Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 27.01.2019 Uruchomiony przez Czapl (29-01-2019 07:05:45) Run:6 Uruchomiony z C:\Users\Czapl\Downloads Załadowane profile: Czapl (Dostępne profile: Czapl) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** HKU\S-1-5-21-3127929803-2353841605-3325064479-1002\...\Winlogon: [Shell] %comspec% <==== UWAGA Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /s Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} EmptyTemp: ***************** "HKU\S-1-5-21-3127929803-2353841605-3325064479-1002\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => pomyślnie usunięto ========= reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 Background REG_SZ 0 0 0 CachedLogonsCount REG_SZ 10 DebugServerCommand REG_SZ no DisableBackButton REG_DWORD 0x1 EnableSIHostIntegration REG_DWORD 0x1 ForceUnlockLogon REG_DWORD 0x0 LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PasswordExpiryWarning REG_DWORD 0x5 PowerdownAfterShutdown REG_SZ 0 PreCreateKnownFolders REG_SZ {A520A1A4-1780-4FF6-BD18-167343C5AF16} ReportBootOk REG_SZ 1 Shell REG_SZ Explorer.exe ShellCritical REG_DWORD 0x0 ShellInfrastructure REG_SZ sihost.exe SiHostCritical REG_DWORD 0x0 SiHostReadyTimeOut REG_DWORD 0x0 SiHostRestartCountLimit REG_DWORD 0x0 SiHostRestartTimeGap REG_DWORD 0x0 Userinit REG_SZ C:\Windows\system32\userinit.exe, VMApplet REG_SZ SystemPropertiesPerformance.exe /pagefile WinStationsDisabled REG_SZ 0 scremoveoption REG_SZ 0 DisableCAD REG_DWORD 0x1 LastLogOffEndTimePerfCounter REG_QWORD 0xb55e54b8 ShutdownFlags REG_DWORD 0x800000ab DisableLockWorkstation REG_DWORD 0x0 EnableFirstLogonAnimation REG_DWORD 0x1 AutoLogonSID REG_SZ S-1-5-21-3127929803-2353841605-3325064479-1002 LastUsedUsername REG_SZ Czapl HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} (Default) REG_SZ Wireless Group Policy DisplayName REG_EXPAND_SZ @wlgpclnt.dll,-100 DllName REG_EXPAND_SZ wlgpclnt.dll GenerateGroupPolicy REG_SZ GenerateWLANPolicy NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessWLANPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0E28E245-9368-4853-AD84-6DA3BA35BB75} (Default) REG_SZ Group Policy Environment DisplayName REG_EXPAND_SZ @gpprefcl.dll,-1 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Environment,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyEnviron PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyEnviron ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExEnviron HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{169EBF44-942F-4C43-87CE-13C93996EBBE} (Default) REG_SZ UEV Policy DllName REG_EXPAND_SZ AppManagementConfiguration.dll ProcessGroupPolicy REG_SZ ProcessUevPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{16be69fa-4209-4250-88cb-716cf41954e0} (Default) REG_SZ Central Access Policy Configuration DisplayName REG_EXPAND_SZ @auditcse.dll,-4000 DllName REG_EXPAND_SZ auditcse.dll EnableAsynchronousProcessing REG_DWORD 0x1 ForceRefreshFG REG_DWORD 0x0 GenerateGroupPolicy REG_SZ GenerateGroupPolicyCap MaxNoGPOListChangesInterval REG_DWORD 0x78 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExCap HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{17D89FEC-5C44-4972-B12D-241CAEF74509} (Default) REG_SZ Group Policy Local Users and Groups DisplayName REG_EXPAND_SZ @gpprefcl.dll,-2 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Local Users and Groups,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyLocUsAndGroups PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyLocUsAndGroups ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExLocUsAndGroups HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{1A6364EB-776B-4120-ADE1-B63A406A76B5} (Default) REG_SZ Group Policy Device Settings DisplayName REG_EXPAND_SZ @gpprefcl.dll,-3 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Device Settings,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyDevices PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyDevices ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExDevices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861} (Default) REG_SZ Folder Redirection DisplayName REG_EXPAND_SZ @fdeploy.dll,-261 DllName REG_EXPAND_SZ fdeploy.dll EventSources REG_MULTI_SZ (Folder Redirection,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicy NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{2A8FDC61-2347-4C87-92F6-B05EB91A201A} (Default) REG_SZ MitigationOptions DisplayName REG_EXPAND_SZ @gpprefcl.dll,-22 DllName REG_SZ C:\Windows\System32\gpprefcl.dll NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyMitigationOptions RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{2BFCC077-22D2-48DE-BDE1-2F618D9B476D} (Default) REG_SZ AppV Policy DllName REG_EXPAND_SZ AppManagementConfiguration.dll ProcessGroupPolicy REG_SZ ProcessAppVPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} (Default) REG_SZ Microsoft Disk Quota DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\dskquota.dll,-100 DllName REG_EXPAND_SZ %SystemRoot%\System32\dskquota.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F} (Default) REG_SZ Group Policy Network Options DisplayName REG_EXPAND_SZ @gpprefcl.dll,-4 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Network Options,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyNetworkOptions PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyNetworkOptions ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExNetworkOptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39} (Default) REG_SZ QoS Packet Scheduler DisplayName REG_EXPAND_SZ @gptext.dll,-201 DllName REG_EXPAND_SZ gptext.dll NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3} (Default) REG_SZ Scripts DisplayName REG_EXPAND_SZ @gpscript.dll,-1 DllName REG_SZ C:\Windows\System32\gpscript.dll GenerateGroupPolicy REG_SZ GenerateScriptsGroupPolicy NoGPOListChanges REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 NotifyLinkTransition REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessScriptsGroupPolicy ProcessGroupPolicyEx REG_SZ ProcessScriptsGroupPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4B7C3B0F-E993-4E06-A241-3FBE06943684} (Default) REG_SZ Per-process Mitigation Options DisplayName REG_EXPAND_SZ @gpprefcl.dll,-22 DllName REG_SZ C:\Windows\System32\gpprefcl.dll ProcessGroupPolicy REG_SZ ProcessGroupPolicyProcessMitigationOptions RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d} (Default) REG_SZ Remote Desktop USB Redirection DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll,-100 DllName REG_EXPAND_SZ %SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} (Default) REG_SZ Internet Explorer Zonemapping DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051 DllName REG_SZ C:\Windows\System32\iedkcs32.dll NoGPOListChanges REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4D2F9B6F-1E52-4711-A382-6A8B1A003DE6} DllName REG_SZ C:\Windows\System32\tsworkspace.dll NoMachinePolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ RADCProcessGroupPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4d968b55-cac2-4ff5-983f-0a54603781a3} (Default) REG_SZ Work Folders DisplayName REG_EXPAND_SZ @WorkFoldersGPExt.dll,-261 DllName REG_EXPAND_SZ WorkFoldersGPExt.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x0 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{5794DAFD-BE60-433f-88A2-1A31939AC01F} (Default) REG_SZ Group Policy Drive Maps DisplayName REG_EXPAND_SZ @gpprefcl.dll,-5 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Drive Maps,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyDrives NoMachinePolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyDrives ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExDrives HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6232C319-91AC-4931-9385-E70C2B099F0E} (Default) REG_SZ Group Policy Folders DisplayName REG_EXPAND_SZ @gpprefcl.dll,-6 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Folders,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyFolders PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyFolders ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2} (Default) REG_SZ Group Policy Network Shares DisplayName REG_EXPAND_SZ @gpprefcl.dll,-7 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Network Shares,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyNetShares NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyNetShares ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExNetShares HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7150F9BF-48AD-4da4-A49C-29EF4A8369BA} (Default) REG_SZ Group Policy Files DisplayName REG_EXPAND_SZ @gpprefcl.dll,-8 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Files,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyFiles PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyFiles ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{728EE579-943C-4519-9EF7-AB56765798ED} (Default) REG_SZ Group Policy Data Sources DisplayName REG_EXPAND_SZ @gpprefcl.dll,-9 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Data Sources,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyDataSources PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyDataSources ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExDataSources HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{74EE6C03-5363-4554-B161-627540339CAB} (Default) REG_SZ Group Policy Ini Files DisplayName REG_EXPAND_SZ @gpprefcl.dll,-10 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Ini Files,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyIniFile PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyIniFile ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExIniFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7909AD9E-09EE-4247-BAB9-7029D5F0A278} (Default) REG_SZ MDM Policy DllName REG_EXPAND_SZ dmenrollengine.dll ProcessGroupPolicy REG_SZ AutoEnrollMDM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93} (Default) REG_SZ Windows Search Group Policy Extension DllName REG_EXPAND_SZ %SystemRoot%\System32\srchadmin.dll EnableAsynchronousProcessing REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x0 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} (Default) REG_SZ Internet Explorer User Accelerators DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051 DllName REG_SZ C:\Windows\System32\iedkcs32.dll NoGPOListChanges REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} (Default) REG_SZ Security DisplayName REG_EXPAND_SZ @(runtime.system32)\scecli.dll,-7650 DllName REG_EXPAND_SZ scecli.dll EnableAsynchronousProcessing REG_DWORD 0x1 ExtensionDebugLevel REG_DWORD 0x0 ExtensionRsopPlanningDebugLevel REG_DWORD 0x1 GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy MaxNoGPOListChangesInterval REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17} (Default) REG_SZ Deployed Printer Connections DisplayName REG_EXPAND_SZ @%systemroot%\system32\gpprnext.dll,-1 DllName REG_EXPAND_SZ %systemroot%\system32\gpprnext.dll EnableAsynchronousProcessing REG_DWORD 0x1 ExtensionEventSource REG_SZ GenerateGroupPolicy REG_SZ PrinterGenerateGroupPolicy MaxNoGPOListChangesInterval REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x1 NotifyLinkTransition REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x0 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ PrinterProcessGroupPolicy ProcessGroupPolicyEx REG_SZ PrinterProcessGroupPolicyEx RequiresSuccessfulRegistry REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{91FBB303-0CD5-4055-BF42-E512A681B325} (Default) REG_SZ Group Policy Services DisplayName REG_EXPAND_SZ @gpprefcl.dll,-11 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Services,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyServices ProcessGroupPolicy REG_SZ ProcessGroupPolicyServices ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{9650FDBC-053A-4715-AD14-FC2DC65E8330} DllName REG_EXPAND_SZ hvsigpext.dll EnableAsynchronousProcessing REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessHVSIPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A3F3E39B-5D83-4940-B954-28315B82F0A8} (Default) REG_SZ Group Policy Folder Options DisplayName REG_EXPAND_SZ @gpprefcl.dll,-12 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Folder Options,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyFolderOptions PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyFolderOptions ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExFolderOptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{AADCED64-746C-4633-A97C-D61349046527} (Default) REG_SZ Group Policy Scheduled Tasks DisplayName REG_EXPAND_SZ @gpprefcl.dll,-13 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Scheduled Tasks,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicySchedTasks PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicySchedTasks ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExSchedTasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B087BE9D-ED37-454f-AF9C-04291E351182} (Default) REG_SZ Group Policy Registry DisplayName REG_EXPAND_SZ @gpprefcl.dll,-14 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Registry,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyRegistry PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyRegistry ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExRegistry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053} (Default) REG_SZ 802.3 Group Policy DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100 DllName REG_EXPAND_SZ dot3gpclnt.dll GenerateGroupPolicy REG_SZ GenerateLANPolicy NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BA649533-0AAC-4E04-B9BC-4DBAE0325B12} (Default) REG_SZ Windows To Go Startup Options DllName REG_EXPAND_SZ pwlauncher.dll ProcessGroupPolicy REG_SZ ProcessLauncherGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D} (Default) REG_SZ Group Policy Printers DisplayName REG_EXPAND_SZ @gpprefcl.dll,-16 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Printers,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyPrinters PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyPrinters ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExPrinters HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C34B2751-1CF4-44F5-9262-C3FC39666591} (Default) REG_SZ Windows To Go Hibernate Options DllName REG_EXPAND_SZ pwlauncher.dll ProcessGroupPolicy REG_SZ ProcessHibernateGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7} (Default) REG_SZ Group Policy Shortcuts DisplayName REG_EXPAND_SZ @gpprefcl.dll,-17 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Shortcuts,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyShortcuts PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyShortcuts ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExShortcuts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8} (Default) REG_SZ Microsoft Offline Files DllName REG_EXPAND_SZ %SystemRoot%\System32\cscobj.dll EnableAsynchronousProcessing REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x0 PerUserLocalSettings REG_DWORD 0x0 ProcessGroupPolicy REG_SZ ProcessGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7} (Default) REG_SZ Software Installation DisplayName REG_EXPAND_SZ @appmgmts.dll,-3252 DllName REG_EXPAND_SZ appmgmts.dll EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicy NoBackgroundPolicy REG_DWORD 0x0 NoSlowLink REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x0 PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx RequiresSucessfulRegistry REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{cdeafc3d-948d-49dd-ab12-e578ba4af7aa} (Default) REG_SZ TCPIP DisplayName REG_EXPAND_SZ @gptext.dll,-204 DllName REG_EXPAND_SZ gptext.dll NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessTCPIPPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} (Default) REG_SZ Internet Explorer Machine Accelerators DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051 DllName REG_SZ C:\Windows\System32\iedkcs32.dll NoGPOListChanges REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27} (Default) REG_SZ IP Security DisplayName REG_EXPAND_SZ @C:\Windows\System32\polstore.dll,-5012 DllName REG_EXPAND_SZ %SystemRoot%\System32\polstore.dll GenerateGroupPolicy REG_SZ GenerateIPSECPolicy NoGPOListChanges REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessIPSECPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E47248BA-94CC-49c4-BBB5-9EB7F05183D0} (Default) REG_SZ Group Policy Internet Settings DisplayName REG_EXPAND_SZ @gpprefcl.dll,-18 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Internet Settings,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyInternet NoMachinePolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyInternet ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExInternet HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E4F48E54-F38D-4884-BFB9-D4D2E5729C18} (Default) REG_SZ Group Policy Start Menu Settings DisplayName REG_EXPAND_SZ @gpprefcl.dll,-19 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Start Menu Settings,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyStartMenu PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyStartMenu ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExStartMenu HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E5094040-C46C-4115-B030-04FB2E545B00} (Default) REG_SZ Group Policy Regional Options DisplayName REG_EXPAND_SZ @gpprefcl.dll,-20 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Regional Options,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyRegionOptions PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyRegionOptions ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExRegionOptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E62688F0-25FD-4c90-BFF5-F508B9D2E31F} (Default) REG_SZ Group Policy Power Options DisplayName REG_EXPAND_SZ @gpprefcl.dll,-21 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Power Options,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyPowerOptions PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyPowerOptions ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExPowerOptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{F312195E-3D9D-447A-A3F5-08DFFA24735E} DisplayName REG_EXPAND_SZ @dggpext.dll,-600 DllName REG_EXPAND_SZ dggpext.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessVirtualizationBasedSecurityGroupPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a} (Default) REG_SZ Audit Policy Configuration DisplayName REG_EXPAND_SZ @auditcse.dll,-3000 DllName REG_EXPAND_SZ auditcse.dll EnableAsynchronousProcessing REG_DWORD 0x1 ForceRefreshFG REG_DWORD 0x0 GenerateGroupPolicy REG_SZ GenerateGroupPolicy MaxNoGPOListChangesInterval REG_DWORD 0x3c0 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{F9C77450-3A41-477E-9310-9ACD617BD9E3} (Default) REG_SZ Group Policy Applications DisplayName REG_EXPAND_SZ @gpprefcl.dll,-15 DllName REG_SZ C:\Windows\System32\gpprefcl.dll EnableAsynchronousProcessing REG_DWORD 0x1 EventSources REG_SZ (Group Policy Applications,Application) GenerateGroupPolicy REG_SZ GenerateGroupPolicyApplications NoMachinePolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessGroupPolicyApplications ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C} (Default) REG_SZ Enterprise QoS DisplayName REG_EXPAND_SZ @gptext.dll,-203 DllName REG_EXPAND_SZ gptext.dll ProcessGroupPolicy REG_SZ ProcessEQoSPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f} (Default) REG_SZ CP DisplayName REG_EXPAND_SZ @gptext.dll,-205 DllName REG_EXPAND_SZ gptext.dll NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessConnectivityPlatformPolicy RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FC491EF1-C4AA-4CE1-B329-414B101DB823} DisplayName REG_EXPAND_SZ @dggpext.dll,-600 DllName REG_EXPAND_SZ dggpext.dll EnableAsynchronousProcessing REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 ProcessGroupPolicy REG_SZ ProcessConfigCIPolicyGroupPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserDefaults ExcludeProfileDirs REG_SZ AppData\Local;AppData\LocalLow;$Recycle.Bin;OneDrive;Work Folders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoLogonChecked HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VolatileUserMgrKey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VolatileUserMgrKey\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VolatileUserMgrKey\1\S-1-5-21-3127929803-2353841605-3325064479-1002 contextLuid REG_QWORD 0x3abf9 ========= Koniec Reg: ========= ========= wevtutil el | Foreach-Object {wevtutil cl "$_"} ========= ========= Koniec Powershell: ========= =========== EmptyTemp: ========== BITS transfer queue => 10510336 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19170688 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 49177 B Edge => 0 B Chrome => 1811249 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 8188 B LocalService => 0 B NetworkService => 0 B NetworkService => 0 B Czapl => 23299943 B RecycleBin => 173519 B EmptyTemp: => 52.5 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 07:08:46 ====