Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 27.01.2024 01 Uruchomiony przez Tomaszu (01-02-2024 18:26:49) Run:1 Uruchomiony z C:\Users\Tomaszu\Desktop Załadowane profile: Tomaszu Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CreateRestorePoint: CloseProcesses: EmptyEventLogs: EmptyTemp: HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Ograniczenia <==== UWAGA HKU\S-1-5-21-2312281861-1873309523-1155339195-1001\...\Run: [ProductAuthenticationService] => C:\Users\Tomaszu\AppData\Roaming\ProductAuthenticationService\pas.exe [1004072 2019-05-07] (ResolveDevOps Limited -> ResolveDevOps Limited) <==== UWAGA StartupDir: C:\Users\Tomaszu\AppData\Local\Temp\d887ceb89d\ <==== UWAGA GroupPolicy: Ograniczenia - Windows Defender <==== UWAGA Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA Task: {338379C5-75CB-4FB3-AF44-FBCF1D34E9B2} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2024-02-01] (Avast Software s.r.o. -> Avast Software) Task: {7A24DDA2-C284-4377-BAC2-B9B485750CA8} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2181560 2024-02-01] (AVG Technologies USA, LLC -> AVG Technologies) 2024-02-01 09:39 - 2024-02-01 09:39 - 000002184 __RSH C:\ProgramData\ntuser.pol CustomCLSID: HKU\S-1-5-21-2312281861-1873309523-1155339195-1001_Classes\CLSID\{1F3E8E93-3429-68D4-FFE7-ED0A7C201572}\InprocServer32 -> Brak ścieżki do pliku CustomCLSID: HKU\S-1-5-21-2312281861-1873309523-1155339195-1001_Classes\CLSID\{2E3E8E93-3429-68D4-FFE7-ED0A7C201572}\InprocServer32 -> Brak ścieżki do pliku AlternateDataStreams: C:\ProgramData:0849ff6b [710] AlternateDataStreams: C:\Users\All Users:0849ff6b [710] AlternateDataStreams: C:\ProgramData\Dane aplikacji:0849ff6b [710] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:0849ff6b [710] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [710] AlternateDataStreams: C:\Users\Tomaszu\Dane aplikacji:0849ff6b [710] AlternateDataStreams: C:\Users\Tomaszu\AppData\Roaming:0849ff6b [710] AlternateDataStreams: C:\Users\Tomaszu\Documents\GTA San Andreas User Files:0849ff6b [710] FirewallRules: [{F175505E-8EDB-441E-9F2C-EBD0025DB374}] => (Allow) E:\Różne rzeczy\Gry\TrackmaniaNext\trackmania.exe => Brak pliku FirewallRules: [{E04BB3F0-26AF-402B-83FF-B349644971C5}] => (Allow) E:\Różne rzeczy\Gry\TrackmaniaNext\trackmania.exe => Brak pliku FirewallRules: [{47260F29-8036-4B27-963A-03750FB88D6B}] => (Allow) E:\Różne rzeczy\Gry\TrackmaniaNext\trackmania.exe => Brak pliku FirewallRules: [{70C8B627-3251-4207-84CA-B941E33F865A}] => (Allow) E:\Różne rzeczy\Gry\TrackmaniaNext\trackmania.exe => Brak pliku FirewallRules: [{57FED6F0-3593-4B77-9B67-4B6C8F6B562A}] => (Allow) C:\Users\Tomaszu\Desktop\AnyDesk.exe => Brak pliku FirewallRules: [{5C6E2B9E-79BD-4762-8382-01AD695FB610}] => (Allow) C:\Users\Tomaszu\Desktop\AnyDesk.exe => Brak pliku FirewallRules: [{44381BA6-E885-4ECD-AD71-40D4C2FEEF88}] => (Allow) C:\Users\Tomaszu\Desktop\AnyDesk.exe => Brak pliku FirewallRules: [{7584636E-D223-4A54-B8CD-652303BB80FE}] => (Allow) C:\Users\Tomaszu\Desktop\AnyDesk.exe => Brak pliku FirewallRules: [{92F5A521-C577-457C-A6B4-20209B32DA8A}] => (Allow) C:\Users\Tomaszu\Desktop\AnyDesk.exe => Brak pliku FirewallRules: [{CEEB5262-B67A-4A3E-9C4C-45F9F6F164B0}] => (Allow) C:\Users\Tomaszu\Desktop\AnyDesk.exe => Brak pliku FirewallRules: [{7652CF87-89A7-411A-9527-D4C75ABD2AAB}] => (Allow) E:\Różne rzeczy\Gry\Em4.exe => Brak pliku FirewallRules: [UDP Query User{9B84B57A-66F3-4E66-8AAF-DB67E4F92A72}E:\różne rzeczy\gry\em4.exe] => (Block) E:\różne rzeczy\gry\em4.exe => Brak pliku FirewallRules: [TCP Query User{48E19299-F517-4BF2-8758-1E98010717E3}E:\różne rzeczy\gry\em4.exe] => (Block) E:\różne rzeczy\gry\em4.exe => Brak pliku FirewallRules: [{0D6D3D26-43B6-4BE4-B304-E5F20140F753}] => (Allow) C:\Users\Tomaszu\Desktop\AeroAdmin.exe => Brak pliku FirewallRules: [{BE937B51-1645-47B7-BA77-5A3C744F0BC8}] => (Allow) C:\Users\Tomaszu\Desktop\AeroAdmin.exe => Brak pliku FirewallRules: [TCP Query User{7852A771-32D8-4704-88DA-F38E68866AC4}C:\users\tomaszu\appdata\local\discord\app-1.0.9011\discord.exe] => (Allow) C:\users\tomaszu\appdata\local\discord\app-1.0.9011\discord.exe => Brak pliku FirewallRules: [UDP Query User{41939A29-D1A5-4677-8501-DFC46B002B70}C:\users\tomaszu\appdata\local\discord\app-1.0.9011\discord.exe] => (Allow) C:\users\tomaszu\appdata\local\discord\app-1.0.9011\discord.exe => Brak pliku FirewallRules: [{527664F1-275B-4AD6-A65C-3B7AA1AA4B04}] => (Allow) E:\Programy\CS16\Steam.exe => Brak pliku FirewallRules: [{66D22F0B-1C18-480F-B078-EF7147CE4907}] => (Allow) E:\Programy\CS16\Steam.exe => Brak pliku FirewallRules: [{5AB360D5-6F78-4793-9326-DF1420F65CB0}] => (Allow) C:\Users\Tomaszu\AppData\Roaming\uTorrent\uTorrent.exe => Brak pliku FirewallRules: [{9553ABC6-564C-4B4E-929A-7BCB780DBC31}] => (Allow) C:\Users\Tomaszu\AppData\Roaming\uTorrent\uTorrent.exe => Brak pliku FirewallRules: [{F2209525-F3AE-4D05-9A84-7FBABDBBE4A5}] => (Allow) C:\Users\Tomaszu\AppData\Roaming\utorrent\uTorrent.exe => Brak pliku FirewallRules: [{55080CC8-5152-4DCC-B9B4-59C5C96FDC4A}] => (Allow) C:\Users\Tomaszu\AppData\Roaming\utorrent\uTorrent.exe => Brak pliku ***************** Punkt przywracania został pomyślnie utworzony. Procesy zostały pomyślnie zamknięte. =========== EmptyEventLogs: ========== 1158 Event logs cleared. ================================ "HKLM\Software\Policies\Microsoft\Windows\System\\EnableSmartScreen" => pomyślnie usunięto HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => pomyślnie usunięto HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center => pomyślnie usunięto "HKU\S-1-5-21-2312281861-1873309523-1155339195-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ProductAuthenticationService" => pomyślnie usunięto StartupDir: C:\Users\Tomaszu\AppData\Local\Temp\d887ceb89d\ <==== UWAGA => pomyślnie przywrócono "C:\WINDOWS\system32\GroupPolicy\Machine" folder - przenoszenie: C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\ProgramData\NTUSER.pol => pomyślnie przeniesiono HKLM\SOFTWARE\Policies\Mozilla => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{338379C5-75CB-4FB3-AF44-FBCF1D34E9B2}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{338379C5-75CB-4FB3-AF44-FBCF1D34E9B2}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Avast Software\Overseer => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7A24DDA2-C284-4377-BAC2-B9B485750CA8}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A24DDA2-C284-4377-BAC2-B9B485750CA8}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\AVG\Overseer => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG\Overseer" => pomyślnie usunięto "C:\ProgramData\ntuser.pol" => nie znaleziono HKU\S-1-5-21-2312281861-1873309523-1155339195-1001_Classes\CLSID\{1F3E8E93-3429-68D4-FFE7-ED0A7C201572} => pomyślnie usunięto HKU\S-1-5-21-2312281861-1873309523-1155339195-1001_Classes\CLSID\{2E3E8E93-3429-68D4-FFE7-ED0A7C201572} => pomyślnie usunięto C:\ProgramData => ":0849ff6b" ADS pomyślnie usunięto "C:\Users\All Users" => ":0849ff6b" ADS nie znaleziono. "C:\ProgramData\Dane aplikacji" => ":0849ff6b" ADS nie znaleziono. C:\ProgramData\MTA San Andreas All => ":0849ff6b" ADS pomyślnie usunięto C:\ProgramData\MTA San Andreas All => ":NT" ADS pomyślnie usunięto C:\ProgramData\MTA San Andreas All => ":NT2" ADS pomyślnie usunięto C:\Users\Tomaszu\Dane aplikacji => ":0849ff6b" ADS pomyślnie usunięto "C:\Users\Tomaszu\AppData\Roaming" => ":0849ff6b" ADS nie znaleziono. C:\Users\Tomaszu\Documents\GTA San Andreas User Files => ":0849ff6b" ADS pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F175505E-8EDB-441E-9F2C-EBD0025DB374}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E04BB3F0-26AF-402B-83FF-B349644971C5}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{47260F29-8036-4B27-963A-03750FB88D6B}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{70C8B627-3251-4207-84CA-B941E33F865A}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{57FED6F0-3593-4B77-9B67-4B6C8F6B562A}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5C6E2B9E-79BD-4762-8382-01AD695FB610}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{44381BA6-E885-4ECD-AD71-40D4C2FEEF88}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7584636E-D223-4A54-B8CD-652303BB80FE}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{92F5A521-C577-457C-A6B4-20209B32DA8A}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CEEB5262-B67A-4A3E-9C4C-45F9F6F164B0}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7652CF87-89A7-411A-9527-D4C75ABD2AAB}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9B84B57A-66F3-4E66-8AAF-DB67E4F92A72}E:\różne rzeczy\gry\em4.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{48E19299-F517-4BF2-8758-1E98010717E3}E:\różne rzeczy\gry\em4.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0D6D3D26-43B6-4BE4-B304-E5F20140F753}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BE937B51-1645-47B7-BA77-5A3C744F0BC8}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7852A771-32D8-4704-88DA-F38E68866AC4}C:\users\tomaszu\appdata\local\discord\app-1.0.9011\discord.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{41939A29-D1A5-4677-8501-DFC46B002B70}C:\users\tomaszu\appdata\local\discord\app-1.0.9011\discord.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{527664F1-275B-4AD6-A65C-3B7AA1AA4B04}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{66D22F0B-1C18-480F-B078-EF7147CE4907}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5AB360D5-6F78-4793-9326-DF1420F65CB0}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9553ABC6-564C-4B4E-929A-7BCB780DBC31}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F2209525-F3AE-4D05-9A84-7FBABDBBE4A5}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{55080CC8-5152-4DCC-B9B4-59C5C96FDC4A}" => pomyślnie usunięto =========== EmptyTemp: ========== FlushDNS => ukończone BITS transfer queue => 1310720 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 86386756 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 554005438 B Windows/system/drivers => 680430 B Edge => 298916 B Chrome => 41703665 B Firefox => 112278951 B Opera => 386239706 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 5774 B NetworkService => 5774 B Tomaszu => 165097753 B DefaultAppPool => 165097753 B RecycleBin => 53660 B EmptyTemp: => 1.4 GB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 18:28:37 ====