Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 14-02-2022 01 Uruchomiony przez User (15-02-2022 09:42:01) Uruchomiony z C:\Users\User\Desktop\Ogólne\Inne\Naprawa Microsoft Windows 11 Home Wersja 21H2 22000.493 (X64) (2021-10-20 10:01:37) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= (Załączenie wejścia w fixlist spowoduje jego usunięcie.) Administrator (S-1-5-21-3523282509-3217289012-4007729472-500 - Administrator - Disabled) Gość (S-1-5-21-3523282509-3217289012-4007729472-501 - Limited - Enabled) Konto domyślne (S-1-5-21-3523282509-3217289012-4007729472-503 - Limited - Disabled) User (S-1-5-21-3523282509-3217289012-4007729472-1001 - Administrator - Enabled) => C:\Users\User WDAGUtilityAccount (S-1-5-21-3523282509-3217289012-4007729472-504 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: mks_vir (Enabled - Up to date) {44F188AD-B446-C4D8-C36C-70DFB0403719} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} FW: mks_vir (Enabled) {7CCA0988-FE29-C580-E833-D9EA4E937062} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Action! (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\Mirillis Action!) (Version: 4.22.0 - Mirillis) Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 21.011.20039 - Adobe Systems Incorporated) Adobe After Effects 2020 (HKLM-x32\...\AEFT_17_7) (Version: 17.7 - Adobe Inc.) Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version: 7.6.0.52 - Adobe Inc.) Adobe Illustrator 2020 (HKLM-x32\...\ILST_24_0_2) (Version: 24.0.2 - Adobe Inc.) Adobe Photoshop 2021 (HKLM-x32\...\PHSP_22_4_3) (Version: 22.4.3.317 - Adobe Inc.) Adobe Premiere Pro 2020 (HKLM-x32\...\PPRO_14_7) (Version: 14.7 - Adobe Inc.) AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 6.2.6 - AnyDesk Software GmbH) AnyMP4 Video Converter Ultimate 8.3.6 (HKLM-x32\...\{B77ACAAE-53EE-43c3-86F1-4AEA52F6CDD5}_is1) (Version: 8.3.6 - AnyMP4 Studio) Arduino (HKLM-x32\...\Arduino) (Version: 1.8.19 - Arduino LLC) ASTRONEER Jet Powered (HKLM-x32\...\ASTRONEER Jet Powered_is1) (Version: - ) Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1189.1 - AVAST Software) Hidden balenaEtcher 1.5.122 (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\d2f3b6c7-6f49-59e2-b8a5-f72e33900c2b) (Version: 1.5.122 - Balena Inc.) blender (HKLM\...\{8E411BEA-E05E-4E73-B9D3-A89A3084D67D}) (Version: 3.0.0 - Blender Foundation) blender (HKLM\...\{F1B2A72E-AF12-4F88-9E67-971A0105CF52}) (Version: 2.93.4 - Blender Foundation) BlueStacks 5 (HKLM\...\BlueStacks_nxt) (Version: 5.3.145.1003 - BlueStack Systems, Inc.) BlueStacks X (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\BlueStacks X) (Version: 0.11.1.9 - BlueStack Systems, Inc.) Care Center Service (HKLM\...\{AFB52E98-7597-4484-9202-58F0FD3512ED}) (Version: 4.00.3042 - Acer Incorporated) Chrome Remote Desktop Host (HKLM-x32\...\{B9B27527-C019-411B-9813-3FC8724C88DA}) (Version: 96.0.4664.39 - Google LLC) Cities Skylines Train Stations (HKLM-x32\...\Cities Skylines Train Stations_is1) (Version: - ) Clickteam Fusion Developer 2.5 R284.10 (HKLM-x32\...\Clickteam Fusion Developer 2.5 R284.10) (Version: - ) Creality Slicer 4.8.2 (HKLM-x32\...\Creality Slicer 4.8.2) (Version: 4.8.2 - Creality Company) Cube adventure (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\Cube adventure) (Version: - ) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.14.0.1762 - Disc Soft Ltd) Descript 31.1.1-release.20220126.4 (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\47d4069d-eba1-5137-bc5f-9c138f7a3859) (Version: 31.1.1-release.20220126.4 - Descript, Inc.) Discord (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\Discord) (Version: 1.0.9002 - Discord Inc.) DriverSetupUtility (HKLM\...\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}) (Version: 1.00.3026 - Acer Incorporated) Dynamic Application Loader Host Interface Service (HKLM\...\{BB78A7A1-B716-49D2-81C4-5A3ABE32C7E2}) (Version: 1.0.0.0 - Intel Corporation) Hidden FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line) Free File Viewer Pro 1.4 (HKLM-x32\...\Free File Viewer Pro_is1) (Version: - filetypeadvisor.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 98.0.4758.82 - Google LLC) Google Earth Pro (HKLM\...\{9BFB06CD-3925-49E2-BAB7-EA695821CE4C}) (Version: 7.3.4.8248 - Google) iCloud Outlook (HKLM\...\{841FC0A2-0DF9-475E-B342-AE7A6F42A90B}) (Version: 13.0.0.156 - Apple Inc.) Icy Tower v1.5.1 (HKLM-x32\...\Icy Tower v1.5.1_is1) (Version: - Free Lunch Design) ImageMagick 7.1.0-22 Q16-HDRI (64-bit) (2022-01-29) (HKLM\...\ImageMagick 7.1.0 Q16-HDRI (64-bit)_is1) (Version: 7.1.0.22 - ImageMagick Studio LLC) Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation) Intel(R) Chipset Device Software (HKLM-x32\...\{66879245-162d-47f5-bac4-840156a7c01e}) (Version: 10.1.18263.8193 - Intel(R) Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2004.14.0.1447 - Intel Corporation) Java 8 Update 301 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180301F0}) (Version: 8.0.3010.9 - Oracle Corporation) Java SE Development Kit 8 Update 301 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180301}) (Version: 8.0.3010.9 - Oracle Corporation) Killer Ethernet Performance Driver Suite UWD (HKLM\...\{1995E767-7D5D-4BC7-9B4B-A0A1220AAC58}) (Version: 2.2.1410 - Rivet Networks) KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - ) LED Sync (HKLM-x32\...\{417D2425-8783-46D4-97DF-EEF7CD17D656}) (Version: 1.1.1 - EVGA) LEGO MINDSTORMS EV3 (HKLM-x32\...\LEGO_SW.{5B0CB826-E499-4E6B-94F0-75B6327ED934}) (Version: 1.0.0 - The LEGO Group) LEGO MINDSTORMS NXT x64 Driver (HKLM\...\{0189C6FA-7333-4873-8E0B-3A1BE8E6726B}) (Version: 1.31.5.0 - LEGO) Lively Wallpaper version 1.7.4.2 (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\{E3E43E1B-DEC8-44BF-84A6-243DBA3F2CB1}}_is1) (Version: 1.7.4.2 - rocksdanister) Logi Bolt (HKLM\...\LogiBolt) (Version: 1.2.6024.0 - Logi) Logitech Options (HKLM\...\LogiOptions) (Version: 9.50.269 - Logitech) LogMeIn Hamachi (HKLM-x32\...\{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}) (Version: 2.2.0.633 - LogMeIn, Inc.) Hidden LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.633 - LogMeIn, Inc.) Malwarebytes version 4.4.10.144 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.10.144 - Malwarebytes) Math is easy (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\Math is easy) (Version: - ) Microsoft Access 2021 - pl-pl (HKLM\...\Access2021Retail - pl-pl) (Version: 16.0.14827.20192 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 98.0.1108.50 - Microsoft Corporation) Microsoft Excel 2021 - pl-pl (HKLM\...\Excel2021Retail - pl-pl) (Version: 16.0.14827.20192 - Microsoft Corporation) Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.002.0103.0004 - Microsoft Corporation) Microsoft PowerPoint 2021 - pl-pl (HKLM\...\PowerPoint2021Retail - pl-pl) (Version: 16.0.14827.20192 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Teams (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\Teams) (Version: 1.5.00.2164 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{2FA9DAAC-895B-4E99-99D9-DC2965FBE79C}) (Version: 2.87.0.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30040 (HKLM-x32\...\{5c6cccca-61ec-4667-a8d9-e133a59a5a73}) (Version: 14.29.30040.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.28.29334 (HKLM-x32\...\{b2d0f752-adc5-496e-8f70-8669de01f746}) (Version: 14.28.29334.0 - Microsoft Corporation) Microsoft Visual Studio Code (User) (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.64.0 - Microsoft Corporation) Microsoft Windows Desktop Runtime - 3.1.21 (x86) (HKLM-x32\...\{d1c9f155-e14a-4486-b545-dde658719aac}) (Version: 3.1.21.30622 - Microsoft Corporation) Microsoft Word 2021 - pl-pl (HKLM\...\Word2021Retail - pl-pl) (Version: 16.0.14827.20192 - Microsoft Corporation) Minecraft Dungeons Echoing Void (HKLM-x32\...\Minecraft Dungeons Echoing Void_is1) (Version: - ) Minecraft Launcher (HKLM-x32\...\{733C3ACB-432D-4880-B0E1-660000D7974D}) (Version: 1.0.0.0 - Mojang) mks_vir (HKLM\...\mks_vir) (Version: - Arcabit/mks_vir) NitroSense Service (HKLM\...\{6FC78E80-6385-43D6-8A43-FA80094F1A2E}) (Version: 3.01.3016 - Acer Incorporated) Npcap (HKLM-x32\...\NpcapInst) (Version: 1.31 - Nmap Project) NVIDIA FrameView SDK 1.2.7321.30900954 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.7321.30900954 - NVIDIA Corporation) NVIDIA GeForce Experience 3.25.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.25.0.84 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.3.39.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.39.3 - NVIDIA Corporation) NVIDIA Sterownik graficzny 511.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 511.65 - NVIDIA Corporation) NVIDIA USBC Driver 1.46.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.46.831.832 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14827.20088 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14827.20158 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0415-1000-0000000FF1CE}) (Version: 16.0.14827.20088 - Microsoft Corporation) Hidden Outlook (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\6b0f23e57a39ebfbf2814acb1a24293d) (Version: 1.0 - Outlook) Pakiet sterowników systemu Windows - Adafruit Industries LLC (usbser) Ports (02/25/2016 6.2.2600.0) (HKLM\...\1245A5961AC9D2C18ADF9EEC931D77E059B7F74E) (Version: 02/25/2016 6.2.2600.0 - Adafruit Industries LLC) Pakiet sterowników systemu Windows - Arduino LLC (www.arduino.cc) Arduino USB Driver (11/24/2015 1.2.3.0) (HKLM\...\8B585560B248755A6C5A24D5C0F50FA998310883) (Version: 11/24/2015 1.2.3.0 - Arduino LLC (www.arduino.cc)) Pakiet sterowników systemu Windows - Arduino LLC (www.arduino.cc) Genuino USB Driver (01/07/2016 1.0.3.0) (HKLM\...\EC414D98E2986DCA1628FAED2163CD1C9A4ED7EC) (Version: 01/07/2016 1.0.3.0 - Arduino LLC (www.arduino.cc)) Pakiet sterowników systemu Windows - libusb-win32 (libusb0) libusb-win32 devices (04/21/2015 1.0.0.0) (HKLM\...\28E91B69CA377EB48D6E1B92C37F897036E8A818) (Version: 04/21/2015 1.0.0.0 - libusb-win32) Pakiet sterowników systemu Windows - VeiKk (WinUsb) USBVeiKk (03/23/2021 1.0.0.2) (HKLM\...\DB72FAA5C65658B5A000C77AA3E6ABF773CF7813) (Version: 03/23/2021 1.0.0.2 - VeiKk) Please Dont Touch Anything 3D v21.01.2017 (HKLM-x32\...\vsetop.com Please Dont Touch Anything 3D v21.01.2017_is1) (Version: 21.01.2017 - VseTop.Com) PuTTY release 0.76 (64-bit) (HKLM\...\{1E0D5689-40F1-4E46-ABBB-EAAC68B5CD89}) (Version: 0.76.0.0 - Simon Tatham) Python 3.10.2 (64-bit) (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\{c60fd5ac-367d-4e3a-a975-f157502ac30a}) (Version: 3.10.2150.0 - Python Software Foundation) Python 3.10.2 Core Interpreter (64-bit) (HKLM\...\{6475B354-B0F6-4837-8738-784937D647B2}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Development Libraries (64-bit) (HKLM\...\{8277936D-8A34-4758-893C-0B29342A6F27}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Documentation (64-bit) (HKLM\...\{B51A07AD-9BCE-485D-8721-C7C83992794B}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Executables (64-bit) (HKLM\...\{EDEE3162-8399-42D4-9D7C-7DA21275BFD0}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 pip Bootstrap (64-bit) (HKLM\...\{08B7036F-0609-4634-9A5F-1688230E9D9D}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Standard Library (64-bit) (HKLM\...\{D862D299-FDC2-4571-B3A1-27CEE951D2D1}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Tcl/Tk Support (64-bit) (HKLM\...\{7863DF45-23BB-4D83-97B3-CF08F3192F5B}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Test Suite (64-bit) (HKLM\...\{D68594E9-2F98-4EA0-8A94-5D7D9FF51960}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python 3.10.2 Utility Scripts (64-bit) (HKLM\...\{300F0759-8294-4971-9FAD-7AB19FA7B270}) (Version: 3.10.2150.0 - Python Software Foundation) Hidden Python Launcher (HKLM-x32\...\{0CD41B07-EDF9-4B77-8C7C-CCCA1C435970}) (Version: 3.10.7686.0 - Python Software Foundation) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.5.10 - Rainmeter) Raspberry Pi Imager (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\Raspberry Pi Imager) (Version: 1.6.2 - Raspberry Pi) Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9054.1 - Realtek Semiconductor Corp.) SD Card Formatter (HKLM-x32\...\{A61131DC-B92D-4AD8-A925-E2D6D5FE217C}) (Version: 5.0.1 - SD Association) Splash (HKLM-x32\...\Mirillis Splash) (Version: 2.7.0 - Mirillis) Sprawdzanie kondycji komputera z systemem Windows (HKLM\...\{645FE595-D9DD-4BD7-AB97-AFF65B8FBD62}) (Version: 3.1.2109.29003 - Microsoft Corporation) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Środowisko uruchomieniowe Microsoft Edge WebView2 (HKLM-x32\...\Microsoft EdgeWebView) (Version: 98.0.1108.50 - Microsoft Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.5.6 - TeamSpeak Systems GmbH) Tofel Fighter 1 (HKLM-x32\...\Tofel Fighter 1) (Version: - ) UE4 Prerequisites (x64) (HKLM\...\{F9EC45F9-074A-48BF-92E9-A8CADD56F693}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{4e242cc8-5e3c-4b08-9d55-dbc62ddd1208}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden VKTabletDriver (HKLM\...\DC6C14C4-4F50-4976-9A7D-191E107219FD_is1) (Version: 2.0.3.3 - Shenzhen Hezon Lito Technology Co.,Ltd.) Voicemod (HKLM\...\{8435A407-F778-4647-9CDB-46E5EC50BAD0}_is1) (Version: 2.25.0.4 - Voicemod S.L.) WhatsApp (HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\WhatsApp) (Version: 2.2140.7 - WhatsApp) Windows Deployment Tools (HKLM-x32\...\{C4443D4E-AC00-CF0E-9519-C9111E83ADBB}) (Version: 10.1.17134.1 - Microsoft) Windows PE x86 x64 (HKLM-x32\...\{346FC109-E9A8-2224-5726-843C7283E4F7}) (Version: 10.1.17134.1 - Microsoft) Windows PE x86 x64 wims (HKLM-x32\...\{64FF0563-D6F1-C8E4-56F8-F678D1158C58}) (Version: 10.1.17134.1 - Microsoft) WinRAR 6.02 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 6.02.0 - win.rar GmbH) Packages: ========= Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2021-09-21] (Adobe Systems Incorporated) Adobe Acrobat DC -> C:\Program Files (x86)\Adobe\Acrobat DC [2022-01-12] (0) Care Center S -> C:\Program Files\WindowsApps\AcerIncorporated.AcerCareCenterS_4.0.3042.0_x64__48frkmn4z8aw4 [2022-01-11] (Acer Incorporated) Centrum sterowania grafiką Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3370.0_x64__8j3eq9eme6ctt [2021-12-15] (INTEL CORP) [Startup Task] Clipchamp -> C:\Program Files\WindowsApps\Clipchamp.Clipchamp_1.6.0.0_neutral__yxz26nhyzhsrt [2022-02-07] (Clipchamp) Dodatek Aparat multimediów dla aplikacji Zdjęcia -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-08-05] (Microsoft Corporation) DTS Sound Unbound -> C:\Program Files\WindowsApps\DTSInc.DTSSoundUnbound_2022.1.3.0_x64__t5j2fzbtdg37r [2022-02-10] (DTS, Inc.) DTS:X Ultra -> C:\Program Files\WindowsApps\DTSInc.DTSXUltra_1.11.3.0_x64__t5j2fzbtdg37r [2022-01-03] (DTS, Inc.) Files -> C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t [2022-02-13] (Yair A) [Startup Task] HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_134.1.221.0_x64__v10z8vjag6ke6 [2022-01-27] (HP Inc.) iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa [2022-01-24] (Apple Inc.) [Startup Task] Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1020.0_x64__8j3eq9eme6ctt [2021-12-15] (INTEL CORP) iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa [2021-12-21] (Apple Inc.) [Startup Task] Killer Control Center -> C:\Program Files\WindowsApps\RivetNetworks.KillerControlCenter_2.2.3216.0_x64__rh07ty8m5nkag [2021-12-15] (Rivet Networks LLC) [Startup Task] Messenger -> C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_1390.5.116.0_x64__8xx8rvfyw5nnt [2022-02-09] (Facebook Inc) [Startup Task] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-10-20] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-10-20] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.1050.0_x64__8wekyb3d8bbwe [2022-01-13] (Microsoft Studios) [MS Ad] Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_52.10201.5809.0_x64__8wekyb3d8bbwe [2022-02-03] (Microsoft Corporation) Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.18.1004.0_x64__8wekyb3d8bbwe [2022-02-09] (Microsoft Studios) Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_1.0.113.0_x64__8wekyb3d8bbwe [2022-01-03] (Microsoft Studios) Minesweeper Saperka Superka -> C:\Program Files\WindowsApps\11719Pikos.MinesweeperSaperkaSuperka_1.0.1.0_x64__8p54f0g1nyk2a [2022-02-11] (Pikos) NitroSense_V31 -> C:\Program Files\WindowsApps\AcerIncorporated.NitroSenseV31_3.1.3016.0_x64__48frkmn4z8aw4 [2021-05-26] (Acer Incorporated) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.962.0_x64__56jybvy8sckqj [2022-02-07] (NVIDIA Corp.) Picsart - Photo Studio -> C:\Program Files\WindowsApps\2FE3CB00.PICSART-PHOTOSTUDIO_9.4.0.0_x64__crhqpqs3x1ygc [2022-01-03] (PicsArt Inc.) Power Automate -> C:\Program Files\WindowsApps\Microsoft.PowerAutomateDesktop_10.0.2953.0_x64__8wekyb3d8bbwe [2022-02-01] (Microsoft Corporation) [Startup Task] PowerPoint -> C:\Program Files\WindowsApps\powerpoint.office.com-8D456796_1.0.0.0_neutral__sxc7ffma4ybfy [2022-02-07] (powerpoint.office.com) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.26.251.0_x64__dt26b99r8h8gj [2021-12-15] (Realtek Semiconductor Corp) SketchPal -> C:\Program Files\WindowsApps\Microsoft.SketchPal_1.2.11.0_x64__8wekyb3d8bbwe [2022-01-03] (Microsoft Corporation) WhatsApp Desktop -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2202.12.0_x64__cv1g1gvanyjgm [2022-02-05] (WhatsApp Inc.) Wikipedia -> C:\Program Files\WindowsApps\WikimediaFoundation.Wikipedia_1.0.1.0_neutral__54ggd3ev8bvz6 [2022-02-07] (Wikimedia Foundation) ==================== Niestandardowe rejestracje CLSID (filtrowane): ============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-3523282509-3217289012-4007729472-1001_Classes\CLSID\{04271989-C4D2-52B4-650A-83A1F32C0F41} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6} CustomCLSID: HKU\S-1-5-21-3523282509-3217289012-4007729472-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.21348.1\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3523282509-3217289012-4007729472-1001_Classes\CLSID\{82716A83-79F0-49E3-B17D-6C2775F17AEA} -> [iCloud Drive] => C:\Users\User\iCloudDrive [2021-11-26 17:01] CustomCLSID: HKU\S-1-5-21-3523282509-3217289012-4007729472-1001_Classes\CLSID\{89b2b650-c4dd-d68b-46e7-3176f1973c8b}\localserver32 -> C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod) CustomCLSID: HKU\S-1-5-21-3523282509-3217289012-4007729472-1001_Classes\CLSID\{ECF72A79-D6F8-4CD4-924F-73C92B972463} -> [Zdjęcia iCloud] => C:\Users\User\Pictures\iCloud Photos\Photos [2021-11-26 17:01] ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-11-08] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-11-08] (Adobe Inc. -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-11-08] (Adobe Inc. -> ) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-11-08] (Adobe Inc. -> ) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2021-12-24] (Adobe Inc. -> Adobe Systems Inc.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2021-09-01] (AVB Disc Soft, SIA -> Disc Soft Ltd) ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2021-09-01] (AVB Disc Soft, SIA -> Disc Soft Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-02-14] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.002.0103.0004\FileSyncShell64.dll [2022-01-27] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nvaci.inf_amd64_94944f9da089b579\nvshext.dll [2022-01-29] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2021-11-08] (Adobe Inc. -> ) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2021-12-24] (Adobe Inc. -> Adobe Systems Inc.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2022-02-14] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-15] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Drivers32: [VIDC.FICV] => C:\Windows\system32\ficvdec_x64.dll [652288 2013-05-28] () [Brak podpisu cyfrowego] HKLM\...\Drivers32: [VIDC.FICV] => C:\Windows\SysWOW64\ficvdec_x86.dll [641024 2013-05-28] () [Brak podpisu cyfrowego] ==================== Skróty & WMI ======================== (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bjhmmnoficofgoiacjaajpkfndojknpb ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Chrome Remote Desktop.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=efmjfjelnicpmdcmfikempdhlmainjcb ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\dobreprogramy - forum.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=eniaajhhmhnfphcohdlgopjceodeimch ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Google Duo.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=imgohncinckhbblnlmaedahepnnpmdma ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\login with paysafecard.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=fcekgojanedchpjcgdncianipihbconh ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Messages.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=hpfldicfbfomlpcikngkocigghgafkph ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\YouTube Music.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=cinhimbnkkaeohfgghhklpknlkffjgod ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\YouTube.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=agimnkijcaahngcdmfeangaknmldooml ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\dobreprogramy - forum.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 1" --app-id=eniaajhhmhnfphcohdlgopjceodeimch ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Tomineba STARY KANAŁ - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1" ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Tamara - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 3" ==================== Załadowane moduły (filtrowane) ============= 2022-02-11 13:34 - 2022-02-11 13:34 - 000175104 _____ () [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\FilesFullTrust.dll 2022-02-05 16:57 - 2021-11-05 06:17 - 000939520 _____ () [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\cef\CefSharp.BrowserSubprocess.Core.dll 2022-02-05 16:57 - 2021-11-05 06:18 - 001419264 _____ () [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\cef\CefSharp.Core.Runtime.dll 2022-02-05 16:57 - 2021-10-30 12:43 - 137802752 _____ () [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\cef\libcef.dll 2022-02-05 16:57 - 2021-10-30 11:24 - 000334848 _____ () [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\cef\libegl.dll 2022-02-05 16:57 - 2021-10-30 11:24 - 005743616 _____ () [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\cef\libglesv2.dll 2015-03-17 00:34 - 2015-03-17 00:34 - 000010240 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\locale\pl_pl\AcroTray.pol 2022-02-01 13:17 - 2022-02-01 13:17 - 000182784 _____ () [Brak podpisu cyfrowego] C:\Program Files\Rainmeter\Plugins\AudioLevel.DLL 2022-02-07 11:19 - 2022-02-07 11:19 - 001497600 _____ () [Brak podpisu cyfrowego] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\e_sqlite3.dll 2022-02-11 13:34 - 2022-02-11 13:34 - 031600640 _____ () [Brak podpisu cyfrowego] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.dll 2022-01-06 09:05 - 2022-01-06 09:05 - 000144896 _____ () [Brak podpisu cyfrowego] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\libssh2.dll 2022-01-06 09:05 - 2022-01-06 09:05 - 000077824 _____ () [Brak podpisu cyfrowego] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\zlib.dll 2022-02-05 16:57 - 2020-04-17 02:01 - 000244224 _____ () [Brak podpisu cyfrowego] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\MSVCP140_APP.dll 2022-02-05 16:57 - 2020-04-17 02:01 - 000013312 _____ () [Brak podpisu cyfrowego] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\VCRUNTIME140_APP.dll 2022-02-05 16:29 - 2022-02-05 16:29 - 000088064 _____ () [Brak podpisu cyfrowego] C:\Users\User\AppData\Roaming\Rainmeter\Plugins\MouseXY.DLL 2022-02-11 13:34 - 2022-02-11 13:34 - 000032256 _____ (Common) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Common.dll 2022-02-05 16:57 - 2020-10-13 07:59 - 000179712 _____ (Dominic Jonas) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\NLogViewer.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000149504 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.Core.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000114176 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.ComCtl32.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000134144 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.Gdi32.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000636928 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.Kernel32.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000441344 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.Ole.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000585216 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.Shared.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000390144 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.Shell32.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000242688 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.PInvoke.User32.dll 2022-02-07 11:19 - 2022-02-07 11:21 - 000277504 _____ (GitHub Community) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Vanara.Windows.Shell.dll 2022-02-05 16:57 - 2021-02-21 23:00 - 001004544 _____ (GitHub) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\Octokit.dll 2022-02-05 16:57 - 2021-04-30 15:35 - 000056832 _____ (Linearstar) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\RawInput.Sharp.dll 2022-02-05 16:57 - 2021-02-08 01:09 - 000007680 _____ (livelySubProcess) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\subproc\livelySubProcess.dll 2022-02-05 16:57 - 2021-11-30 22:08 - 001132544 _____ (livelywpf) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\livelywpf.dll 2022-02-05 16:57 - 2021-11-30 22:08 - 000024576 _____ (livelywpf) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\pl\livelywpf.resources.dll 2022-02-05 16:57 - 2020-01-25 11:39 - 000005120 _____ (Matteo Pagani) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\DesktopBridge.Helpers.dll 2022-02-07 11:19 - 2022-02-07 11:20 - 000361984 _____ (Maurício David) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\LiteDB.dll 2022-02-07 11:19 - 2022-02-07 11:20 - 000114688 _____ (Microsoft Corporation) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Microsoft.Management.Infrastructure.dll 2022-02-07 11:19 - 2022-02-07 11:20 - 000142336 _____ (Microsoft Corporation) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Microsoft.Management.Infrastructure.Native.dll 2022-02-07 11:19 - 2022-02-07 11:20 - 000123904 _____ (Microsoft Corporation) [Brak podpisu cyfrowego] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\mi.dll 2022-02-07 11:19 - 2022-02-07 11:20 - 000017920 _____ (Microsoft Corporation) [Brak podpisu cyfrowego] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\Microsoft.Management.Infrastructure.Native.Unmanaged.DLL 2022-02-07 11:19 - 2022-02-07 11:20 - 000239616 _____ (Microsoft Corporation) [Brak podpisu cyfrowego] C:\Program Files\WindowsApps\49306atecsolution.FilesUWP_2.1.13.0_x64__et10x9a9vyk8t\Files.Launcher\miutils.dll 2021-11-26 12:31 - 2021-11-26 12:31 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\Root\Office16\AppVIsvSubsystems64.dll 2021-11-26 12:31 - 2021-11-26 12:31 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\Root\Office16\c2r64.dll 2022-02-05 16:57 - 2021-03-23 17:33 - 000914944 _____ (ModernWpf) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\ModernWpf.dll 2022-02-05 16:57 - 2021-03-23 17:33 - 000007168 _____ (ModernWpf) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\pl-PL\ModernWpf.resources.dll 2022-02-05 16:57 - 2021-03-23 17:34 - 000702464 _____ (ModernWpf.Controls) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\ModernWpf.Controls.dll 2022-02-05 16:57 - 2021-10-24 23:54 - 000822272 _____ (NLog) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\NLog.dll 2022-02-05 16:29 - 2022-02-05 16:29 - 000316928 _____ (Socks the Fox) [Brak podpisu cyfrowego] C:\Users\User\AppData\Roaming\Rainmeter\Plugins\Chameleon.DLL 2022-02-05 16:57 - 2021-10-30 11:29 - 000965120 _____ (The Chromium Authors) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Users\User\AppData\Local\Programs\Lively Wallpaper\plugins\cef\chrome_elf.dll 2022-01-06 09:05 - 2022-01-06 09:05 - 000355840 _____ (The cURL library, hxxp://curl.haxx.se/) [Brak podpisu cyfrowego] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBCURL.dll 2022-01-06 09:05 - 2022-01-06 09:05 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Brak podpisu cyfrowego] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBEAY32.dll 2022-01-06 09:05 - 2022-01-06 09:05 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Brak podpisu cyfrowego] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\SSLEAY32.dll ==================== Alternate Data Streams (filtrowane) ======== ==================== Tryb awaryjny (filtrowane) ================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Powiązania plików (filtrowane) ================= ==================== Internet Explorer (filtrowane) ========== BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_301\bin\ssv.dll [2021-08-08] (Oracle America, Inc. -> Oracle Corporation) BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2021-09-09] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_301\bin\jp2ssv.dll [2021-08-08] (Oracle America, Inc. -> Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2021-09-09] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-11-26] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2021-09-09] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2021-09-09] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2021-09-09] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2021-09-09] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-02-03] (Microsoft Corporation -> Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) IE trusted site: HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\sharepoint.com -> hxxps://obornikiedu-files.sharepoint.com ==================== Hosts - zawartość: ========================= (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2019-12-07 10:14 - 2022-02-11 13:48 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost ==================== Inne obszary =========================== (Obecnie brak automatycznej naprawy dla tej sekcji.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\ImageMagick-7.1.0-Q16-HDRI;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\IVI Foundation\VISA\WinNT\Bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\PuTTY\;C:\Program Files (x86)\dotnet\ HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.8.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Zapora systemu Windows [funkcja wyłączona] Network Binding: ============= Hamachi: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Wi-Fi: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Ethernet: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) Połączenie sieciowe Bluetooth: Npcap Packet Driver (NPCAP) -> INSECURE_NPCAP (enabled) ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Załączenie wejścia w fixlist spowoduje jego usunięcie.) HKLM\...\StartupApproved\StartupFolder: => "AnyDesk.lnk" HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\StartupApproved\Run: => "utweb" HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-3523282509-3217289012-4007729472-1001\...\StartupApproved\Run: => "ut" ==================== Reguły Zapory systemu Windows (filtrowane) ================ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [TCP Query User{F468232A-782C-4386-AF14-03CFA72EB0FB}C:\Program Files (x86)\LEGO Software\LEGO MINDSTORMS EV3 Home Edition\MindstormsEV3.exe] => (Allow) C:\Program Files (x86)\LEGO Software\LEGO MINDSTORMS EV3 Home Edition\MindstormsEV3.exe (National Instruments) [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{68E46633-8DC3-499C-A590-8A85F5FE92AD}C:\Program Files (x86)\LEGO Software\LEGO MINDSTORMS EV3 Home Edition\MindstormsEV3.exe] => (Allow) C:\Program Files (x86)\LEGO Software\LEGO MINDSTORMS EV3 Home Edition\MindstormsEV3.exe (National Instruments) [Brak podpisu cyfrowego] FirewallRules: [{621E4619-85A8-4D6E-A39B-992AC1A4DA76}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\planets under attack\game.exe (Targem Games) [Brak podpisu cyfrowego] FirewallRules: [{EE016A1F-1F6D-4700-A03D-59DB9745EDFE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\planets under attack\game.exe (Targem Games) [Brak podpisu cyfrowego] FirewallRules: [{FEBE6AE1-1FBE-4D90-A047-7A61EC78BFDB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Smart Thief\Smart Thief.exe () [Brak podpisu cyfrowego] FirewallRules: [{8648E0A6-39FF-424A-B049-DEA8E71C590C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Smart Thief\Smart Thief.exe () [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{C814D613-75DE-4276-BE7C-A12CD73DEEFA}C:\program files\java\jdk1.8.0_301\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_301\bin\java.exe FirewallRules: [TCP Query User{2B26BD7E-DF92-4B83-BAD4-B04D827ECC4B}C:\program files\java\jdk1.8.0_301\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_301\bin\java.exe FirewallRules: [UDP Query User{98218B12-524A-4D2F-A3CB-3950EC842492}C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe FirewallRules: [TCP Query User{D5A0A491-BD72-48D2-8F33-9937680E182F}C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe FirewallRules: [UDP Query User{2DB19BB1-3CBC-42C5-9252-F6155D5FCE04}C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe FirewallRules: [TCP Query User{75958B4B-1DD7-49DA-99E2-E89E1B68F598}C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_263544265\java.exe FirewallRules: [{B7195CC7-4C13-4C6E-B874-6C41A723EB7C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Iron Sky Invasion\ISI_DX9.exe () [Brak podpisu cyfrowego] FirewallRules: [{B3EDD786-BBB7-43B7-B27B-E6B9C6888C3A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Iron Sky Invasion\ISI_DX9.exe () [Brak podpisu cyfrowego] FirewallRules: [{DC702262-9D51-4EFC-BAF0-A97072886609}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Iron Sky Invasion\ISI_DX11.exe () [Brak podpisu cyfrowego] FirewallRules: [{55102038-9159-4060-8911-0B91BA2CB47D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Iron Sky Invasion\ISI_DX11.exe () [Brak podpisu cyfrowego] FirewallRules: [{9239128D-C25F-4DB6-B5AA-AD4AAB1B359A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Geometry Dash\GeometryDash.exe () [Brak podpisu cyfrowego] FirewallRules: [{914ABA47-5E24-4495-AC80-508737340C29}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Geometry Dash\GeometryDash.exe () [Brak podpisu cyfrowego] FirewallRules: [{507C5E6A-3E15-4C4C-8D99-51FAEB11BB28}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\My Loved Heart\win64\nw.exe (The NWJS Community) [Brak podpisu cyfrowego] FirewallRules: [{DF768467-8B53-4236-A56C-ED6A1F57CCDC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\My Loved Heart\win64\nw.exe (The NWJS Community) [Brak podpisu cyfrowego] FirewallRules: [{82EF0DD6-1CC7-4593-8E67-D35CEDCFD043}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{C91C1CC7-C641-42FB-8168-700298E83320}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{835EF9D5-2A63-457E-AB0D-99498861F644}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{1F9DBAD3-F41A-4E5B-8103-09DD2241AF64}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{71E55CD6-52FF-443C-AD89-66A5136F2F3C}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd) FirewallRules: [{785042CB-2D0D-469A-95A6-98AC7B1C2218}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd) FirewallRules: [UDP Query User{56FA7F49-BDE0-49A0-8133-362BE9C63E4C}C:\program files (x86)\mirillis\action!\action.exe] => (Allow) C:\program files (x86)\mirillis\action!\action.exe (Mirillis Sp. z o.o. -> Mirillis Ltd.) FirewallRules: [TCP Query User{C5CA5BF9-F228-4E44-8AA0-AA4560073602}C:\program files (x86)\mirillis\action!\action.exe] => (Allow) C:\program files (x86)\mirillis\action!\action.exe (Mirillis Sp. z o.o. -> Mirillis Ltd.) FirewallRules: [UDP Query User{6F21C075-5E76-4B23-B307-10B9C55F2A52}C:\users\user\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\user\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe FirewallRules: [TCP Query User{E2A0CDAC-0C18-44D8-B0B5-EF536C0D575C}C:\users\user\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe] => (Allow) C:\users\user\appdata\roaming\.tlauncher\jvms\jre1.8.0_281\bin\javaw.exe FirewallRules: [UDP Query User{C1C3B191-9CEE-4B5B-BA8D-540335D3D611}C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe] => (Allow) C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe FirewallRules: [TCP Query User{4A63F7D8-DC54-4C45-B7B1-E05028CCAFD7}C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe] => (Allow) C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe FirewallRules: [UDP Query User{D5E23563-9430-4A3B-B380-E9D4DF1077EF}C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe FirewallRules: [TCP Query User{B28A9798-FF73-470D-8296-4E70776CD797}C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe FirewallRules: [UDP Query User{94740058-843B-40D7-BEA5-202F32CECE2F}C:\users\user\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\user\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{8676F840-D35F-4740-B1FF-88E8E70997F9}C:\users\user\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\user\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{7E14A823-6BA0-47B4-BD70-82248BC6DD37}C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe] => (Block) C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe FirewallRules: [TCP Query User{37A9D37E-6696-478C-BFA8-2C9DBA012591}C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe] => (Block) C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe FirewallRules: [UDP Query User{357AF10C-1843-4BD9-A5DD-37809F3F03EB}C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe FirewallRules: [TCP Query User{BC13F31A-EC90-4014-A668-35B9DAF43A85}C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe FirewallRules: [UDP Query User{1AC6FD91-DD74-4FC4-8F42-AFD9E1179021}C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe] => (Block) C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe FirewallRules: [TCP Query User{29534DA7-E3A4-49B7-99F2-23D3B272BDE9}C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe] => (Block) C:\users\user\appdata\roaming\.minecraft\sigma\jre1.8.0_202\bin\java.exe FirewallRules: [UDP Query User{EBDDFAE9-6D95-4521-87DC-BA5E060E8F92}C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe FirewallRules: [TCP Query User{57DEB75F-57C3-4BB4-8319-81E65BA14798}C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-legacy\windows-x64\jre-legacy\bin\javaw.exe FirewallRules: [UDP Query User{70DCDED0-9624-43D0-B3C5-04E36C142570}C:\users\user\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\user\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{48FB872E-8D59-42CB-A89D-4B574E6AF535}C:\users\user\appdata\local\programs\microsoft vs code\code.exe] => (Allow) C:\users\user\appdata\local\programs\microsoft vs code\code.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{C371EDAB-A459-4065-BB06-50C4A8CF5C59}C:\users\user\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\user\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{D3B78A7A-733B-42FC-AF70-9DD3E8903671}C:\users\user\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\user\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{AFA7498A-D0DD-48DC-BD77-80661BE249DD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{705C0DF2-DA11-467B-8D12-728E379FC275}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{42560C94-0FD0-4132-8341-56A407AA31B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fairytales Three Heroes\bin\Game.exe () [Brak podpisu cyfrowego] FirewallRules: [{66C56DC0-01DD-46EC-BB0B-C9FC750BF0E7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fairytales Three Heroes\bin\Game.exe () [Brak podpisu cyfrowego] FirewallRules: [{800B11CB-A1BC-4C84-AECC-BBA58643DCCA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Latte Stand Tycoon\latteStand.exe () [Brak podpisu cyfrowego] FirewallRules: [{63AA066C-FE6B-4D5A-B435-CB40644BF7F3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Latte Stand Tycoon\latteStand.exe () [Brak podpisu cyfrowego] FirewallRules: [{D4909FFE-78F5-430D-B641-78F6D5248C50}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Concept Destruction\Concept Destruction.exe () [Brak podpisu cyfrowego] FirewallRules: [{30EE6781-F787-415E-8A73-B5BA61DB3B43}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Concept Destruction\Concept Destruction.exe () [Brak podpisu cyfrowego] FirewallRules: [{996C806E-4E0D-404E-BD65-F2061EFF1923}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\WayOut 2 Hex\WayOut2.exe () [Brak podpisu cyfrowego] FirewallRules: [{E4F9A339-1B95-4446-A92F-20D818E2786F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\WayOut 2 Hex\WayOut2.exe () [Brak podpisu cyfrowego] FirewallRules: [{2D633BB2-7201-4466-8985-B4004BA95117}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Deed\Game.exe () [Brak podpisu cyfrowego] FirewallRules: [{F23C190B-02C1-45FF-A731-2FC6BDBC09BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Deed\Game.exe () [Brak podpisu cyfrowego] FirewallRules: [{2BC60661-4BEC-4CF1-AE0A-9F68D4ACE827}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Freedom Fighter\Freedom Fighter.exe (Numb Thumb Studios) [Brak podpisu cyfrowego] FirewallRules: [{5180C029-4ACA-43BD-B7D0-7AEE739E42AA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Freedom Fighter\Freedom Fighter.exe (Numb Thumb Studios) [Brak podpisu cyfrowego] FirewallRules: [{CC148F26-3879-4F91-ABF0-B92C7E524F2C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Super Switch\superswitch.exe () [Brak podpisu cyfrowego] FirewallRules: [{FDEBAAD3-9D66-4E15-9271-577FB23EF096}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Super Switch\superswitch.exe () [Brak podpisu cyfrowego] FirewallRules: [{DCF98567-D42E-4B48-9705-6EB3B82A64AB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cybarian The Time Travelling Warrior\Cybarian.exe (Microsoft Corporation) [Brak podpisu cyfrowego] FirewallRules: [{6189B232-DFB7-472C-B29F-30FDD7307537}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cybarian The Time Travelling Warrior\Cybarian.exe (Microsoft Corporation) [Brak podpisu cyfrowego] FirewallRules: [{C4CA1D57-0E25-40A0-8129-8C178C0BC92F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HotFloor\HotFloor.exe () [Brak podpisu cyfrowego] FirewallRules: [{89651D27-B466-48E2-9427-4D8AAA491B5C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HotFloor\HotFloor.exe () [Brak podpisu cyfrowego] FirewallRules: [{2401C996-C9D1-4134-B136-19C744A36E33}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe (Bluestack Systems, Inc -> BlueStack Systems) FirewallRules: [TCP Query User{C9CCE32F-0EF1-4D13-992A-021DB1EF56DA}C:\program files\creality slicer 4.8.2\crealityslicer.exe] => (Allow) C:\program files\creality slicer 4.8.2\crealityslicer.exe () [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{1BF3E57F-AABE-4681-B9E2-B4C9C0F27088}C:\program files\creality slicer 4.8.2\crealityslicer.exe] => (Allow) C:\program files\creality slicer 4.8.2\crealityslicer.exe () [Brak podpisu cyfrowego] FirewallRules: [{AF8FAFCF-2FF3-4DA0-9DC4-DAB8B30E6EAB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AtmaSphere\AtmaSphereFinal.exe () [Brak podpisu cyfrowego] FirewallRules: [{C7E440B9-A1D1-48DF-A554-DFF6BAC0F951}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AtmaSphere\AtmaSphereFinal.exe () [Brak podpisu cyfrowego] FirewallRules: [{B250BF3B-0486-4634-8465-A301C1A633D4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Caveman World Mountains of Unga Boonga\Caveman World.exe () [Brak podpisu cyfrowego] FirewallRules: [{1D5D6EAF-CE22-4337-8B03-0295DF2EA44A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Caveman World Mountains of Unga Boonga\Caveman World.exe () [Brak podpisu cyfrowego] FirewallRules: [{331D2815-992F-41D2-8D01-2334C3D95F1C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chicken Shoot 2\Kurka.exe () [Brak podpisu cyfrowego] FirewallRules: [{AA76FCB1-7A88-464B-87EB-685C61151955}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chicken Shoot 2\Kurka.exe () [Brak podpisu cyfrowego] FirewallRules: [{C7C0116F-27A3-4384-A9DA-DF2EFFDED908}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Devils Gold\Game.exe (KADOKAWA) [Brak podpisu cyfrowego] FirewallRules: [{F1675827-CB54-4A6E-BF55-66E2096E5643}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Devils Gold\Game.exe (KADOKAWA) [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{6BBD6660-3124-4026-9806-CB7425089CB5}C:\users\user\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\users\user\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe FirewallRules: [UDP Query User{E7F6C885-7B01-41C3-8D25-691EF6E5B5A2}C:\users\user\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe] => (Allow) C:\users\user\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-alpha\windows-x64\java-runtime-alpha\bin\javaw.exe FirewallRules: [{69EF1CEF-6E07-4DE2-96B1-B5FB1298CE54}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dream_pinball_3D\dp3d.exe () [Brak podpisu cyfrowego] FirewallRules: [{BC3E8DA8-E64B-4CFF-902F-3072D6736D0D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dream_pinball_3D\dp3d.exe () [Brak podpisu cyfrowego] FirewallRules: [{9C12351F-99E7-454F-AE67-F6400931D4CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Timore Inferno\Timore Inferno.exe () [Brak podpisu cyfrowego] FirewallRules: [{9C018696-D416-4B82-A212-2E50F378DAEA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Timore Inferno\Timore Inferno.exe () [Brak podpisu cyfrowego] FirewallRules: [{741B06D4-5C65-4AC2-9EF3-F2295D137DD4}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\96.0.4664.39\remoting_host.exe (Google LLC -> Google LLC) FirewallRules: [{96972C7C-9A66-4346-BFC3-E37F14B1ECE3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Animaze\Bin\AnimazeDesktop.exe (Holotech Studios, Inc. -> ) FirewallRules: [{2B966CF5-5500-4847-B833-9B5F344281F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Animaze\Bin\AnimazeDesktop.exe (Holotech Studios, Inc. -> ) FirewallRules: [{5F6C9DC0-DED1-4BA7-BCEE-471E8C6F7567}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PC\Nemesis Race Against The Pandemic.exe () [Brak podpisu cyfrowego] FirewallRules: [{929FA86A-4D20-4DD0-9619-E47C284042BE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Solo Fox\Solo Fox.exe () [Brak podpisu cyfrowego] FirewallRules: [{D1751024-7A84-45E9-BF82-E39BF32FC8E4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO - The Hobbit\LEGOHobbit.exe (Travellers Tales (UK) Ltd -> Warner Bros. Interactive Entertainment) FirewallRules: [{331186A8-1963-400E-B900-8684DA66DEB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LEGO - The Hobbit\LEGOHobbit.exe (Travellers Tales (UK) Ltd -> Warner Bros. Interactive Entertainment) FirewallRules: [TCP Query User{7DE8AD1C-77E2-4723-AB52-1BCEB4F75FEE}C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe FirewallRules: [UDP Query User{D8C90112-6F8C-4AE7-9041-7216273D6521}C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe FirewallRules: [{70858979-2E6D-4BF0-B3C0-F82EA077A460}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_21323.200.1078.109_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{02AE7898-BD78-4CA1-9512-895E1A1D5356}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_21323.200.1078.109_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{37ADF4B8-44FE-415E-82CE-498DCD0D73CF}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod) FirewallRules: [TCP Query User{F7F5D404-2058-481F-BF6A-E6DC7C7A339A}C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe FirewallRules: [UDP Query User{5789D5CD-1E29-4535-AA7B-F04DAE9F98C7}C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\java-runtime-beta\windows-x64\java-runtime-beta\bin\javaw.exe FirewallRules: [{82EF7B7D-9B46-490C-9383-88F13570CB48}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{825330DE-1059-43F1-BB06-F4B7860DCFD3}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{8A573BBA-E76D-42FE-AF3D-EC1707D0AB49}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{5E1F146F-F3F1-45FA-9DD6-CAC9E32D1D09}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{07D491AB-6500-443D-B10B-A8F72C0EA4CF}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{54534426-001B-4C89-811E-A7F67E8E3073}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{70DBECB3-BBC2-4E03-9916-6806B885F8F5}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{02C5581D-4A5A-41A4-B10C-EC9024683F8C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{C2D0865E-5682-4445-A0BC-CBA02DF41DAC}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{0241DD2A-64CE-4250-ABF6-CD6A1A15506C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{28BF8A3C-45A3-4EC1-BB8C-9101898F702C}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{5A05C9E6-A695-49FA-A359-2A2C4266ACDC}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12122.2.54019.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{37572C29-1484-48F7-A5AB-8148BB3BFDD0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Animaze\Bin\AnimazeDesktop.exe (Holotech Studios, Inc. -> ) FirewallRules: [{F8BF30F3-51EB-4224-9FB9-FEC1BC8C9EC9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Animaze\Bin\AnimazeDesktop.exe (Holotech Studios, Inc. -> ) FirewallRules: [{11DECD7D-FA22-4E3E-8146-5A6155B75A61}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aseprite\Aseprite.exe (Igara Studio S.A. -> Igara Studio S.A.) FirewallRules: [{3E6CCBB8-BA7B-41F6-838D-8F2ED8621017}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Aseprite\Aseprite.exe (Igara Studio S.A. -> Igara Studio S.A.) FirewallRules: [{61EA213E-B05B-45BF-9ACB-ACD46D5D41E2}] => (Allow) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech, Inc.) FirewallRules: [{CF597198-01AC-4B8D-B98C-FA4C50EA90A4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{CAB1EBD8-F39C-420D-93E2-DAADDC1C9C22}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{9DB7CDE5-2DA6-410B-985D-4CE6A64C7342}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{9B90DC3A-A58B-4B72-BC2A-E776614E4471}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{4BAD76C2-94EF-4B52-AADC-07246194799D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{24301B1A-0801-47B1-B730-EFA5F5427F3D}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\98.0.1108.50\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{7D5C03E2-0A44-435B-B527-3E67862F7CAD}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{6954A28A-EBCE-49AD-91B0-31FEFBB5136C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{D555AF8F-AAF5-43F0-9E23-2651BD25CF87}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{D9F9D617-347C-417F-909C-D0B0408C37A3}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{ABF2CC39-C992-493A-BA06-A36B0155271E}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) FirewallRules: [{C50963AB-D847-40C7-8890-EF74D73C8664}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) ==================== Punkty Przywracania systemu ========================= ==================== Wadliwe urządzenia w Menedżerze urządzeń ============ Name: LogMeIn Hamachi Virtual Ethernet Adapter Description: LogMeIn Hamachi Virtual Ethernet Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: LogMeIn Inc. Service: Hamachi Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Animaze Virtual Camera Description: Animaze Virtual Camera Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: e2eSoft Service: VCamSDK Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Błędy w Dzienniku zdarzeń: ======================== Dziennik Aplikacja: ================== Error: (02/14/2022 09:13:59 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury CoCreateInstance. hr = 0x8007045b, Trwa proces zamykania systemu. . Error: (02/14/2022 09:13:59 PM) (Source: VSS) (EventID: 13) (User: ) Description: Informacje Usługi kopiowania woluminów w tle: nie można uruchomić serwera usługi COM z identyfikatorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} i nazwą CEventSystem. [0x8007045b, Trwa proces zamykania systemu. ] Error: (02/14/2022 09:13:59 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury CoCreateInstance. hr = 0x8007045b, Trwa proces zamykania systemu. . Error: (02/14/2022 09:13:59 PM) (Source: VSS) (EventID: 13) (User: ) Description: Informacje Usługi kopiowania woluminów w tle: nie można uruchomić serwera usługi COM z identyfikatorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} i nazwą CEventSystem. [0x8007045b, Trwa proces zamykania systemu. ] Error: (02/14/2022 10:41:26 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nazwa aplikacji powodującej błąd: mbamtray.exe, wersja: 4.0.0.1162, sygnatura czasowa: 0x61783b28 Nazwa modułu powodującego błąd: Qt5Core.dll, wersja: 5.14.1.0, sygnatura czasowa: 0x603971ce Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000219dc5 Identyfikator procesu powodującego błąd: 0x569c Godzina uruchomienia aplikacji powodującej błąd: 0x01d821867a6a0e6d Ścieżka aplikacji powodującej błąd: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Ścieżka modułu powodującego błąd: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll Identyfikator raportu: b2e87e15-af08-4605-83f9-22d5c88caeba Pełna nazwa pakietu powodującego błąd: Identyfikator aplikacji względem pakietu powodującego błąd: Error: (02/13/2022 08:43:40 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury CoCreateInstance. hr = 0x8007045b, Trwa proces zamykania systemu. . Error: (02/13/2022 08:43:40 PM) (Source: VSS) (EventID: 13) (User: ) Description: Informacje Usługi kopiowania woluminów w tle: nie można uruchomić serwera usługi COM z identyfikatorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} i nazwą CEventSystem. [0x8007045b, Trwa proces zamykania systemu. ] Error: (02/13/2022 08:43:40 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Błąd Usługi kopiowania woluminów w tle: nieoczekiwany błąd podczas wywoływania procedury CoCreateInstance. hr = 0x8007045b, Trwa proces zamykania systemu. . Dziennik System: ============= Error: (02/15/2022 08:37:28 AM) (Source: volsnap) (EventID: 36) (User: ) Description: Wykonywanie kopii w tle woluminu C: zostało przerwane, ponieważ nie można powiększyć magazynu kopii w tle z powodu limitu wprowadzonego przez użytkownika. Error: (02/15/2022 07:33:24 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\User\AppData\Local\Temp\ehdrv.sys Error: (02/15/2022 07:33:24 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi eapihdrv z powodu następującego błędu: Nastąpiło zablokowanie ładowania sterownika Error: (02/15/2022 07:33:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi eapihdrv z powodu następującego błędu: Nastąpiło zablokowanie ładowania sterownika Error: (02/15/2022 07:33:23 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\User\AppData\Local\Temp\ehdrv.sys Error: (02/15/2022 07:33:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi eapihdrv z powodu następującego błędu: Nastąpiło zablokowanie ładowania sterownika Error: (02/15/2022 07:33:23 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\User\AppData\Local\Temp\ehdrv.sys Error: (02/15/2022 07:33:23 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\User\AppData\Local\Temp\ehdrv.sys Windows Defender: ================ Date: 2021-11-26 11:19:20 Description: Produkt Program antywirusowy Microsoft Defender wykrył złośliwe oprogramowanie lub inne potencjalnie niechciane oprogramowanie. Aby uzyskać więcej informacji, zobacz: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0 Nazwa: HackTool:Win32/AutoKMS Identyfikator: 2147685180 Ważność: Wysoki Kategoria: Narzędzie Ścieżka: file:_C:\Program Files\KMSpico\scripts\UnInstall_Service.cmd Pochodzenie wykrycia: Komputer lokalny Typ wykrycia: Konkretne Źródło wykrycia: Ochrona w czasie rzeczywistym Użytkownik: DESKTOP-TOBIASZ\User Nazwa procesu: C:\Windows\System32\cmd.exe Wersja analizy zabezpieczeń: AV: 1.353.1619.0, AS: 1.353.1619.0, NIS: 1.353.1619.0 Wersja aparatu: AM: 1.1.18700.4, NIS: 1.1.18700.4 Date: 2021-11-26 11:17:58 Description: Produkt Program antywirusowy Microsoft Defender wykrył złośliwe oprogramowanie lub inne potencjalnie niechciane oprogramowanie. Aby uzyskać więcej informacji, zobacz: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0 Nazwa: HackTool:Win32/AutoKMS Identyfikator: 2147685180 Ważność: Wysoki Kategoria: Narzędzie Ścieżka: containerfile:_C:\Program Files\KMSpico\AutoPico.exe; file:_C:\Program Files\KMSpico\AutoPico.exe->[MSILRES:AutoPico.SECOH-QAD.x86.dll]; file:_C:\Program Files\KMSpico\AutoPico.exe->[MSILRES:AutoPico.SECOH-QAD.x86.exe] Pochodzenie wykrycia: Komputer lokalny Typ wykrycia: Konkretne Źródło wykrycia: Ochrona w czasie rzeczywistym Użytkownik: DESKTOP-TOBIASZ\User Nazwa procesu: C:\Users\User\AppData\Local\Temp\is-NCTM5.tmp\KMSpico_setup.tmp Wersja analizy zabezpieczeń: AV: 1.353.1619.0, AS: 1.353.1619.0, NIS: 1.353.1619.0 Wersja aparatu: AM: 1.1.18700.4, NIS: 1.1.18700.4 Date: 2021-11-26 11:17:43 Description: Produkt Program antywirusowy Microsoft Defender wykrył złośliwe oprogramowanie lub inne potencjalnie niechciane oprogramowanie. Aby uzyskać więcej informacji, zobacz: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win64/AutoKMS&threatid=2147723334&enterprise=0 Nazwa: HackTool:Win64/AutoKMS Identyfikator: 2147723334 Ważność: Wysoki Kategoria: Narzędzie Ścieżka: containerfile:_C:\Program Files\KMSpico\KMSELDI.exe; file:_C:\Program Files\KMSpico\KMSELDI.exe->[MSILRES:KMSELDI.SECOH-QAD.x64.dll]; file:_C:\Program Files\KMSpico\KMSELDI.exe->[MSILRES:KMSELDI.SECOH-QAD.x64.exe] Pochodzenie wykrycia: Komputer lokalny Typ wykrycia: Konkretne Źródło wykrycia: System Użytkownik: ZARZĄDZANIE NT\SYSTEM Nazwa procesu: Unknown Wersja analizy zabezpieczeń: AV: 1.353.1619.0, AS: 1.353.1619.0, NIS: 1.353.1619.0 Wersja aparatu: AM: 1.1.18700.4, NIS: 1.1.18700.4 Date: 2021-11-26 11:17:43 Description: Produkt Program antywirusowy Microsoft Defender wykrył złośliwe oprogramowanie lub inne potencjalnie niechciane oprogramowanie. Aby uzyskać więcej informacji, zobacz: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0 Nazwa: HackTool:Win32/AutoKMS Identyfikator: 2147685180 Ważność: Wysoki Kategoria: Narzędzie Ścieżka: containerfile:_C:\Program Files\KMSpico\KMSELDI.exe; file:_C:\Program Files\KMSpico\KMSELDI.exe->[MSILRES:KMSELDI.SECOH-QAD.x86.dll]; file:_C:\Program Files\KMSpico\KMSELDI.exe->[MSILRES:KMSELDI.SECOH-QAD.x86.exe] Pochodzenie wykrycia: Komputer lokalny Typ wykrycia: Konkretne Źródło wykrycia: System Użytkownik: ZARZĄDZANIE NT\SYSTEM Nazwa procesu: Unknown Wersja analizy zabezpieczeń: AV: 1.353.1619.0, AS: 1.353.1619.0, NIS: 1.353.1619.0 Wersja aparatu: AM: 1.1.18700.4, NIS: 1.1.18700.4 Date: 2021-11-26 11:17:33 Description: Produkt Program antywirusowy Microsoft Defender wykrył złośliwe oprogramowanie lub inne potencjalnie niechciane oprogramowanie. Aby uzyskać więcej informacji, zobacz: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0 Nazwa: HackTool:Win32/AutoKMS Identyfikator: 2147685180 Ważność: Wysoki Kategoria: Narzędzie Ścieżka: containerfile:_C:\Program Files\KMSpico\KMSELDI.exe; containerfile:_C:\Program Files\KMSpico\Service_KMS.exe; file:_C:\Program Files\KMSpico\KMSELDI.exe->[MSILRES:KMSELDI.SECOH-QAD.x86.dll]; file:_C:\Program Files\KMSpico\KMSELDI.exe->[MSILRES:KMSELDI.SECOH-QAD.x86.exe]; file:_C:\Program Files\KMSpico\scripts\Install_Service.cmd; file:_C:\Program Files\KMSpico\scripts\Install_Task.cmd; file:_C:\Program Files\KMSpico\Service_KMS.exe->[MSILRES:Service_KMS.SECOH-QAD.x86.dll]; file:_C:\Program Files\KMSpico\Service_KMS.exe->[MSILRES:Service_KMS.SECOH-QAD.x86.exe]; regkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1; uninstall:_HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 Pochodzenie wykrycia: Komputer lokalny Typ wykrycia: Konkretne Źródło wykrycia: System Użytkownik: ZARZĄDZANIE NT\SYSTEM Nazwa procesu: C:\Windows\System32\cmd.exe Wersja analizy zabezpieczeń: AV: 1.353.1619.0, AS: 1.353.1619.0, NIS: 1.353.1619.0 Wersja aparatu: AM: 1.1.18700.4, NIS: 1.1.18700.4  CodeIntegrity: =============== Date: 2022-02-15 03:02:23 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Statystyki pamięci =========================== BIOS: Insyde Corp. V2.06 08/19/2021 Płyta główna: CML Stonic_CMS Procesor: Intel(R) Core(TM) i5-10300H CPU @ 2.50GHz Procent pamięci w użyciu: 37% Całkowita pamięć fizyczna: 32599.05 MB Dostępna pamięć fizyczna: 20363.61 MB Całkowita pamięć wirtualna: 37463.05 MB Dostępna pamięć wirtualna: 23142.18 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:466.15 GB) (Free:128.16 GB) NTFS Drive d: (WINDRIVER) (Fixed) (Total:9.81 GB) (Free:0.64 GB) NTFS \\?\Volume{68581084-5526-4ec2-9a76-3f11290a7e3e}\ () (Fixed) (Total:0.87 GB) (Free:0.08 GB) NTFS \\?\Volume{accf2efd-eebc-d015-c312-8aa29d41c55f}\ () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS \\?\Volume{bc4fcc9b-24c1-4374-22b3-6f00a9526a2b}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Tablica partycji ==================== Attempted reading MBR returned 0 bytes. Could not read MBR for disk 1. ==================== Koniec Addition.txt =======================