Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 16-10-2022
- Uruchomiony przez battl (16-10-2022 20:37:17) Run:1
- Uruchomiony z D:\Instalatory
- Załadowane profile: battl & postgres
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- CreateRestorePoint:
- CloseProcesses:
- EmptyTemp:
- HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Ograniczenia <==== UWAGA
- HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Ograniczenia <==== UWAGA
- HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
- HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ograniczenia <==== UWAGA
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\...\Run: [AdobeBridge] => [X]
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\...\Run: [Xvid] => WScript "C:\Program Files (x86)\Xvid\CheckUpdateLauncher.vbs" "C:\Program Files (x86)\Xvid\CheckUpdate.ps1" (Brak pliku)
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\...\Run: [UrlsFile] => cmd /c start C:\Users\battl\UrlsFile.lnk -ep unrestricted -file C:\Users\battl\MakeJunk.ps1 (Brak pliku) <==== UWAGA
- HKU\S-1-5-18\...\Policies\system: [DisableTaskMgr] 1
- HKU\S-1-5-18\...\Policies\system: [DisableCMD] 1
- HKU\S-1-5-18\...\Policies\system: [DisableRegistryTools] 1
- GroupPolicy: Ograniczenia ? <==== UWAGA
- Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA
- HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA
- Task: {007EE8F4-02D8-4290-926A-22F29C864D25} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2250576 2022-10-16] (Avast Software s.r.o. -> Avast Software)
- Task: {46283DC6-18A8-4777-96AF-8D70D94E6DB8} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (Brak pliku)
- Task: {B2774336-753F-4534-AE68-DD88A57440DC} - System32\Tasks\{12EA3BA8-815A-715A-8A8A-681A8C47AD9E} => rundll32.exe "C:\Users\battl\AppData\Roaming\{7F5851CB-DA38-5830-BDBB-3D3E9EA37578}\quokzufe.dll",#1 --naey="GridShed\license.dat"
- Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
- Tcpip\..\Interfaces\{6eccc877-e394-4617-8c3a-d4abd1d62b5d}: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{99df9e13-86ca-47a9-8b45-ab5ff39e89d5}: [DhcpNameServer] 192.168.213.170
- Tcpip\..\Interfaces\{9f2cce24-81fd-4df1-9ed5-beac232edd83}: [DhcpNameServer] 192.168.55.1
- FF Extension: (Brak nazwy) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [nie znaleziono]
- FF Extension: (Brak nazwy) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [nie znaleziono]
- S3 mracsvc; C:\WINDOWS\System32\mracsvc.exe [16966416 2019-07-14] (Mail.Ru LLC -> LLC Mail.Ru)
- S3 mracdrv; C:\WINDOWS\System32\drivers\mracdrv.sys [16228328 2019-07-14] (Mail.Ru LLC -> LLC Mail.Ru)
- 2022-10-16 17:07 - 2022-10-16 17:07 - 030585424 _____ (g10 Code GmbH) C:\Users\battl\AppData\Roaming\gpg4win-2.2.5.exe
- 2022-10-16 17:07 - 2022-10-16 17:07 - 000252928 _____ (M2-Team) C:\Users\battl\AppData\Roaming\Nsudo.exe
- 2019-10-08 16:12 - 2019-10-08 16:12 - 009256960 _____ () C:\Program Files (x86)\GUTD232.tmp
- 2021-01-21 18:08 - 2021-03-07 20:20 - 000000610 _____ () C:\Users\battl\AppData\Roaming\KONOR.MTBF.txt
- 2022-10-16 17:07 - 2022-10-16 17:07 - 000071168 _____ () C:\Users\battl\AppData\Roaming\p9d2.dll
- 2022-10-16 17:07 - 2022-10-16 17:07 - 000041474 _____ () C:\Users\battl\AppData\Roaming\p9d2.dll.gpg
- 2022-10-16 17:07 - 2022-10-16 17:07 - 000033389 _____ () C:\Users\battl\AppData\Roaming\p9d2s.exe.gpg
- 2022-10-16 17:07 - 2022-10-16 17:07 - 000000009 _____ () C:\Users\battl\AppData\Roaming\runanddelete.bat
- 2022-10-16 17:07 - 2022-10-16 17:07 - 000010487 _____ () C:\Users\battl\AppData\Roaming\scripttodo.ps1
- ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku
- AlternateDataStreams: C:\Users\battl\AppData\Local\Temp:com.affinity.photo.2 [241]
- AlternateDataStreams: C:\Users\battl\AppData\Local\Temp:com.affinity.photo.3 [197]
- AlternateDataStreams: C:\Users\Public\AppData:CSM [474]
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Classes\.reg: => <==== UWAGA
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Classes\.bat: => <==== UWAGA
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Classes\.cmd: => <==== UWAGA
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell17win10.msn.com/?pc=DCTE
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
- SearchScopes: HKU\S-1-5-21-1928712825-2472657400-24126803-1001 -> DefaultScope {EEF017EE-74F7-489B-877A-FDC75E984B0A} URL =
- SearchScopes: HKU\S-1-5-21-1928712825-2472657400-24126803-1001 -> {EEF017EE-74F7-489B-877A-FDC75E984B0A} URL =
- Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - Brak pliku
- FirewallRules: [TCP Query User{E02A49A9-BFEE-43DD-9646-6870B6A0761D}I:\program files (x86)\dragon age\bin_ship\daorigins.exe] => (Allow) I:\program files (x86)\dragon age\bin_ship\daorigins.exe => Brak pliku
- FirewallRules: [UDP Query User{2FFDCD9C-946B-4679-96A1-436B1A87D72F}I:\program files (x86)\dragon age\bin_ship\daorigins.exe] => (Allow) I:\program files (x86)\dragon age\bin_ship\daorigins.exe => Brak pliku
- RemoveProxy:
- *****************
- Punkt przywracania został pomyślnie utworzony.
- Procesy zostały pomyślnie zamknięte.
- HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiSpyware"="0" => Wartość pomyślnie przywrócono
- HKLM\SOFTWARE\Microsoft\Windows Defender\\"DisableAntiVirus"="0" => Wartość pomyślnie przywrócono
- HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => pomyślnie usunięto
- HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => pomyślnie usunięto
- "HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => pomyślnie usunięto
- "HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Xvid" => pomyślnie usunięto
- "HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Windows\CurrentVersion\Run\\UrlsFile" => pomyślnie usunięto
- "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableTaskMgr" => pomyślnie usunięto
- "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD" => pomyślnie usunięto
- "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableRegistryTools" => pomyślnie usunięto
- C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono
- C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
- C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono
- C:\ProgramData\NTUSER.pol => pomyślnie przeniesiono
- HKLM\SOFTWARE\Policies\Mozilla => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{007EE8F4-02D8-4290-926A-22F29C864D25}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{007EE8F4-02D8-4290-926A-22F29C864D25}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\Avast Software\Overseer => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{46283DC6-18A8-4777-96AF-8D70D94E6DB8}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46283DC6-18A8-4777-96AF-8D70D94E6DB8}" => pomyślnie usunięto
- C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2774336-753F-4534-AE68-DD88A57440DC}" => nie znaleziono
- "C:\WINDOWS\System32\Tasks\{12EA3BA8-815A-715A-8A8A-681A8C47AD9E}" => nie znaleziono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{12EA3BA8-815A-715A-8A8A-681A8C47AD9E}" => nie znaleziono
- C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => pomyślnie przeniesiono
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6eccc877-e394-4617-8c3a-d4abd1d62b5d}\\DhcpNameServer" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{99df9e13-86ca-47a9-8b45-ab5ff39e89d5}\\DhcpNameServer" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9f2cce24-81fd-4df1-9ed5-beac232edd83}\\DhcpNameServer" => pomyślnie usunięto
- C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => ścieżki pomyślnie usunięto
- C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi => ścieżki pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\mracsvc => pomyślnie usunięto
- mracsvc => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\mracdrv => pomyślnie usunięto
- mracdrv => serwis pomyślnie usunięto
- C:\Users\battl\AppData\Roaming\gpg4win-2.2.5.exe => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\Nsudo.exe => pomyślnie przeniesiono
- C:\Program Files (x86)\GUTD232.tmp => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\KONOR.MTBF.txt => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\p9d2.dll => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\p9d2.dll.gpg => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\p9d2s.exe.gpg => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\runanddelete.bat => pomyślnie przeniesiono
- C:\Users\battl\AppData\Roaming\scripttodo.ps1 => pomyślnie przeniesiono
- HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => pomyślnie usunięto
- C:\Users\battl\AppData\Local\Temp => ":com.affinity.photo.2" ADS pomyślnie usunięto
- C:\Users\battl\AppData\Local\Temp => ":com.affinity.photo.3" ADS pomyślnie usunięto
- C:\Users\Public\AppData => ":CSM" ADS pomyślnie usunięto
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Classes\.reg => pomyślnie usunięto
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Classes\.bat => pomyślnie usunięto
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Classes\.cmd => pomyślnie usunięto
- HKLM\Software\\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" => Wartość pomyślnie przywrócono
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" => Wartość pomyślnie przywrócono
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\Software\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => Wartość pomyślnie przywrócono
- "HKU\S-1-5-21-1928712825-2472657400-24126803-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => pomyślnie usunięto
- HKU\S-1-5-21-1928712825-2472657400-24126803-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEF017EE-74F7-489B-877A-FDC75E984B0A} => pomyślnie usunięto
- HKLM\Software\Classes\PROTOCOLS\Handler\sacore => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E02A49A9-BFEE-43DD-9646-6870B6A0761D}I:\program files (x86)\dragon age\bin_ship\daorigins.exe" => pomyślnie usunięto
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2FFDCD9C-946B-4679-96A1-436B1A87D72F}I:\program files (x86)\dragon age\bin_ship\daorigins.exe" => pomyślnie usunięto
- ========= RemoveProxy: =========
- "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
- "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
- "HKU\S-1-5-21-1928712825-2472657400-24126803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
- "HKU\S-1-5-21-1928712825-2472657400-24126803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
- ========= Koniec RemoveProxy: =========
- =========== EmptyTemp: ==========
- FlushDNS => ukończone
- BITS transfer queue => 0 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10555785 B
- Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 821930258 B
- Windows/system/drivers => 22619915 B
- Edge => 65244 B
- Vivaldi => 1410016 B
- Firefox => 242543741 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Default => 6656 B
- ProgramData => 6656 B
- Public => 6656 B
- systemprofile => 20122330 B
- systemprofile32 => 20122394 B
- LocalService => 20122394 B
- NetworkService => 58216018 B
- battl => 138812246 B
- postgres => 138818902 B
- SSASTELEMETRY => 138818902 B
- SQLTELEMETRY => 138818902 B
- MSSQLServerOLAPService => 138818902 B
- MSSQLSERVER => 138818902 B
- RecycleBin => 0 B
- EmptyTemp: => 1.9 GB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 20:39:24 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement