86)\LKvaHIuaGFsrl.exe
- 2018-04-12 01:34 - 2018-04-12 01:34 - 000178688 ____N (Microsoft Corporation) C:\Program Files (x86)\mpOE.exe
- 2018-03-26 14:57 - 2018-03-26 14:00 - 006860752 _____ (NeoSoft Tools ) C:\Users\norbi\AppData\Roaming\cexplorer.exe
- 2018-04-17 10:16 - 2018-04-17 10:16 - 001814528 _____ (TODO: <Company name>) C:\Users\norbi\AppData\Local\Kaykix.exe
- ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
- ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
- ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
- ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku
- Task: {0427CE24-7173-4F22-B9C8-594852EE0F46} - System32\Tasks\{B65EBFA6-2BB3-6D01-9B2F-26994F19324F} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://kotcatk.com/cl/?guid=4qwzsm6x0iwfo3nuixgzm3kw6mx0m52g&prid=1&pid=4_1324_0
- Task: {241F8DAA-98C5-40D4-B9A5-5B630021E37E} - System32\Tasks\{550D103A-F658-75DB-46DF-D5DF4C97A13E} => C:\Program Files (x86)\LKvaHIuaGFsrl.exe [2018-04-12] (Microsoft Corporation) <==== UWAGA
- Task: {D635FC26-D720-42D9-9244-407A72818605} - \Optimize Thumbnail Cache Files -> Brak pliku <==== UWAGA
- Task: {F970549A-A7E8-41A3-A3B8-DE2FB3776D2F} - \InstallShield® Update Service Scheduler -> Brak pliku <==== UWAGA
- AlternateDataStreams: C:\Users\Public\AppData:CSM [442]
- AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
- FirewallRules: [{4850792C-E096-42E6-847D-8A6962FB72D0}] => (Allow) C:\WINDOWS\SouAUHbxIaS.exe
- FirewallRules: [{F00891FE-2B58-4F94-A882-F4530F492FA4}] => (Allow) C:\Program Files (x86)\LKvaHIuaGFsrl.exe
- FirewallRules: [{8EF0E004-0459-4E62-BEE7-2379127E0A56}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{353B1DDE-6AA1-4C5F-BA03-5CC2DB219E1A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{1D9A8F74-199F-46C3-B975-E9BE37E6550D}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{80A5F7E4-0479-420A-8B35-87D6B3D69839}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{9C6D43F2-E42C-4F38-8043-DE597BEAD688}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{5E55B06E-3322-4EE6-9A73-82EF7BCD18E5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{63B7883C-4AC3-4C7F-8F87-AB74EF38A76A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{D46E3C0B-42D8-4EA4-8410-8EF0C089603A}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{EB61FBEC-9773-4AD7-9B10-102D883EDDD9}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{3246921C-EF87-422C-A72E-05737DDB156E}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{FFB58663-2FF6-4FEE-91AD-EF6B9A874EB5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{B3D6ADD2-DBCE-4569-AA7B-91C3666790CB}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{CC7538E7-4B1C-48E1-AA15-383E1B78F0A5}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{CC99CE33-0C0A-48E9-B553-3B03088011D9}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{ED4172DD-69C4-4807-9103-1C5E2ECADCF7}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{F06DC41B-2591-4F1E-AA83-189319F8F864}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{0629BE34-0D43-4811-A4C3-9DB240C00FAC}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{B6ACCBD2-EBFF-4949-B143-72624E6FECC2}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{FB61D9AD-161C-467D-8158-D97A3E26C586}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{6D39C980-91AC-437E-BB67-41A9E6FFA0BA}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{600875FF-454C-4655-8275-399D56C03509}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{0B6400E7-63D3-4971-A437-C7B13B1FEC59}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{AB749D88-724B-4D47-B5A9-AFDC6EEB2204}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{69537C68-5BF8-4D93-BE71-DDA0187C57DA}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{C63A934A-7F24-471A-807D-952122A21DC8}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{1D6F702E-8AFE-40E5-BDCB-B907EFE98325}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{E07C8AC0-0CC8-4C92-BC30-D9A914BF7FB9}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FirewallRules: [{EBDB3934-1E2D-4963-A787-9E723265D09C}] => (Allow) C:\WINDOWS\SysWOW64\svchost.exe
- FilesInDirectory: C:\Users\norbi\AppData\Local\*.exe;*.dll;*.ini
- FilesInDirectory: C:\Users\norbi\AppData\Roaming\*.exe;*.dll;*.ini
- CMD: dir /a "C:\Program Files"
- CMD: dir /a "C:\Program Files (x86)"
- CMD: dir /a "C:\Users\norbi\AppData"
- CMD: dir /a "C:\Users\norbi\AppData\Local"
- *****************
- Procesy zostały pomyślnie zamknięte.
- Punkt przywracania został pomyślnie utworzony.
- VirusTotal: C:\Program Files (x86)\LKvaHIuaGFsrl.exe => https://www.virustotal.com/file/b656b13e12b9caa5c0e041d6528aae515c310edb77a1267b73d901a7ba3a86fd/analysis/1531883740/
- VirusTotal: C:\Program Files (x86)\mpOE.exe => https://www.virustotal.com/file/ffabee87d6e0159ab95b73a367499dbe9689f887fe23b5919ef86095f3b930aa/analysis/1531920286/
- VirusTotal: C:\Users\norbi\AppData\Roaming\cexplorer.exe => https://www.virustotal.com/file/e71c48c03b8cfd37bf17e62460733a4bfe9c484e947fd9db291f65405a2ba9e8/analysis/1529983649/
- VirusTotal: C:\Users\norbi\AppData\Local\Kaykix.exe => https://www.virustotal.com/file/446eb9b430e01a149408b602a64ea857b185daf4b3e762d626c0bcec27fbc3ae/analysis/1524702822/
- "HKU\S-1-5-21-1127345323-2592640102-239408248-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{31f92ed6-6e49-11e8-a5ea-9822ef706bbe}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{31f92ed6-6e49-11e8-a5ea-9822ef706bbe} => nie znaleziono
- C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2fa46e70-352c-4210-b3e6-52dd18a8fd10}\\NameServer" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7e0fc2c7-a2fb-4ec8-873f-697f8f5763c7}\\DhcpNameServer" => pomyślnie usunięto
- "HKU\S-1-5-21-1127345323-2592640102-239408248-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => pomyślnie usunięto
- "Firefox newtab" => pomyślnie usunięto
- "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck" => pomyślnie usunięto
- "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0" => pomyślnie usunięto
- WinRing0_1_2_0 => serwis pomyślnie usunięto
- C:\Users\norbi\ntuser.pol => pomyślnie przeniesiono
- C:\Users\Administrator\ntuser.pol => pomyślnie przeniesiono
- C:\ProgramData\ntuser.pol => pomyślnie przeniesiono
- C:\Program Files (x86)\LKvaHIuaGFsrl.exe => pomyślnie przeniesiono
- C:\Program Files (x86)\mpOE.exe => pomyślnie przeniesiono
- C:\Users\norbi\AppData\Roaming\cexplorer.exe => pomyślnie przeniesiono
- C:\Users\norbi\AppData\Local\Kaykix.exe => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => nie znaleziono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => nie znaleziono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => nie znaleziono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => nie znaleziono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => nie znaleziono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3} => nie znaleziono
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3} => nie znaleziono
- "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => nie znaleziono
- "HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => nie znaleziono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0427CE24-7173-4F22-B9C8-594852EE0F46}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0427CE24-7173-4F22-B9C8-594852EE0F46}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\{B65EBFA6-2BB3-6D01-9B2F-26994F19324F} => pomyślnie przeniesiono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B65EBFA6-2BB3-6D01-9B2F-26994F19324F}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{241F8DAA-98C5-40D4-B9A5-5B630021E37E}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{241F8DAA-98C5-40D4-B9A5-5B630021E37E}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\{550D103A-F658-75DB-46DF-D5DF4C97A13E} => pomyślnie przeniesiono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{550D103A-F658-75DB-46DF-D5DF4C97A13E}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D635FC26-D720-42D9-9244-407A72818605}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D635FC26-D720-42D9-9244-407A72818605}" => pomyślnie usunięto
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Thumbnail Cache Files => nie znaleziono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F970549A-A7E8-41A3-A3B8-DE2FB3776D2F}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F970549A-A7E8-41A3-A3B8-DE2FB3776D2F}" => pomyślnie usunięto
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\InstallShield® Update Service Scheduler => nie znaleziono
- C:\Users\Public\AppData => ":CSM" ADS pomyślnie usunięto
- C:\Users\Public\Shared Files => ":VersionCache" ADS pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4850792C-E096-42E6-847D-8A6962FB72D0}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F00891FE-2B58-4F94-A882-F4530F492FA4}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8EF0E004-0459-4E62-BEE7-2379127E0A56}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{353B1DDE-6AA1-4C5F-BA03-5CC2DB219E1A}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1D9A8F74-199F-46C3-B975-E9BE37E6550D}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{80A5F7E4-0479-420A-8B35-87D6B3D69839}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9C6D43F2-E42C-4F38-8043-DE597BEAD688}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5E55B06E-3322-4EE6-9A73-82EF7BCD18E5}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{63B7883C-4AC3-4C7F-8F87-AB74EF38A76A}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D46E3C0B-42D8-4EA4-8410-8EF0C089603A}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EB61FBEC-9773-4AD7-9B10-102D883EDDD9}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3246921C-EF87-422C-A72E-05737DDB156E}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FFB58663-2FF6-4FEE-91AD-EF6B9A874EB5}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3D6ADD2-DBCE-4569-AA7B-91C3666790CB}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CC7538E7-4B1C-48E1-AA15-383E1B78F0A5}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CC99CE33-0C0A-48E9-B553-3B03088011D9}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ED4172DD-69C4-4807-9103-1C5E2ECADCF7}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F06DC41B-2591-4F1E-AA83-189319F8F864}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0629BE34-0D43-4811-A4C3-9DB240C00FAC}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B6ACCBD2-EBFF-4949-B143-72624E6FECC2}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FB61D9AD-161C-467D-8158-D97A3E26C586}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6D39C980-91AC-437E-BB67-41A9E6FFA0BA}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{600875FF-454C-4655-8275-399D56C03509}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0B6400E7-63D3-4971-A437-C7B13B1FEC59}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AB749D88-724B-4D47-B5A9-AFDC6EEB2204}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{69537C68-5BF8-4D93-BE71-DDA0187C57DA}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C63A934A-7F24-471A-807D-952122A21DC8}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1D6F702E-8AFE-40E5-BDCB-B907EFE98325}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E07C8AC0-0CC8-4C92-BC30-D9A914BF7FB9}" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EBDB3934-1E2D-4963-A787-9E723265D09C}" => pomyślnie usunięto
- ========================= FilesInDirectory: C:\Users\norbi\AppData\Local\*.exe;*.dll;*.ini ========================
- 2018-04-17 10:16 - 2018-04-17 10:16 - 001814528 ____A [98BCD4FDE4F9B894051AA374DB3553A9] (TODO: <Company name>) C:\Users\norbi\AppData\Local\Alphazap.exe
- 2018-07-16 09:19 - 2018-07-16 09:19 - 000000002 ____A [23B58DEF11B45727D3351702515F86AF] () C:\Users\norbi\AppData\Local\imw.ini
- ====== Koniec Filesindirectory ======
- ========================= FilesInDirectory: C:\Users\norbi\AppData\Roaming\*.exe;*.dll;*.ini ========================
- ====== Koniec Filesindirectory ======
- ========= dir /a "C:\Program Files" =========
- Volume in drive C is Acer
- Volume Serial Number is 9E2E-6809
- Directory of C:\Program Files
- 15.07.2018 15:58 <DIR> .
- 15.07.2018 15:58 <DIR> ..
- 18.04.2018 12:30 <DIR> Acer
- 17.04.2018 10:57 <DIR> AVAST Software
- 18.04.2018 13:09 <DIR> CCleaner
- 05.06.2018 17:18 <DIR> Common Files
- 12.04.2018 01:36 174 desktop.ini
- 05.06.2018 16:24 <DIR> Dolby
- 18.04.2018 10:47 <DIR> Epic Games
- 17.04.2018 10:24 <DIR> FZ5UV6ATOW
- 15.07.2018 13:39 <DIR> Grand Theft Auto V
- 15.06.2018 08:40 <DIR> HP
- 05.06.2018 17:18 <DIR> Intel
- 12.04.2018 17:52 <DIR> internet explorer
- 15.06.2018 22:40 <DIR> iVMS-4200 Station
- 16.07.2018 19:42 <DIR> KMSpico
- 17.04.2018 13:35 <DIR> Microsoft Analysis Services
- 17.04.2018 13:37 <DIR> Microsoft Office
- 17.04.2018 13:37 <DIR> Microsoft SQL Server
- 05.06.2018 17:18 <DIR> Microsoft.NET
- 05.06.2018 16:55 <DIR> MSBuild
- 17.04.2018 10:18 <DIR> My Program
- 10.04.2018 14:22 <DIR> Norton Security
- 05.06.2018 16:25 <DIR> NVIDIA Corporation
- 05.06.2018 17:13 <DIR> Realtek
- 15.07.2018 20:12 <DIR> Recuva
- 05.06.2018 16:55 <DIR> Reference Assemblies
- 10.04.2018 13:49 <DIR> rempl
- 07.05.2018 19:52 <DIR> Rockstar Games
- 12.05.2018 15:21 <DIR> The Sims 4
- 23.11.2017 11:45 <DIR> Uninstall Information
- 19.06.2018 14:02 <DIR> VideoLAN
- 05.06.2018 16:45 <DIR> Windows Defender
- 05.06.2018 17:18 <DIR> Windows Mail
- 05.06.2018 17:01 <DIR> Windows Media Player
- 12.04.2018 01:38 <DIR> Windows Multimedia Platform
- 05.06.2018 16:46 <DIR> windows nt
- 15.06.2018 17:17 <DIR> Windows Photo Viewer
- 12.04.2018 01:38 <DIR> Windows Portable Devices
- 12.04.2018 01:38 <DIR> Windows Security
- 12.04.2018 01:38 <DIR> Windows Sidebar
- 18.07.2018 19:39 <DIR> WindowsApps
- 12.04.2018 01:38 <DIR> WindowsPowerShell
- 17.04.2018 09:58 <DIR> WinRAR
- 1 File(s) 174 bytes
- 43 Dir(s) 690˙928˙218˙112 bytes free
- ========= Koniec CMD: =========
- ========= dir /a "C:\Program Files (x86)" =========
- Volume in drive C is Acer
- Volume Serial Number is 9E2E-6809
- Directory of C:\Program Files (x86)
- 18.07.2018 21:45 <DIR> .
- 18.07.2018 21:45 <DIR> ..
- 18.04.2018 12:31 <DIR> Acer
- 15.04.2018 19:18 <DIR> AMX Mod X
- 19.04.2018 12:17 <DIR> Anvsoft
- 23.11.2017 12:09 <DIR> Bluetooth Suite
- 11.04.2018 14:25 <DIR> City Car Driving
- 15.07.2018 16:44 <DIR> CleverFiles
- 20.06.2018 14:48 <DIR> Common Files
- 12.04.2018 01:36 174 desktop.ini
- 18.04.2018 21:54 <DIR> EasyAntiCheat
- 18.04.2018 10:45 <DIR> Epic Games
- 17.04.2018 10:19 <DIR> foldershare
- 18.07.2018 19:22 <DIR> Google
- 17.04.2018 11:04 <DIR> hash
- 15.06.2018 22:40 <DIR> InstallShield Installation Information
- 23.11.2017 12:14 <DIR> Intel
- 12.04.2018 17:52 <DIR> Internet Explorer
- 31.05.2018 12:50 <DIR> IObit
- 19.04.2018 12:20 <DIR> K-Lite Codec Pack
- 17.04.2018 10:40 <DIR> KMSPico 10.2.1 Final
- 17.04.2018 13:35 <DIR> Microsoft Analysis Services
- 17.04.2018 13:35 <DIR> Microsoft Office
- 17.04.2018 13:37 <DIR> Microsoft SQL Server
- 05.06.2018 17:18 <DIR> Microsoft.NET
- 18.07.2018 19:29 <DIR> Mozilla Firefox
- 18.07.2018 19:29 <DIR> Mozilla Maintenance Service
- 05.06.2018 16:55 <DIR> MSBuild
- 23.11.2017 12:53 <DIR> NortonInstaller
- 21.05.2018 15:02 <DIR> NVIDIA Corporation
- 01.05.2018 10:20 <DIR> PhotoScape
- 23.11.2017 12:28 <DIR> Qualcomm
- 20.06.2018 14:48 <DIR> Razer
- 23.11.2017 12:26 <DIR> Realtek
- 05.06.2018 16:55 <DIR> Reference Assemblies
- 07.05.2018 19:53 <DIR> Rockstar Games
- 16.07.2018 10:58 <DIR> Steam
- 10.04.2018 15:22 <DIR> SteamServerBrowser
- 23.11.2017 12:54 <DIR> SymSilent
- 23.11.2017 12:27 <DIR> Temp
- 05.06.2018 16:23 <DIR> VulkanRT
- 15.06.2018 22:41 <DIR> Win10Pcap
- 05.06.2018 17:01 <DIR> Windows Defender
- 05.06.2018 17:13 <DIR> Windows Mail
- 05.06.2018 17:01 <DIR> Windows Media Player
- 12.04.2018 01:38 <DIR> Windows Multimedia Platform
- 12.04.2018 01:38 <DIR> windows nt
- 15.06.2018 17:17 <DIR> Windows Photo Viewer
- 12.04.2018 01:38 <DIR> Windows Portable Devices
- 12.04.2018 01:38 <DIR> Windows Sidebar
- 12.04.2018 01:38 <DIR> WindowsPowerShell
- 1 File(s) 174 bytes
- 50 Dir(s) 690˙928˙218˙112 bytes free
- ========= Koniec CMD: =========
- ========= dir /a "C:\Users\norbi\AppData" =========
- Volume in drive C is Acer
- Volume Serial Number is 9E2E-6809
- Directory of C:\Users\norbi\AppData
- 05.06.2018 16:44 <DIR> .
- 05.06.2018 16:44 <DIR> ..
- 18.07.2018 21:45 <DIR> Local
- 16.07.2018 09:33 <DIR> LocalLow
- 15.07.2018 20:19 80 Local???????????????????
- 18.07.2018 21:45 <DIR> Roaming
- 1 File(s) 80 bytes
- 5 Dir(s) 690˙928˙218˙112 bytes free
- ========= Koniec CMD: =========
- ========= dir /a "C:\Users\norbi\AppData\Local" =========
- Volume in drive C is Acer
- Volume Serial Number is 9E2E-6809
- Directory of C:\Users\norbi\AppData\Local
- 18.07.2018 21:45 <DIR> .
- 18.07.2018 21:45 <DIR> ..
- 29.05.2018 13:38 <DIR> acer
- 17.04.2018 10:16 7˙602˙176 agent.dat
- 17.04.2018 10:16 1˙814˙528 Alphazap.exe
- 17.04.2018 10:16 1˙989˙393 Alphazap.tst
- 10.04.2018 13:54 <DIR> AOP SDK
- 10.04.2018 14:10 <DIR> Apps
- 16.07.2018 19:55 <DIR> AVAST Software
- 10.04.2018 15:13 <DIR> CEF
- 26.04.2018 15:37 <DIR> Comms
- 17.04.2018 10:16 70˙896 Config.xml
- 10.04.2018 13:55 <DIR> ConnectedDevicesPlatform
- 18.07.2018 19:11 <DIR> CrashDumps
- 16.06.2018 20:21 <DIR> CrashReportClient
- 15.07.2018 16:44 <DIR> CrashRpt
- 05.07.2018 13:29 <DIR> D3DSCache
- 05.06.2018 16:27 <JUNCTION> Dane aplikacji [C:\Users\norbi\AppData\Local]
- 11.04.2018 14:25 <DIR> DBG
- 18.07.2018 19:41 <DIR> Deployment
- 15.06.2018 22:27 <DIR> DeskShare Data
- 15.07.2018 09:48 <DIR> Diagnostics
- 15.07.2018 18:25 <DIR> DiskDrill
- 18.04.2018 10:45 <DIR> EpicGamesLauncher
- 18.04.2018 11:05 <DIR> FortniteGame
- 18.07.2018 19:23 <DIR> Google
- 05.06.2018 16:27 <JUNCTION> Historia [C:\Users\norbi\AppData\Local\Microsoft\Windows\History]
- 18.07.2018 20:48 255˙078 IconCache.db
- 10.04.2018 19:41 <DIR> IIIQF
- 16.07.2018 09:19 2 imw.ini
- 17.04.2018 10:16 140˙800 installer.dat
- 17.04.2018 10:16 278˙509 Kaykix.tst
- 17.04.2018 10:16 5˙568 md.xml
- 15.06.2018 08:08 <DIR> Microsoft
- 17.04.2018 14:46 <DIR> Microsoft Help
- 10.04.2018 19:35 <DIR> MicrosoftEdge
- 10.04.2018 14:03 <DIR> Mozilla
- 17.04.2018 10:16 126˙464 noah.dat
- 31.05.2018 18:48 <DIR> NVIDIA
- 21.05.2018 15:09 <DIR> NVIDIA Corporation
- 16.07.2018 19:53 <DIR> Packages
- 29.06.2018 22:02 <DIR> PlaceholderTileLogoFolder
- 10.04.2018 15:20 <DIR> Programs
- 10.04.2018 15:00 <DIR> Publishers
- 20.06.2018 14:48 <DIR> Razer
- 17.06.2018 08:18 <DIR> Razer_Inc
- 07.05.2018 19:26 <DIR> Rockstar Games
- 17.04.2018 10:18 929˙792 sham.db
- 15.06.2018 22:24 <DIR> Spoon
- 16.07.2018 11:01 <DIR> Sports Interactive
- 10.04.2018 15:14 <DIR> Steam
- 18.07.2018 21:45 <DIR> Temp
- 05.06.2018 16:27 <JUNCTION> Temporary Internet Files [C:\Users\norbi\AppData\Local\Microsoft\Windows\INetCache]
- 10.04.2018 19:34 <DIR> TileDataLayer
- 17.04.2018 10:16 32˙038 uninstall_temp.ico
- 12.07.2018 20:13 <DIR> UnrealEngine
- 18.04.2018 10:45 <DIR> UnrealEngineLauncher
- 10.04.2018 13:54 <DIR> VirtualStore
- 17.04.2018 10:16 1˙895˙384 Warmtech.bin
- 13 File(s) 15˙140˙628 bytes
- 46 Dir(s) 690˙928˙214˙016 bytes free
- ========= Koniec CMD: =========
- =========== EmptyTemp: ==========
- BITS transfer queue => 8675328 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10807030 B
- Java, Flash, Steam htmlcache => 0 B
- Windows/system/drivers => 185308 B
- Edge => 3584 B
- Chrome => 377582406 B
- Firefox => 1169091 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Default => 0 B
- Users => 0 B
- ProgramData => 0 B
- Public => 0 B
- systemprofile => 0 B
- systemprofile32 => 0 B
- LocalService => 1814 B
- LocalService => 0 B
- NetworkService => 0 B
- NetworkService => 0 B
- norbi => 16068537 B
- Administrator => 71051258 B
- RecycleBin => 584766 B
- EmptyTemp: => 463.6 MB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 21:46:28 ====
Add Comment
Please, Sign In to add comment