Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 15-01-2020 Uruchomiony przez KOMPUTER (17-01-2020 20:16:27) Uruchomiony z C:\Users\KOMPUTER\Desktop Windows 10 Pro Wersja 1903 18362.592 (X64) (2019-08-06 18:27:42) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-2396012584-1682684127-3418686497-500 - Administrator - Disabled) antek (S-1-5-21-2396012584-1682684127-3418686497-1003 - Limited - Disabled) Gość (S-1-5-21-2396012584-1682684127-3418686497-501 - Limited - Disabled) KOMPUTER (S-1-5-21-2396012584-1682684127-3418686497-1001 - Administrator - Enabled) => C:\Users\KOMPUTER Konto domyślne (S-1-5-21-2396012584-1682684127-3418686497-503 - Limited - Disabled) postgres (S-1-5-21-2396012584-1682684127-3418686497-1002 - Limited - Enabled) => C:\Users\postgres WDAGUtilityAccount (S-1-5-21-2396012584-1682684127-3418686497-504 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Kaspersky Free (Disabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) Algodoo v2.1.0 (HKLM-x32\...\Algodoo_is1) (Version: - Algoryx) AMD Ryzen Master (HKLM\...\AMD Ryzen Master) (Version: 2.0.1.1233 - Advanced Micro Devices, Inc.) Aslain's WoT Modpack (wersja 1.6.1.2.02) (HKLM-x32\...\Aslains_WoT_Modpack_Installer_is1) (Version: 1.6.1.2.02 - Aslain) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 19.8.2393 - AVAST Software) Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 77.2.2154.121 - AVAST Software) Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.5.245.0 - AVAST Software) Hidden Discord (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\Discord) (Version: 0.0.305 - Discord Inc.) Epic Games Launcher (HKLM-x32\...\{C447C1A4-1691-4C80-A759-19A2F6F67258}) (Version: 1.1.220.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Fairlight Audio Accelerator Utility (HKLM\...\FairlightAudioAccelerator_is1) (Version: 1.0.11 - Blackmagic Design) FastStone Image Viewer 7.4 (HKLM-x32\...\FastStone Image Viewer) (Version: 7.4 - FastStone Soft) GAMDIAS HERA (wersja 2.9.4) (HKLM-x32\...\{BF80AB45-9860-4FE6-B93A-9BF2A84A19F5}_is1) (Version: 2.9.4 - GAMDIAS Technology Co., Ltd.) GIMP 2.10.14 (HKLM\...\GIMP-2_is1) (Version: 2.10.14 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.117 - Google LLC) Google Earth Pro (HKLM\...\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}) (Version: 7.3.2.5776 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.421 - Google LLC) Hidden HitFilm Express (HKLM\...\{2A3E6329-261E-4FF7-8865-FB96A669690C}) (Version: 13.0.9126.07201 - FXHOME) Kaspersky Free (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden Kaspersky Free (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Kaspersky Secure Connection (HKLM-x32\...\{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky) K-Lite Codec Pack 14.9.9 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.9.9 - KLCP) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden LibreOffice 6.2.4.2 (HKLM\...\{B8FF8670-C6F4-4868-9DB2-C23324C0E575}) (Version: 6.2.4.2 - The Document Foundation) Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes) Microsoft OneDrive (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\OneDriveSetup.exe) (Version: 19.222.1110.0006 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Minecraft Launcher (HKLM-x32\...\{810F1419-7760-402E-8772-B4054FAA2B72}) (Version: 1.0.0.0 - Mojang) Mozilla Firefox 72.0.1 (x64 pl) (HKLM\...\Mozilla Firefox 72.0.1 (x64 pl)) (Version: 72.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.0.1 - Mozilla) PostgreSQL 9.5 (HKLM\...\PostgreSQL 9.5) (Version: 9.5 - PostgreSQL Global Development Group) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8228 - Realtek Semiconductor Corp.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TT server maker (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\0a2223a9edf7aa38) (Version: 1.4.4.1 - TThread) Twitch (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.7.1 - VideoLAN) War Thunder Launcher 1.0.3.196 (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment) Wargaming.net Game Center (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\Wargaming.net Game Center) (Version: 19.8.0.7920 - Wargaming.net) WinRAR 5.71 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH) World of Tanks EU (HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\WOT.EU.PRODUCTION) (Version: - Wargaming.net) Packages: ========= DirectX -> C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_9.29.952.0_x64__8wekyb3d8bbwe [2019-08-12] (Microsoft Corporation) DirectX -> C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_9.29.952.0_x86__8wekyb3d8bbwe [2019-08-09] (Microsoft Corporation) Dodatek Aparat multimediów dla aplikacji Zdjęcia -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-07] (Microsoft Corporation) Dodatek Zdjęcia -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2020-01-13] (Microsoft Corporation) Messenger -> C:\Program Files\WindowsApps\Facebook.317180B0BB486_196.2292.59195.0_x86__8xx8rvfyw5nnt [2019-08-07] (Facebook Inc) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-08-13] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-08-13] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-16] (Microsoft Studios) [MS Ad] MSN Pogoda -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.34.13393.0_x64__8wekyb3d8bbwe [2019-12-23] (Microsoft Corporation) [MS Ad] Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.3.180.0_x64__dt26b99r8h8gj [2019-12-01] (Realtek Semiconductor Corp) Scratch Desktop -> C:\Program Files\WindowsApps\ScratchFoundation.ScratchDesktop_3.6.0.0_x86__wmbdy4q6dbx4t [2019-11-26] (Scratch Foundation) Sea of Thieves -> C:\Program Files\WindowsApps\Microsoft.SeaofThieves_2.87.8848.2_x64__8wekyb3d8bbwe [2019-12-02] (ms-resource:PublisherDisplayName) Sphero Edu -> C:\Program Files\WindowsApps\C7085897.SpheroEdu_5.3.0.0_x64__yeht7bxwg8ame [2019-12-26] (Orbotix Inc.) Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0 [2019-12-27] (Spotify AB) [Startup Task] Usługi gier -> C:\Program Files\WindowsApps\Microsoft.GamingServices_1.35.26001.0_x64__8wekyb3d8bbwe [2019-12-16] (Microsoft Corporation) WhatsApp Desktop -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.9309.0_x64__cv1g1gvanyjgm [2019-12-16] (WhatsApp Inc.) Xbox (Beta) -> C:\Program Files\WindowsApps\Microsoft.GamingApp_1912.1001.8.0_x64__8wekyb3d8bbwe [2019-12-14] (Microsoft Corporation) [Startup Task] ==================== Niestandardowe rejestracje CLSID (filtrowane): ============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-12-07] (AVAST Software s.r.o. -> AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-12-07] (AVAST Software s.r.o. -> AVAST Software) ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-08-06] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-08-06] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-12-07] (AVAST Software s.r.o. -> AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-10] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-08-06] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-12-07] (AVAST Software s.r.o. -> AVAST Software) ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-08-06] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-10] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (filtrowane) ==================== ==================== Skróty & WMI ======================== (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\KOMPUTER\Desktop\CupSell.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=oochlagpfbapclpdhdbnijchiolgpghn ShortcutWithArgument: C:\Users\KOMPUTER\Desktop\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=adnlfjpnmidfimlkaohpidplnoimahfh ShortcutWithArgument: C:\Users\KOMPUTER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\CupSell (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=oochlagpfbapclpdhdbnijchiolgpghn ShortcutWithArgument: C:\Users\KOMPUTER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\CupSell.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=oochlagpfbapclpdhdbnijchiolgpghn ShortcutWithArgument: C:\Users\KOMPUTER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=adnlfjpnmidfimlkaohpidplnoimahfh ==================== Załadowane moduły (filtrowane) ============= 2019-09-10 13:53 - 2016-08-09 06:13 - 000183296 _____ () [Brak podpisu cyfrowego] C:\Program Files\PostgreSQL\9.5\bin\LIBPQ.dll 2019-09-10 13:54 - 2016-07-27 09:08 - 002264576 _____ () [Brak podpisu cyfrowego] C:\Program Files\PostgreSQL\9.5\bin\libxml2.dll 2019-09-10 13:54 - 2015-08-26 09:40 - 001687930 _____ (Free Software Foundation) [Brak podpisu cyfrowego] C:\Program Files\PostgreSQL\9.5\bin\libiconv-2.dll 2019-09-10 13:54 - 2015-08-26 09:40 - 000685350 _____ (Free Software Foundation) [Brak podpisu cyfrowego] C:\Program Files\PostgreSQL\9.5\bin\libintl-8.dll 2019-09-10 13:54 - 2016-05-05 07:35 - 001655808 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Brak podpisu cyfrowego] C:\Program Files\PostgreSQL\9.5\bin\LIBEAY32.dll 2019-09-10 13:54 - 2016-05-05 07:35 - 000349696 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Brak podpisu cyfrowego] C:\Program Files\PostgreSQL\9.5\bin\SSLEAY32.dll ==================== Alternate Data Streams (filtrowane) ======== (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\Users\KOMPUTER\Dane aplikacji:fbd50e2f7662a5c33287ddc6e65ab5a1 [394] AlternateDataStreams: C:\Users\KOMPUTER\AppData\Roaming:fbd50e2f7662a5c33287ddc6e65ab5a1 [394] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [478] ==================== Tryb awaryjny (filtrowane) ================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Powiązania plików (filtrowane) ================= ==================== Internet Explorer - Witryny zaufane i z ograniczeniami ========== ==================== Hosts - zawartość: ========================= (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2019-03-19 05:49 - 2020-01-03 17:53 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts 2019-10-20 12:45 - 2019-10-20 12:45 - 000000448 _____ C:\Windows\system32\drivers\etc\hosts.ics ==================== Inne obszary =========================== (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\KOMPUTER\Downloads\tapeciarnia.pl-108643_windows_xp_pokemon.jpg HKU\S-1-5-21-2396012584-1682684127-3418686497-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg DNS Servers: 192.168.8.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Załączenie wejścia w fixlist spowoduje jego usunięcie.) HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\StartupApproved\StartupFolder: => "Twitch.lnk" HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\StartupApproved\Run: => "EpicGamesLauncher" HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\StartupApproved\Run: => "Wargaming.net Game Center" HKU\S-1-5-21-2396012584-1682684127-3418686497-1001\...\StartupApproved\Run: => "GAMDIAS HERA" ==================== Reguły Zapory systemu Windows (filtrowane) ================ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{5C247AC2-9A52-48A0-A5CD-E47908EADE43}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{7FBFEF30-2BC3-4615-89C3-7A060D18789B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{A1518B30-EC62-40B2-8058-7F7E1D3ED1EB}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [UDP Query User{2B53F1D1-6C7D-441A-B36E-521691697BC1}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [TCP Query User{2E5D917F-F586-45D5-A1D7-0B809F915503}C:\games\world_of_tanks_eu\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\worldoftanks.exe Brak pliku FirewallRules: [UDP Query User{B04F79F3-5BA6-4407-97CB-FF702645BE81}C:\games\world_of_tanks_eu\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\worldoftanks.exe Brak pliku FirewallRules: [TCP Query User{826D194F-9614-4387-A4D1-BC3B5CCCDB66}D:\gry\world_of_tanks_eu\worldoftanks.exe] => (Allow) D:\gry\world_of_tanks_eu\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [UDP Query User{2B31877D-522B-480D-98E8-145BB1AD0A2A}D:\gry\world_of_tanks_eu\worldoftanks.exe] => (Allow) D:\gry\world_of_tanks_eu\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [{DCF368F1-63F3-4B2A-896D-E21D4406EFFF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe Brak pliku FirewallRules: [{54F92AFD-3145-400D-97D7-C5286350A816}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe Brak pliku FirewallRules: [TCP Query User{CB93E834-0D81-48A2-8841-15C46498F9B6}D:\windowsapps\spotifyab.spotifymusic_1.112.449.0_x86__zpdnekdrzrea0\spotify.exe] => (Allow) D:\windowsapps\spotifyab.spotifymusic_1.112.449.0_x86__zpdnekdrzrea0\spotify.exe Brak pliku FirewallRules: [UDP Query User{47ABBD4A-400C-408E-9D1E-AB5BDF6B5988}D:\windowsapps\spotifyab.spotifymusic_1.112.449.0_x86__zpdnekdrzrea0\spotify.exe] => (Allow) D:\windowsapps\spotifyab.spotifymusic_1.112.449.0_x86__zpdnekdrzrea0\spotify.exe Brak pliku FirewallRules: [{50F6E659-EA03-4513-8E1E-BC4B62068097}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\Resolve.exe Brak pliku FirewallRules: [{DC980CEC-D147-4E2E-A664-89EB06C922C7}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\bmdpaneld.exe Brak pliku FirewallRules: [{2BED7E37-DFDC-48C3-931B-9E8CEC4456F5}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\DaVinciPanelDaemon.exe Brak pliku FirewallRules: [{B5B46402-38A5-4026-BBBF-1DE4C20E904D}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\JLCooperPanelDaemon.exe Brak pliku FirewallRules: [{E3E3AF13-6BB6-4C47-980E-0820A232B2F7}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\EuphonixPanelDaemon.exe Brak pliku FirewallRules: [{8FFD129F-84EF-4065-B8B6-C274F3F359EA}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\TangentPanelDaemon.exe Brak pliku FirewallRules: [{2F2F061D-342F-48DE-AF00-E8A77B3A45ED}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\ElementsPanelDaemon.exe Brak pliku FirewallRules: [{AC02973E-D3AF-4A5C-BEED-62F0ADE598E1}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\OxygenPanelDaemon.exe Brak pliku FirewallRules: [{97FE5198-170E-49F8-AB65-03CEE99AEAAD}] => (Allow) D:\PROGRAM DO OBRÓBKI FILMÓW\DPDecoder.exe Brak pliku FirewallRules: [{49AAB8BA-750D-4370-BEBF-58E2A1059672}] => (Allow) C:\ProgramData\Blackmagic Design\DaVinci Resolve\Support\QtDecoder\QTDecoder.exe Brak pliku FirewallRules: [TCP Query User{D9E910B1-3610-4FDD-B5D8-0AADE12BFC34}D:\program do obróbki filmów\dpdecoder.exe] => (Allow) D:\program do obróbki filmów\dpdecoder.exe Brak pliku FirewallRules: [UDP Query User{AC33100E-91C2-41C7-A3CF-D01DF86B67B0}D:\program do obróbki filmów\dpdecoder.exe] => (Allow) D:\program do obróbki filmów\dpdecoder.exe Brak pliku FirewallRules: [TCP Query User{15D6C71C-35B5-4180-9BD1-D789485C73DB}D:\program do obróbki filmów\resolve.exe] => (Allow) D:\program do obróbki filmów\resolve.exe Brak pliku FirewallRules: [UDP Query User{1E0D9A57-E0CE-41AE-8721-BE0CE66690B0}D:\program do obróbki filmów\resolve.exe] => (Allow) D:\program do obróbki filmów\resolve.exe Brak pliku FirewallRules: [TCP Query User{C1ADE104-941D-4632-9DCB-AE24AB43EA67}D:\program do obróbki filmów\fuscript.exe] => (Allow) D:\program do obróbki filmów\fuscript.exe Brak pliku FirewallRules: [UDP Query User{100C0819-2C3D-49D6-AA39-94F7BEC50CFA}D:\program do obróbki filmów\fuscript.exe] => (Allow) D:\program do obróbki filmów\fuscript.exe Brak pliku FirewallRules: [TCP Query User{B92BE422-15F9-4F2B-9C09-776F39574E32}D:\program do obróbki filmów\davincipaneldaemon.exe] => (Allow) D:\program do obróbki filmów\davincipaneldaemon.exe Brak pliku FirewallRules: [UDP Query User{F63332AF-A0E1-4B7A-9019-BCCE8C073966}D:\program do obróbki filmów\davincipaneldaemon.exe] => (Allow) D:\program do obróbki filmów\davincipaneldaemon.exe Brak pliku FirewallRules: [{438EDD81-7556-457D-8A24-56DBC5FA4C1B}] => (Allow) D:\STEAM\steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{AEE991FD-50E2-48AE-AD03-D7C8D2268460}] => (Allow) D:\STEAM\steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{F651EBAE-5E7B-476F-8D10-8121617E488F}] => (Allow) D:\STEAM\steam\bin\cef\cef.win7\steamwebhelper.exe Brak pliku FirewallRules: [{B5F7C469-EA82-4181-BE23-4A581A7275B8}] => (Allow) D:\STEAM\steam\bin\cef\cef.win7\steamwebhelper.exe Brak pliku FirewallRules: [{E437875C-ED57-4B58-AAD5-D5316B5661C7}] => (Allow) D:\STEAM\steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe (BeamNG GmbH) [Brak podpisu cyfrowego] FirewallRules: [{5CB6CD22-84BB-4A7F-8AF0-39A7F40EFA25}] => (Allow) D:\STEAM\steam\steamapps\common\BeamNG.drive\BeamNG.drive.exe (BeamNG GmbH) [Brak podpisu cyfrowego] FirewallRules: [{A737BA91-96C4-40C4-96C9-236F12C72FA1}] => (Allow) D:\STEAM\steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{9178D865-2E4A-45B4-9B07-0A49C20FAECE}] => (Allow) D:\STEAM\steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [TCP Query User{2B2C599C-F1F2-497C-AA64-3D5B37942750}D:\gry\world_of_tanks_eu\win32\worldoftanks.exe] => (Allow) D:\gry\world_of_tanks_eu\win32\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [UDP Query User{90FCA82E-6777-4C68-A9DD-E5B82329F298}D:\gry\world_of_tanks_eu\win32\worldoftanks.exe] => (Allow) D:\gry\world_of_tanks_eu\win32\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [TCP Query User{86520F6F-69C5-4883-84A0-D02623A2D16C}D:\sterowniki do myszy\hera\herapassserver.exe] => (Block) D:\sterowniki do myszy\hera\herapassserver.exe (GAMDIAS) [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{B57E02AF-A500-4CFA-9E90-A8255D97F2A0}D:\sterowniki do myszy\hera\herapassserver.exe] => (Block) D:\sterowniki do myszy\hera\herapassserver.exe (GAMDIAS) [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{6EF432BD-BBDC-4361-BAEA-6EC9C566919B}D:\gry\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe] => (Allow) D:\gry\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe Brak pliku FirewallRules: [UDP Query User{4DC1D6A5-FABA-4FAF-B4C4-D72E5314210E}D:\gry\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe] => (Allow) D:\gry\pubglite\client\shadowtrackerextra\binaries\win64\pubglite-win64-shipping.exe Brak pliku FirewallRules: [TCP Query User{4BD9894E-FB13-4E73-A91A-1E5026ABD89E}D:\sterowniki do myszy\hera\herapassserver.exe] => (Allow) D:\sterowniki do myszy\hera\herapassserver.exe (GAMDIAS) [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{80DCFA71-F0C9-46BC-AA04-58313CBBF708}D:\sterowniki do myszy\hera\herapassserver.exe] => (Allow) D:\sterowniki do myszy\hera\herapassserver.exe (GAMDIAS) [Brak podpisu cyfrowego] FirewallRules: [{5FEAFD4B-C5F2-4B4E-890C-2EC039A7BB2F}] => (Allow) D:\STEAM\steam\steamapps\common\War Thunder\launcher.exe (Gaijin Network LTD -> Gaijin Entertainment) FirewallRules: [{C91E28C4-8D31-4B75-A6DB-DF7D623BBF73}] => (Allow) D:\STEAM\steam\steamapps\common\War Thunder\launcher.exe (Gaijin Network LTD -> Gaijin Entertainment) FirewallRules: [TCP Query User{54FD74EA-E29B-4BF5-94C8-D802BB8246C2}D:\steam\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) D:\steam\steam\steamapps\common\war thunder\win64\aces.exe (Gaijin Network LTD -> Gaijin Entertainment) FirewallRules: [UDP Query User{D04D37A4-FE96-48E4-8AB9-09D6C7174966}D:\steam\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) D:\steam\steam\steamapps\common\war thunder\win64\aces.exe (Gaijin Network LTD -> Gaijin Entertainment) FirewallRules: [TCP Query User{79CC3805-05BC-4476-AEE1-9FB99F70EED1}D:\gry\runtime\jre-x64\bin\javaw.exe] => (Allow) D:\gry\runtime\jre-x64\bin\javaw.exe FirewallRules: [UDP Query User{A98DBAFE-9AF4-4AED-BA4D-60D8142FFAEA}D:\gry\runtime\jre-x64\bin\javaw.exe] => (Allow) D:\gry\runtime\jre-x64\bin\javaw.exe FirewallRules: [TCP Query User{F837A7FB-82B9-41F1-87E6-64F5629BB759}D:\gry\runtime\jre-x64\bin\javaw.exe] => (Allow) D:\gry\runtime\jre-x64\bin\javaw.exe FirewallRules: [UDP Query User{47269465-A6B3-463D-A4EF-415ED2EFE270}D:\gry\runtime\jre-x64\bin\javaw.exe] => (Allow) D:\gry\runtime\jre-x64\bin\javaw.exe FirewallRules: [{492F4398-35FE-486E-91E8-6E1C224B4615}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (AVAST Software s.r.o. -> AVAST Software) FirewallRules: [TCP Query User{25EC53EC-CD17-4AE0-8F7B-79D152D3CC27}C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe Brak pliku FirewallRules: [UDP Query User{33705CF6-5E39-4484-ADC9-C0C592192FDA}C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe Brak pliku FirewallRules: [{4E239B77-0E63-4CCE-AD84-0F33CCB68153}] => (Allow) D:\STEAM\steam\steamapps\common\Universe Sandbox 2\Universe Sandbox x64.exe () [Brak podpisu cyfrowego] FirewallRules: [{FFD8D667-2E70-416E-8D72-F5C7C636D88D}] => (Allow) D:\STEAM\steam\steamapps\common\Universe Sandbox 2\Universe Sandbox x64.exe () [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{2114E0AF-8972-44FD-B585-6A818FC243F8}C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe Brak pliku FirewallRules: [UDP Query User{C1CC7A16-C672-4AD1-AA42-7FE212A6E192}C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_8795078\java.exe Brak pliku FirewallRules: [TCP Query User{B1CE643D-8439-4815-BB3F-B29D99F957DE}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [UDP Query User{79FE4065-E9F2-4BDC-9EF9-53061D80E375}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe (Wargaming.net Limited -> Wargaming.net) FirewallRules: [{7F300EF7-FDB1-4BA5-BF95-7E3B3A4D0971}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{45CCE285-6292-4B50-B39B-6542768F5518}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{8C73AA6F-2014-470D-B87F-79B074F2F75F}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{5A631C4C-F5C7-45C9-A17B-FC98E87237F4}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{E3FECEA2-A6C6-4F05-8DF7-46419BF1F7FE}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{93D2B335-443F-4490-8FE2-032B834E3418}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{A3BC95B2-377F-4F7C-97F7-B8FB048315C0}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{E39525B3-DABB-41D8-88FA-602198F44EBD}] => (Allow) D:\WindowsApps\SpotifyAB.SpotifyMusic_1.122.633.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{5CDDDF91-D390-43A0-A7A2-BB922FC24A52}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Punkty Przywracania systemu ========================= UWAGA: Przywracanie systemu jest wyłączone (Total:111.16 GB) (Free:58.14 GB) (52%) ==================== Wadliwe urządzenia w Menedżerze urządzeń ============ ==================== Błędy w Dzienniku zdarzeń: ======================== Dziennik Aplikacja: ================== Dziennik System: ============= Error: (01/17/2020 08:13:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi MBAMInstallerService z powodu następującego błędu: Nie można odnaleźć określonego pliku. Error: (01/17/2020 08:13:41 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: ZARZĄDZANIE NT) Description: Uruchomienie modułu rozszerzalności sieci WLAN nie powiodło się. Ścieżka modułu: C:\Windows\system32\Rtlihvs.dll Kod błędu: 126 Error: (01/17/2020 08:13:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa użytkownika powiadomień WNS_18396b3. Error: (01/17/2020 08:13:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa użytkownika powiadomień WNS_18396b3. CodeIntegrity: =================================== Date: 2020-01-17 20:15:43.569 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2020-01-17 20:15:43.563 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements. Date: 2020-01-17 20:15:43.558 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2020-01-17 20:15:43.553 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements. Date: 2020-01-17 20:15:43.541 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2020-01-17 20:15:43.534 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements. Date: 2020-01-17 20:14:48.224 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-01-17 20:14:48.209 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. ==================== Statystyki pamięci =========================== BIOS: American Megatrends Inc. F2 08/08/2018 Płyta główna: Gigabyte Technology Co., Ltd. B450M DS3H-CF Procesor: AMD Ryzen 3 2200G with Radeon Vega Graphics Procent pamięci w użyciu: 22% Całkowita pamięć fizyczna: 15307.32 MB Dostępna pamięć fizyczna: 11833.91 MB Całkowita pamięć wirtualna: 17611.32 MB Dostępna pamięć wirtualna: 13783.59 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:111.16 GB) (Free:58.13 GB) NTFS Drive d: () (Fixed) (Total:931.5 GB) (Free:748.55 GB) NTFS \\?\Volume{fc75c787-5e91-41da-8869-c1e997202ee3}\ (Odzyskiwanie) (Fixed) (Total:0.52 GB) (Free:0.13 GB) NTFS \\?\Volume{71476211-cd40-4824-b68d-5ec2f25e3d22}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Tablica partycji ==================== ========================================================== Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== Koniec Addition.txt =======================