Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 01-09-2021
- Uruchomiony przez Sebastian 2 (04-09-2021 12:05:31) Run:2
- Uruchomiony z H:\Users\Sebastian\Downloads
- Załadowane profile: Sebastian 2 & postgres & Administrator
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- 2021-09-04 04:48 - 2021-09-04 04:48 - 003062560 _____ (Realtek Semiconductor Corp.) C:\Users\Sebastian 2\AppData\Roaming\1696297.exe
- 2021-09-04 04:48 - 2021-09-04 04:48 - 000282112 _____ (hdgrfdgregre) C:\Users\Sebastian 2\AppData\Roaming\4792837.exe
- 2021-09-04 04:48 - 2021-09-04 04:48 - 000166912 _____ (sdvsdsdvds) C:\Users\Sebastian 2\AppData\Roaming\6052910.exe
- 2021-09-04 04:48 - 2021-09-04 04:48 - 000282112 _____ (hdgrfdgregre) C:\Users\Sebastian 2\AppData\Roaming\6784667.exe
- RemoveDirectory: C:\ProgramData\KSVJ4L5U1DBU3TY4J9QZ3HTLA
- S3 GVCIDrv; \??\C:\Program Files (x86)\GIGABYTE\RGBFusion\GVCIDrv64.sys [X]
- S2 iocbios2; \??\C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [X]
- S4 RAMDiskVE; System32\Drivers\RAMDiskVE.sys [X]
- S3 VGPU; System32\drivers\rdvgkmd.sys [X]
- S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\GIGABYTE\RGBFusion\MODAPI.sys [X]
- S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
- Task: {181ED6B7-6DBE-4EF9-AD61-5FD4DEFD7BDD} - System32\Tasks\{D1DA9553-5AA9-4A5A-9267-88B6A14F2CE5} => C:\Windows\system32\pcalua.exe -a "H:\Users\Sebastian\Downloads\dotNetFx35setup (1).exe" -d H:\Users\Sebastian\Downloads
- Task: {D66374E9-1347-4474-BD9D-A13C995B9886} - System32\Tasks\{2676CEC3-7C92-4DFE-9A0C-E2A05C50C351} => C:\Windows\system32\pcalua.exe -a "C:\Users\Sebastian 2\Downloads\DDU v18.0.2.1\Display Driver Uninstaller.exe" -d "C:\Users\Sebastian 2\Downloads\DDU v18.0.2.1"
- GroupPolicy: Ograniczenia ? <==== UWAGA
- Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA
- FirewallRules: [{368B294D-A676-42C2-A683-AF180D1526B7}] => (Allow) C:\Steam\steamapps\common\Mordhau\Mordhau.exe => Brak pliku
- FirewallRules: [{F75D3DC0-D4FA-42DF-B808-D52D05A47A69}] => (Allow) C:\Steam\steamapps\common\Mordhau\Mordhau.exe => Brak pliku
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP_TDI => ""="Driver Group"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Schedule => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Schedule => ""="Service"
- HOSTS:
- Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
- EmptyTemp:
- *****************
- "C:\Users\Sebastian 2\AppData\Roaming\1696297.exe" => nie znaleziono
- "C:\Users\Sebastian 2\AppData\Roaming\4792837.exe" => nie znaleziono
- "C:\Users\Sebastian 2\AppData\Roaming\6052910.exe" => nie znaleziono
- "C:\Users\Sebastian 2\AppData\Roaming\6784667.exe" => nie znaleziono
- "C:\ProgramData\KSVJ4L5U1DBU3TY4J9QZ3HTLA" => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\GVCIDrv => pomyślnie usunięto
- GVCIDrv => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\iocbios2 => pomyślnie usunięto
- iocbios2 => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\RAMDiskVE => pomyślnie usunięto
- RAMDiskVE => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\VGPU => pomyślnie usunięto
- VGPU => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0 => pomyślnie usunięto
- WinRing0_1_2_0 => serwis pomyślnie usunięto
- HKLM\System\CurrentControlSet\Services\xhunter1 => pomyślnie usunięto
- xhunter1 => serwis pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{181ED6B7-6DBE-4EF9-AD61-5FD4DEFD7BDD}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{181ED6B7-6DBE-4EF9-AD61-5FD4DEFD7BDD}" => pomyślnie usunięto
- C:\Windows\System32\Tasks\{D1DA9553-5AA9-4A5A-9267-88B6A14F2CE5} => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D1DA9553-5AA9-4A5A-9267-88B6A14F2CE5}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D66374E9-1347-4474-BD9D-A13C995B9886}" => pomyślnie usunięto
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D66374E9-1347-4474-BD9D-A13C995B9886}" => pomyślnie usunięto
- C:\Windows\System32\Tasks\{2676CEC3-7C92-4DFE-9A0C-E2A05C50C351} => pomyślnie przeniesiono
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2676CEC3-7C92-4DFE-9A0C-E2A05C50C351}" => pomyślnie usunięto
- C:\Windows\system32\GroupPolicy\Machine => pomyślnie przeniesiono
- C:\Windows\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
- C:\ProgramData\NTUSER.pol => pomyślnie przeniesiono
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{368B294D-A676-42C2-A683-AF180D1526B7}" => nie znaleziono
- "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F75D3DC0-D4FA-42DF-B808-D52D05A47A69}" => nie znaleziono
- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PNP_TDI => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Schedule => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MBAMService => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PAexec => pomyślnie usunięto
- HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Schedule => pomyślnie usunięto
- C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono
- Hosts pomyślnie przywrócono.
- ========= wevtutil el | Foreach-Object {wevtutil cl "$_"} =========
- ========= Koniec Powershell: =========
- =========== EmptyTemp: ==========
- BITS transfer queue => 8388608 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10478138 B
- Java, Flash, Steam htmlcache => 1014072156 B
- Windows/system/drivers => 4189324 B
- Edge => 0 B
- Chrome => 662834503 B
- Firefox => 298988 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Default => 0 B
- Public => 0 B
- ProgramData => 0 B
- systemprofile => 101090 B
- systemprofile32 => 167318 B
- LocalService => 299562 B
- NetworkService => 407910 B
- Sebastian 2 => 1793108454 B
- postgres => 1793108454 B
- Administrator => 1794407237 B
- DefaultAppPool => 1794407237 B
- RecycleBin => 14010465535 B
- EmptyTemp: => 21.3 GB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 12:10:22 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement