Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 14-08-2021 Uruchomiony przez User (17-08-2021 08:41:57) Run:1 Uruchomiony z C:\Users\User\Downloads Załadowane profile: User Tryb startu: Normal ============================================== fixlist - zawartość: ***************** HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA S3 MpKsl8d98f40c; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{98D74470-176D-43FB-94B1-9A1CFEBE0E54}\MpKslDrv.sys [X] Edge Extension: (Brak nazwy) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [nie znaleziono] Edge Extension: (Brak nazwy) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [nie znaleziono] Edge Extension: (Brak nazwy) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [nie znaleziono] Edge Extension: (Brak nazwy) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [nie znaleziono] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku FirewallRules: [UDP Query User{E5CEBDA9-6E43-44AF-84D7-4C2184DD5445}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe => Brak pliku FirewallRules: [TCP Query User{29F3E7AC-5248-4AA3-814F-468981B87EF7}C:\program files\bitcomet\bitcomet.exe] => (Allow) C:\program files\bitcomet\bitcomet.exe => Brak pliku FirewallRules: [{192A3153-6AE0-4298-B613-4D45CEFC2297}] => (Allow) C:\Users\User\AppData\Roaming\Zoom\bin\airhost.exe => Brak pliku FirewallRules: [UDP Query User{05593B62-A413-4A55-8993-BA6E74FD8130}C:\users\user\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\67.0.3575.97\opera.exe => Brak pliku FirewallRules: [TCP Query User{B3F0A3C3-2A13-48BA-AC91-119EC4F181C8}C:\users\user\appdata\local\programs\opera\67.0.3575.97\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\67.0.3575.97\opera.exe => Brak pliku FirewallRules: [UDP Query User{509114B5-6F71-4886-A30C-92E5BEC8A450}C:\users\user\appdata\local\programs\opera\66.0.3515.103\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\66.0.3515.103\opera.exe => Brak pliku FirewallRules: [TCP Query User{946E367C-F4CB-40EF-A9D3-0D4405BF6226}C:\users\user\appdata\local\programs\opera\66.0.3515.103\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\66.0.3515.103\opera.exe => Brak pliku FirewallRules: [TCP Query User{5AB4A264-14CC-4A91-A387-02B6210F5902}C:\users\user\desktop\imagej\imagej.exe] => (Allow) C:\users\user\desktop\imagej\imagej.exe => Brak pliku FirewallRules: [UDP Query User{DE0BF156-6E30-4579-A354-CF3A350B1FD7}C:\users\user\desktop\imagej\imagej.exe] => (Allow) C:\users\user\desktop\imagej\imagej.exe => Brak pliku FirewallRules: [TCP Query User{612C5CB1-4905-4C9A-899F-E854BF549FA3}C:\users\user\appdata\local\programs\opera\65.0.3467.62\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\65.0.3467.62\opera.exe => Brak pliku FirewallRules: [UDP Query User{C8AF5CF1-ED0C-4333-B400-6E4A8FE677FB}C:\users\user\appdata\local\programs\opera\65.0.3467.62\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\65.0.3467.62\opera.exe => Brak pliku FirewallRules: [{87CF360A-6C4F-4238-8F86-3B667C3E1BFE}] => (Allow) C:\Program Files\BitComet\BitComet.exe => Brak pliku FirewallRules: [{6AC26BCE-A8EE-4235-AA1C-84EF90A9AE9B}] => (Allow) C:\Program Files\BitComet\BitComet.exe => Brak pliku FirewallRules: [TCP Query User{6F7E5565-0FA9-47E2-A585-36037E2D871D}C:\users\user\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\65.0.3467.78\opera.exe => Brak pliku FirewallRules: [UDP Query User{214081E5-C0AB-4014-877B-85BF2711508F}C:\users\user\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\user\appdata\local\programs\opera\65.0.3467.78\opera.exe => Brak pliku Shortcut: C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Driver Booster.lnk -> C:\Program Files (x86)\IObit\Driver Booster\7.5.0\DriverBooster.exe (Brak pliku) Shortcut: C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 7\Dezinstalacja aplikacji Driver Booster 7.lnk -> C:\Program Files (x86)\IObit\Driver Booster\7.5.0\unins000.exe (Brak pliku) Shortcut: C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 7\Driver Booster 7.lnk -> C:\Program Files (x86)\IObit\Driver Booster\7.5.0\DriverBooster.exe (Brak pliku) Shortcut: C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\Program Files (x86)\IObit\Driver Booster\7.5.0\Driver Booster 7.lnk -> C:\Program Files (x86)\IObit\Driver Booster\7.5.0\DriverBooster.exe (Brak pliku) Shortcut: C:\Users\User\Desktop\programy\BitComet.lnk -> C:\Program Files\BitComet\BitComet.exe (Brak pliku) Shortcut: C:\Users\User\Desktop\programy\Driver Booster 7.lnk -> C:\Program Files (x86)\IObit\Driver Booster\7.5.0\DriverBooster.exe (Brak pliku) Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Tombstones\Driver Booster (2).lnk -> C:\Program Files (x86)\IObit\Driver Booster\7.5.0\DriverBooster.exe (Brak pliku) ***************** HKLM\SOFTWARE\Policies\Mozilla => pomyślnie usunięto HKLM\SOFTWARE\Policies\Google => pomyślnie usunięto MpKsl8d98f40c => serwis nie znaleziono. HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => pomyślnie usunięto HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => pomyślnie usunięto HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E5CEBDA9-6E43-44AF-84D7-4C2184DD5445}C:\program files\bitcomet\bitcomet.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{29F3E7AC-5248-4AA3-814F-468981B87EF7}C:\program files\bitcomet\bitcomet.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{192A3153-6AE0-4298-B613-4D45CEFC2297}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{05593B62-A413-4A55-8993-BA6E74FD8130}C:\users\user\appdata\local\programs\opera\67.0.3575.97\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B3F0A3C3-2A13-48BA-AC91-119EC4F181C8}C:\users\user\appdata\local\programs\opera\67.0.3575.97\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{509114B5-6F71-4886-A30C-92E5BEC8A450}C:\users\user\appdata\local\programs\opera\66.0.3515.103\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{946E367C-F4CB-40EF-A9D3-0D4405BF6226}C:\users\user\appdata\local\programs\opera\66.0.3515.103\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5AB4A264-14CC-4A91-A387-02B6210F5902}C:\users\user\desktop\imagej\imagej.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DE0BF156-6E30-4579-A354-CF3A350B1FD7}C:\users\user\desktop\imagej\imagej.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{612C5CB1-4905-4C9A-899F-E854BF549FA3}C:\users\user\appdata\local\programs\opera\65.0.3467.62\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C8AF5CF1-ED0C-4333-B400-6E4A8FE677FB}C:\users\user\appdata\local\programs\opera\65.0.3467.62\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{87CF360A-6C4F-4238-8F86-3B667C3E1BFE}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6AC26BCE-A8EE-4235-AA1C-84EF90A9AE9B}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6F7E5565-0FA9-47E2-A585-36037E2D871D}C:\users\user\appdata\local\programs\opera\65.0.3467.78\opera.exe" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{214081E5-C0AB-4014-877B-85BF2711508F}C:\users\user\appdata\local\programs\opera\65.0.3467.78\opera.exe" => pomyślnie usunięto "C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Driver Booster.lnk" => nie znaleziono "C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 7\Dezinstalacja aplikacji Driver Booster 7.lnk" => nie znaleziono "C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 7\Driver Booster 7.lnk" => nie znaleziono "C:\ProgramData\CheckMAL\AppCheck\RansomShelter\Device\HarddiskVolume4\Program Files (x86)\IObit\Driver Booster\7.5.0\Driver Booster 7.lnk" => nie znaleziono C:\Users\User\Desktop\programy\BitComet.lnk => pomyślnie przeniesiono C:\Users\User\Desktop\programy\Driver Booster 7.lnk => pomyślnie przeniesiono C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Tombstones\Driver Booster (2).lnk => pomyślnie przeniesiono ==== Koniec Fixlog 08:41:58 ====