Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 22-03-2020 Uruchomiony przez SirKroko (22-03-2020 21:16:49) Run:2 Uruchomiony z C:\Users\SirKroko\Desktop Załadowane profile: SirKroko (Dostępne profile: SirKroko) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: EmptyTemp: HKLM\...\Run: [AVGUI.exe] => "C:\Program Files\AVG\Antivirus\AvLaunch.exe" /gui HKU\S-1-5-21-4037187918-1198607602-2718029985-1000\...\Run: [Norton Download Manager{NS22150088-SHPD-FSD5140133}] => C:\Users\SirKroko\AppData\Local\Temp\{27594057-99DE-42BA-AC3E-E415BAE49DDE}\Upgrade.exe [1926304 2020-01-21] (Symantec Corporation -> Symantec Corporation) <==== UWAGA Task: {497B8F7A-1A85-41F0-B5F0-3E8CDC75504D} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe Task: {6105C371-05B8-42BC-AE68-78B78B6AEF41} - System32\Tasks\Norton Security\Norton Security Error Processor => C:\Program Files\Norton Security\Engine\22.20.1.69\SymErr.exe Task: {699A2651-8466-49FE-80FE-047FBC1C9AD0} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe Task: {6FFEE45E-6D4C-49A9-ABBC-1A431277E2F3} - System32\Tasks\Norton Security\Norton Security Autofix => C:\Program Files\Norton Security\Engine\22.20.1.69\SymErr.exe Task: {8123AC6E-495F-49AA-A917-9CD631E56828} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security\Engine\22.20.1.69\WSCStub.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Tcpip\..\Interfaces\{099e88f7-e85a-438e-a919-1d6cd6fc9dc6}: [DhcpNameServer] 192.168.1.1 S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X] S3 SymEvnt; \??\C:\Program Files\Norton Security\NortonData\22.15.0.88\SymPlatform\SymEvnt.sys [X] ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => -> Brak pliku ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => -> Brak pliku ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => -> Brak pliku ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => -> Brak pliku ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => -> Brak pliku ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => -> Brak pliku CMD: ipconfig /flushdns RemoveProxy: Hosts: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AVGUI.exe" => pomyślnie usunięto "HKU\S-1-5-21-4037187918-1198607602-2718029985-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Norton Download Manager{NS22150088-SHPD-FSD5140133}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{497B8F7A-1A85-41F0-B5F0-3E8CDC75504D}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{497B8F7A-1A85-41F0-B5F0-3E8CDC75504D}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\AVG\Overseer => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG\Overseer" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6105C371-05B8-42BC-AE68-78B78B6AEF41}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6105C371-05B8-42BC-AE68-78B78B6AEF41}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Norton Security\Norton Security Error Processor => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Security\Norton Security Error Processor" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{699A2651-8466-49FE-80FE-047FBC1C9AD0}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{699A2651-8466-49FE-80FE-047FBC1C9AD0}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Antivirus Emergency Update => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Antivirus Emergency Update" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6FFEE45E-6D4C-49A9-ABBC-1A431277E2F3}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FFEE45E-6D4C-49A9-ABBC-1A431277E2F3}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Norton Security\Norton Security Autofix => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Security\Norton Security Autofix" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8123AC6E-495F-49AA-A917-9CD631E56828}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8123AC6E-495F-49AA-A917-9CD631E56828}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Norton WSC Integration => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration" => pomyślnie usunięto C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => pomyślnie przeniesiono "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{099e88f7-e85a-438e-a919-1d6cd6fc9dc6}\\DhcpNameServer" => pomyślnie usunięto HKLM\System\CurrentControlSet\Services\MBAMChameleon => pomyślnie usunięto MBAMChameleon => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\SymEvnt => pomyślnie usunięto SymEvnt => serwis pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OverlayExcluded => pomyślnie usunięto HKLM\Software\Classes\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C} => pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OverlayPending => pomyślnie usunięto HKLM\Software\Classes\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OverlayProtected => pomyślnie usunięto HKLM\Software\Classes\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148} => pomyślnie usunięto HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OverlayExcluded => pomyślnie usunięto HKLM\Software\Wow6432Node\Classes\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C} => pomyślnie usunięto HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OverlayPending => pomyślnie usunięto HKLM\Software\Wow6432Node\Classes\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => pomyślnie usunięto HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OverlayProtected => pomyślnie usunięto HKLM\Software\Wow6432Node\Classes\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148} => pomyślnie usunięto ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= Koniec CMD: ========= ========= RemoveProxy: ========= "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto "HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto "HKU\S-1-5-21-4037187918-1198607602-2718029985-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto "HKU\S-1-5-21-4037187918-1198607602-2718029985-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto ========= Koniec RemoveProxy: ========= C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. =========== EmptyTemp: ========== BITS transfer queue => 10248192 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12658079 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 1165466 B Edge => 6722932 B Chrome => 0 B Firefox => 1107074223 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 11774 B SirKroko => 19575881 B RecycleBin => 0 B EmptyTemp: => 1.1 GB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 21:17:57 ====