Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x64) Wersja: 01-07-2025 Uruchomiony przez PC (01-07-2025 16:09:08) Uruchomiony z C:\Users\PC\Downloads Microsoft Windows 11 Pro Wersja 24H2 26100.4484 (X64) (2024-10-08 13:01:26) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= (Załączenie wejścia w fixlist spowoduje jego usunięcie.) Administrator (S-1-5-21-253548459-3443913753-2107736815-500 - Administrator - Disabled) Gość (S-1-5-21-253548459-3443913753-2107736815-501 - Limited - Disabled) Konto domyślne (S-1-5-21-253548459-3443913753-2107736815-503 - Limited - Disabled) Mama (S-1-5-21-253548459-3443913753-2107736815-1002 - Administrator - Enabled) => C:\Users\Mama PC (S-1-5-21-253548459-3443913753-2107736815-1001 - Administrator - Enabled) => C:\Users\PC WDAGUtilityAccount (S-1-5-21-253548459-3443913753-2107736815-504 - Limited - Disabled) ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) µTorrent (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\uTorrent) (Version: 3.5.5.45790 - BitTorrent Inc.) AIDA64 Extreme v7.00 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 7.00 - FinalWire Ltd.) Akko Cloud Driver 0.0.0 (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\3b87340d-d0a0-5dd5-be42-4d2cdcb0c3c2) (Version: 0.0.0 - ) Alipay Cert Component 2.6.0.0 (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\AlipayCert) (Version: 2.6.0.0 - Alipay.com Co., Ltd.) AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.) AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.134 - Advanced Micro Devices, Inc.) Hidden AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.9 - Advanced Micro Devices, Inc.) Hidden AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.39.0.0 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden AMD Ryzen Master SDK (HKLM\...\{DBD50508-5F75-416B-995D-C42433A00944}) (Version: 2.14.2.3330 - Advanced Micro Devices, Inc.) AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.44 - Advanced Micro Devices, Inc.) Hidden AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: GENER - Advanced Micro Devices, Inc.) AMD_Chipset_Drivers (HKLM-x32\...\{43ab2cfd-3f71-4aa8-ab15-5f517f620c41}) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.) Hidden AntiCheatExpert (HKLM\...\AntiCheatExpert) (Version: 20.3.2505.653 - ) Balanced (HKLM-x32\...\{EFD0705E-598B-46D4-8D5B-4539431764B8}) (Version: 2.02.0000 - Advanced Micro Devices, Inc.) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Beach Life (HKLM-x32\...\{F9657EF6-C156-4CE9-A0A2-562CD3E94842}) (Version: - ) BlueStacks (HKLM\...\BlueStacks_nxt) (Version: 5.21.630.1018 - now.gg, Inc.) BlueStacks Services (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\BlueStacksServices) (Version: 3.0.9 - now.gg, Inc.) Brother MFL-Pro Suite DCP-1510 series (HKLM-x32\...\{90C24B16-9C28-44AB-8C63-BB9822218E18}) (Version: 1.0.0.0 - Brother Industries, Ltd.) CCleaner (HKLM\...\CCleaner) (Version: 6.37 - Piriform) Chrome Remote Desktop Host (HKLM-x32\...\{54085C96-EA33-4490-B68E-CC3B2C4C9AB7}) (Version: 138.0.7204.6 - Google LLC) Discord (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\Discord) (Version: 0.0.310 - Discord Inc.) DZLauncher version 0.1.6.8 (HKLM-x32\...\{1E299AE2-74C8-4CD8-6B17-A86E0ED3C4D2}_is1) (Version: 0.1.6.8 - Maca134) DZSALauncher version 0.0.5.4 (HKLM-x32\...\DZSALauncher_is1) (Version: 0.0.5.4 - Maca134) EA app (HKLM\...\{C2622085-ABD2-49E5-8AB9-D3D6A642C091}) (Version: 13.491.0.6004 - Electronic Arts) Hidden EA app (HKLM-x32\...\{6a2cab7c-78d8-42d9-bb85-6674959d4c77}) (Version: 13.491.0.6004 - Electronic Arts) e-file [ID] wersja 1.5.15.0 (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\{EF9A27D3-62E7-473E-9D32-23653A0F6CBB}_is1) (Version: 1.5.15.0 - e-file sp. z o.o. sp. k.) Epic Games Launcher (HKLM-x32\...\{C1338E61-3B7A-43B6-9FDA-D519EEBE045D}) (Version: 1.1.215.0 - Epic Games, Inc.) Epic Online Services (HKLM-x32\...\{4B31654B-80C2-405C-91C9-49B14AEB0F42}) (Version: 2.0.32.0 - Epic Games, Inc.) e-pity 17.4.1 za rok 2024 (HKLM-x32\...\{80D8170E-5590-218-B9ED-E24E4C99A11D}_is1) (Version: 17.4.1 - e-file sp. z o.o. sp.k.) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) FACEIT Anti-Cheat (HKLM\...\{1419E44C-0EF4-4822-9194-9F1A4D43973D}_is1) (Version: 2.0 - FACEIT LTD) GOG.com Heroes of Might and Magic 3 (HKLM\...\{1d3c859c-1028-4822-b0a7-da4f7bbc18bc}.sdb) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 138.0.7204.97 - Google LLC) Grammarly (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\GrammarlyForWindows) (Version: 1.5.75 - Grammarly) Grammarly for Microsoft® Office Suite (HKLM\...\{DE46CC28-5477-4CFB-9AE2-8C7C111E3EE7}) (Version: 6.8.261 - Grammarly) Hidden Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\{ee962c45-b827-4262-a720-3a939910ce37}) (Version: 6.8.261 - Grammarly) Grand Theft Auto V Enhanced (HKLM-x32\...\{5EFC6C07-6B87-43FC-9524-F9E967241741}) (Version: 1.0.811.8 - Rockstar Games) iCloud Outlook (HKLM\...\{7AB369BE-3EC1-475A-AEEE-BF91FE270A39}) (Version: 15.2.0.157 - Apple Inc.) Java(TM) SE Development Kit 14.0.1 (64-bit) (HKLM\...\{AF1122ED-203C-5CC1-8249-F85131C61AC4}) (Version: 14.0.1.0 - Oracle Corporation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden League of Legends (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc) Microsoft .NET Host - 6.0.36 (x64) (HKLM\...\{D6932D97-36F1-40B8-9CDC-CA8365B21000}) (Version: 48.144.23141 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 6.0.36 (x64) (HKLM\...\{A9E32B25-994B-4856-A12B-0EBED3050410}) (Version: 48.144.23141 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 6.0.36 (x64) (HKLM\...\{C912E33F-956A-4921-9F55-CC11AE8F09AF}) (Version: 48.144.23141 - Microsoft Corporation) Hidden Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 138.0.3351.55 - Microsoft Corporation) Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation) Microsoft Office Home 2024 - en-us (HKLM\...\Home2024Retail - en-us) (Version: 16.0.18827.20164 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\OneDriveSetup.exe) (Version: 24.025.0204.0003 - Microsoft Corporation) Microsoft OneNote - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 16.0.18827.20164 - Microsoft Corporation) Microsoft Teams (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\Teams) (Version: 1.6.00.33567 - Microsoft Corporation) Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.25702 - Microsoft) Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34438 (HKLM-x32\...\{ba10fda9-f731-441f-a999-000bbb7ceec2}) (Version: 14.42.34438.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34438 (HKLM-x32\...\{A5592FEF-F948-4BA6-A066-8BBFC2DC7EE1}) (Version: 14.42.34438 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34438 (HKLM-x32\...\{5D0C4511-3CA1-4FF8-A4BA-C0E1957ABEEA}) (Version: 14.42.34438 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM\...\{61D4736B-3325-4D4A-BD41-8BD206C6A86E}) (Version: 48.144.23186 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 6.0.36 (x64) (HKLM-x32\...\{0532b8f2-12d7-43de-95fc-7b87006758a8}) (Version: 6.0.36.34217 - Microsoft Corporation) MoH:AA Spearhead - wersja polska (HKLM-x32\...\{281C9F53-AD2C-490A-9473-17713E9C8125}) (Version: 0.40.0000 - Michal "[FPP]SavageMarine" Janczykowski) MSI Afterburner 4.6.4 (HKLM-x32\...\Afterburner) (Version: 4.6.4 - MSI Co., LTD) MSI Center SDK (HKLM-x32\...\{15289038-41BE-48F8-B8B9-0B1021D3089E}}_is1) (Version: 3.2025.0617.01 - MSI) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.6.9 - Notepad++ Team) NVIDIA FrameView (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameView) (Version: 1.4.8323.32104943 - NVIDIA Corporation) NVIDIA FrameView SDK 1.5.10819.35301613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.5.10819.35301613 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation) NVIDIA Sterownik dźwięku HD 1.4.3.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.3.2 - NVIDIA Corporation) NVIDIA Sterownik graficzny 576.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 576.80 - NVIDIA Corporation) Ö§¸¶±¦°˛Č«żŘĽţ 4.0.0.101 (HKLM-x32\...\alieditplus) (Version: 4.0.0.101 - Alipay.com Co., Ltd.) OEM Application Profile (HKLM-x32\...\{84AD2AF7-10C8-0395-66F9-FFAEB4C5DBF1}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.18827.20102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.18827.20164 - Microsoft Corporation) Hidden Open Multiplayer Launcher (HKLM-x32\...\Open Multiplayer Launcher) (Version: 1.5.2 - open) ParkControl (HKLM-x32\...\ParkControl) (Version: 5.2.0.6 - Bitsum) PowerToys (Preview) (HKLM\...\{E8F0C415-D535-4D4F-B0BE-759C5C6DC9E1}) (Version: 0.84.1 - Microsoft Corporation) Hidden PowerToys (Preview) x64 (HKLM-x32\...\{73832102-bbe4-4baa-aa29-6ae822b1b9e8}) (Version: 0.84.1 - Microsoft Corporation) Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.3.0 - Advanced Micro Devices, Inc.) Hidden Qualcomm USB Drivers For Windows (HKLM-x32\...\{D9FB7F91-9687-4B09-894D-072903CADEA4}) (Version: 1.00.25 - QUALCOMM Incorporated) Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9738.1 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.71.312.2024 - Realtek) REDlauncher (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\{7258BA11-600C-430E-A759-27E2C691A335}-REDlauncher_is1) (Version: - GOG.com) Riot Vanguard (HKLM\...\Riot Vanguard) (Version: - Riot Games, Inc.) RivaTuner Statistics Server 7.3.6 (HKLM-x32\...\RTSS) (Version: 7.3.6 - Unwinder) Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.101.2370 - Rockstar Games) Rockstar Games SDK (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.4.0.52 - Rockstar Games) Session 1.15.1 (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\f1339da8-b3f2-5116-b780-aafa611bc7f7) (Version: 1.15.1 - Session Foundation) SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.34.9745 - SoftEther VPN Project) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Środowisko uruchomieniowe Microsoft Edge WebView2 (HKLM-x32\...\Microsoft EdgeWebView) (Version: 137.0.3296.93 - Microsoft Corporation) Hidden TeamSpeak (HKLM\...\{ABBB9B76-9258-4FD5-B000-12041AAD8782}) (Version: 5.0.0 - TeamSpeak) TeamSpeak 3 Client (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\TeamSpeak 3 Client) (Version: 3.2.5 - TeamSpeak Systems GmbH) The Witcher 3 HD Reworked Project (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\The Witcher 3 HD Reworked Project 5.1) (Version: 5.1 - HalkHoganPL) UE4 Prerequisites (x64) (HKLM\...\{F9EC45F9-074A-48BF-92E9-A8CADD56F693}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{0d995f46-317b-4b5f-bf3e-9f98bae9d339}) (Version: 1.0.14.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{4e242cc8-5e3c-4b08-9d55-dbc62ddd1208}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN) WeChat (HKLM-x32\...\WeChat) (Version: 3.7.0.26 - 腾讯科技(深圳)有限公司) WinRAR 7.01 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 7.01.0 - win.rar GmbH) 阿里旺旺 (HKLM-x32\...\阿里旺旺) (Version: 9.12.10C - 阿里巴巴(中国)有限公司) Chrome apps: ============ Arkusze (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\b16c46758ea30fb6fae83d930cb54321) (Version: 1.0 - Google\Chrome) Dokumenty (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\8e812839c3e3f12c341a32d1ef3163ef) (Version: 1.0 - Google\Chrome) Dysk Google (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\ab81d35554a932fc375c4f1524eed2c4) (Version: 1.0 - Google\Chrome) Gmail (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\8d932de5387e8ea7acdbe92422229e44) (Version: 1.0 - Google\Chrome) Prezentacje (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\6593cbac87adafbd7bf30f59ebc64946) (Version: 1.0 - Google\Chrome) YouTube (HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\487cdb8940ea5d8cad155dd8488cc607) (Version: 1.0 - Google\Chrome) Packages: ========= @{MicrosoftWindows.54792954.Filons_1000.26100.4202.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.54792954.Filons/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.54792954.Filons_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.54792954.Filons_1000.26100.4351.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.54792954.Filons/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.54792954.Filons_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.55182690.Taskbar_1000.26100.3624.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-05-29] () @{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-05-29] () @{MicrosoftWindows.55182690.Taskbar_1000.26100.3912.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-05-29] () @{MicrosoftWindows.56978801.Voiess_1000.26100.4202.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.56978801.Voiess/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.56978801.Voiess_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.56978801.Voiess_1000.26100.4351.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.56978801.Voiess/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.56978801.Voiess_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.57058570.Speion_1000.26100.4202.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.57058570.Speion/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57058570.Speion_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.57058570.Speion_1000.26100.4351.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.57058570.Speion/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57058570.Speion_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.57074914.Livtop_1000.26100.4202.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.57074914.Livtop/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074914.Livtop_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.57074914.Livtop_1000.26100.4351.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.57074914.Livtop/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074914.Livtop_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.Client.CoreAI_1000.26100.3912.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CoreAI/AIXHost/ClickToDo/AppDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.Client.CoreAI_1000.26100.4061.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CoreAI/AIXHost/ClickToDo/AppDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.Client.CoreAI_1000.26100.4202.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CoreAI/AIXHost/ClickToDo/AppDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) @{MicrosoftWindows.Client.CoreAI_1000.26100.4351.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.CoreAI/AIXHost/ClickToDo/AppDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) HyperX NGENUITY -> C:\Program Files\WindowsApps\33C30B79.HyperXNGenuity_5.31.0.0_x64__0a78dr3hq0pvt [2025-06-04] (HP Inc.) [Startup Task] iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_15.3.152.0_x64__nzyj5cx40ttqa [2025-05-02] (Apple Inc.) [Startup Task] Kliknij, aby wykonać (wersja zapoznawcza) -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CoreAI_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-04-25] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-04-25] (Microsoft Corporation) [MS Ad] MSI Center -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.55.0_x64__kzh8wxbdkxb8p [2025-06-30] (MICRO-STAR INTERNATIONAL CO., LTD) [Startup Task] Notepad++ -> C:\Program Files\Notepad++\contextMenu [2024-09-11] (Notepad++) NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.968.0_x64__56jybvy8sckqj [2025-06-11] (NVIDIA Corp.) OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-06-24] () Pakiet Windows Feature Experience -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.54792954.Filons_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) Pakiet Windows Feature Experience -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.56978801.Voiess_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) Pakiet Windows Feature Experience -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57058570.Speion_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) Pakiet Windows Feature Experience -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074904.InpApp_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) Pakiet Windows Feature Experience -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074914.Livtop_cw5n1h2txyewy [2025-06-27] (Microsoft Windows) PDF Merger & Splitter -> C:\Program Files\WindowsApps\AnywaySoftInc.PDFMergerSplitter_2.0.1.0_x64__0qkrc2qacwvfm [2024-07-22] (AnywaySoft, Inc.) [MS Ad] PowerToys FileLocksmith Context Menu -> C:\Program Files\PowerToys\WinUI3Apps [2024-09-11] (Microsoft) PowerToys ImageResizer Context Menu -> C:\Program Files\PowerToys [2024-09-11] (Microsoft) PowerToys PowerRename Context Menu -> C:\Program Files\PowerToys\WinUI3Apps [2024-09-11] (Microsoft) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.51.349.0_x64__dt26b99r8h8gj [2024-10-09] (Realtek Semiconductor Corp) WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2524.4.0_x64__cv1g1gvanyjgm [2025-06-19] (WhatsApp Inc.) [Startup Task] WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-29] (Microsoft Corp.) WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_7000.522.1444.0_x64__8wekyb3d8bbwe [2025-06-26] (Microsoft Corp.) Windows File Recovery -> C:\Program Files\WindowsApps\Microsoft.WindowsFileRecovery_0.1.20151.0_x64__8wekyb3d8bbwe [2021-01-19] (Microsoft Corporation) WinRAR -> C:\Program Files\WinRAR [2024-09-11] (win.rar GmbH) Wintoys -> C:\Program Files\WindowsApps\11413PtruceanBogdan.Wintoys_2.0.91.0_x64__ankwhmsh70gj6 [2025-06-19] (Bogdan Pătrăucean) ==================== Niestandardowe rejestracje CLSID (filtrowane): ============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{08D512D2-7D97-4E22-B7DB-82791106C086}\InprocServer32 -> C:\Users\PC\AppData\Roaming\alipay\cf\alicdo_x64.dll (Alipay.com Co.,Ltd -> Alipay) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{10144713-1526-46C9-88DA-1FB52807A9FF}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.SvgThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{19C0F6F0-DFDD-4513-8751-915FAD91F339} -> [Zdjęcia iCloud] => C:\Users\PC\Pictures\iCloud Photos\Photos CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\PC\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.8.261\D2AC175CD9\GrammarlyShim64.dll (Grammarly, Inc. -> CompanyName) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{3F03BF53-1EA1-4A43-8B53-6662AE59412D} -> [iCloud Drive] => C:\Users\PC\iCloudDrive [2024-09-10 15:29] CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\Users\PC\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.8.261\D2AC175CD9\Grammarly.AddIn.Connect.ActiveX.dll (Grammarly, Inc. -> Grammarly) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{4D2EE9B9-B68F-4E5D-A58D-2253B0E2B01D} -> [iCloud Drive] => C:\Users\PC\iCloudDrive [2024-09-10 15:29] CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{5C4D8D77-5B87-40CA-884E-F56858227E5C}\localserver32 -> C:\Program Files\TeamSpeak\notification_helper.exe (TeamSpeak Systems GmbH -> The Chromium Authors) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{5ea9a442-5352-ed6e-d37f-9d511e7e2caa}\localserver32 -> C:\Program Files\PowerToys\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{60789D87-9C3C-44AF-B18C-3DE2C2820ED3}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.MarkdownPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{729B72CD-B72E-4FE9-BCBF-E954B33FE699}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.QoiPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{77257004-6F25-4521-B602-50ECC6EC62A6}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.StlThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32 -> => Brak pliku CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{A0257634-8812-4CE8-AF11-FA69ACAEAFAE}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.GcodePreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{A5A41CC7-02CB-41D4-8C9B-9087040D6098}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.PdfPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{AD856B15-D25E-4008-AFB7-AFAA55586188}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.QoiThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\PC\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{D8034CFA-F34B-41FE-AD45-62FCBB52A6DA}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.MonacoPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{D8BB9942-93BD-412D-87E4-33FAB214DC1A}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.PdfThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{F2847CBE-CD03-4C83-A359-1A8052C1B9D5}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.GcodeThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-253548459-3443913753-2107736815-1001_Classes\CLSID\{FCDD4EED-41AA-492F-8A84-31A1546226E0}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.SvgPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers2: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll [2024-09-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers3: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll [2024-09-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers3: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll [2024-09-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Brak pliku ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3253815aea1845c4\nvshext.dll [2025-06-13] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers5: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll [2024-09-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Brak pliku ==================== Codecs (filtrowane) ==================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Drivers32: [VIDC.RTV1] => c:\windows\system32\rtvcvfw64.dll [1102848 2023-04-10] () [Brak podpisu cyfrowego] HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [891904 2023-04-10] () [Brak podpisu cyfrowego] ==================== Skróty & WMI ======================== (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Arkusze.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 16" --app-id=fhihpiojkbmbpdjeoajapmgkhlnakfjf ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Dokumenty.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 16" --app-id=mpnpojknpmmopombnjdcgaaiekajbnjb ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Dysk Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 16" --app-id=aghbiahbpaijignceidepookljebhfak ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Gmail.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 16" --app-id=fmgjjmmmlfnkbppncabfkddbjimcfncm ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Prezentacje.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 16" --app-id=kefjledonklijopmnomlcbpllchaibag ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 16" --app-id=agimnkijcaahngcdmfeangaknmldooml ==================== Załadowane moduły (filtrowane) ============= 2020-11-17 19:54 - 2020-11-17 19:54 - 000063488 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\MSI Afterburner\PlugIns\Monitoring\HwInfo.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000232960 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\MSI Afterburner\RTCore.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000057344 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\MSI Afterburner\RTFC.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000668672 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000074240 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll 2021-12-03 15:36 - 2021-12-03 15:36 - 000371712 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\MSI Afterburner\RTUI.dll 2024-03-23 11:00 - 2024-03-23 11:00 - 000074240 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll 2024-03-23 11:01 - 2024-03-23 11:01 - 000112128 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll 2024-03-23 11:00 - 2024-03-23 11:00 - 000413696 _____ () [Brak podpisu cyfrowego] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll 2020-04-06 01:48 - 2020-04-06 01:48 - 005833216 _____ (University of Tsukuba) [Brak podpisu cyfrowego] C:\Program Files\SoftEther VPN Client\VpnGatePlugin_x64.dll ==================== Alternate Data Streams (filtrowane) ======== (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\WINDOWS\tracing:? [16] AlternateDataStreams: C:\ProgramData\CcAddAppList.mod:181AA586D5 [5154] AlternateDataStreams: C:\ProgramData\CcAddAppList.mod:7CAB5C5CDE [3442] AlternateDataStreams: C:\ProgramData\DP45977C.lfl:677104FCAA [5154] AlternateDataStreams: C:\ProgramData\fontcacheev1.dat:D758CE5CE2 [5154] AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [5154] AlternateDataStreams: C:\ProgramData\NVDisplayContainerWatchdog.log:204739A7F2 [3442] AlternateDataStreams: C:\ProgramData\NVDisplayContainerWatchdog.log_backup1:C3CA1050CA [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\SoftEther VPN Client Manager.lnk:5148F90048 [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FACEIT AC.lnk:550995E265 [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sticky Notes (new).lnk:954E53D7F9 [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak.lnk:DBB58A0286 [5154] AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk:7AD7FA8AB1 [5154] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [468] AlternateDataStreams: C:\Users\Public\Documents\CcAddAppList.mod:0983F7BAE6 [3442] ==================== Tryb awaryjny (filtrowane) ================== ==================== Powiązania plików (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) HKU\S-1-5-21-253548459-3443913753-2107736815-1001\Software\Classes\regfile: <==== UWAGA HKU\S-1-5-21-253548459-3443913753-2107736815-1001\Software\Classes\.reg: => <==== UWAGA HKU\S-1-5-21-253548459-3443913753-2107736815-1001\Software\Classes\.bat: => <==== UWAGA HKU\S-1-5-21-253548459-3443913753-2107736815-1001\Software\Classes\.cmd: => <==== UWAGA ==================== Internet Explorer (filtrowane) ============= BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2025-06-02] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-06-24] (Microsoft Corporation -> Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) IE trusted site: HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\sharepoint.com -> hxxps://psww-files.sharepoint.com ==================== Hosts - zawartość: ========================= (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2018-09-15 09:31 - 2024-05-17 21:23 - 000003488 _____ C:\WINDOWS\system32\drivers\etc\hosts 109.94.209.70 fitgirlrepacks.in # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.in # Fake FitGirl site 109.94.209.70 fitgirlrepacks.co # Fake FitGirl site 109.94.209.70 fitgirl-repacks.cc # Fake FitGirl site 109.94.209.70 fitgirl-repacks.to # Fake FitGirl site 109.94.209.70 fitgirl-repack.com # Fake FitGirl site 109.94.209.70 fitgirl-repacks.website # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.co # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks.cc # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks.to # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.com # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks.website # Fake FitGirl site 109.94.209.70 ww9.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 *.fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 fitgirl-repacks.xyz # Fake FitGirl site 109.94.209.70 fitgirl-repack.net # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.net # Fake FitGirl site 109.94.209.70 fitgirlpack.site # Fake FitGirl site 109.94.209.70 www.fitgirlpack.site # Fake FitGirl site 109.94.209.70 fitgirl-repack.org # Fake FitGirl site 109.94.209.70 www.fitgirl-repack.org # Fake FitGirl site 109.94.209.70 fitgirlrepacks.pro # Fake FitGirl site 109.94.209.70 www.fitgirlrepacks.pro # Fake FitGirl site 109.94.209.70 fitgirlrepack.games # Fake FitGirl site 109.94.209.70 www.fitgirlrepack.games # Fake FitGirl site 109.94.209.70 fitgirl-repacks-site.org # Fake FitGirl site 109.94.209.70 www.fitgirl-repacks-site.org # Fake FitGirl site 109.94.209.70 fitgirls-repacks.com # Fake FitGirl site 109.94.209.70 fitgirlrepack.cc # Fake FitGirl site 109.94.209.70 fitgirlrepacks.org # Fake FitGirl site 2019-04-28 15:28 - 2019-04-28 15:31 - 000000444 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics 172.17.120.17 DESKTOP-BA5V5FP.mshome.net # 2024 4 5 26 13 31 23 48 ==================== Network =========================== (Obecnie brak automatycznej naprawy dla tej sekcji.) DNS Servers: 1.1.1.2 - 1.0.0.2 Zapora systemu Windows [funkcja włączona] Network Binding: ============= VPN - VPN Client: VPN Client Adapter - VPN -> Neo6_x64_VPN.sys Ethernet 4: TAP-Windows Adapter V9 -> tap0901.sys Połączenie sieciowe Bluetooth 4: Bluetooth Device (Personal Area Network) #4 -> bthpan.sys Ethernet 6: Realtek PCIe GbE Family Controller #4 -> rt640x64.sys SeLow: SoftEther Lightweight Network Protocol ==================== Inne obszary =========================== (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-253548459-3443913753-2107736815-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\PC\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\NXf9T9.png HKU\S-1-5-21-253548459-3443913753-2107736815-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Mama\AppData\Local\Microsoft\Windows\Themes\img1.jpg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) HKU\S-1-5-21-253548459-3443913753-2107736815-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 0) HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5) HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0) HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\hogwart\Hogwarts.Legacy.Deluxe.Edition-EMPRESS\emp-hl.iso ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Załączenie wejścia w fixlist spowoduje jego usunięcie.) MSCONFIG\Services: BEService => 3 MSCONFIG\Services: EABackgroundService => 3 MSCONFIG\Services: edgeupdate => 2 MSCONFIG\Services: edgeupdatem => 3 HKLM\...\StartupApproved\StartupFolder: => "SoftEther VPN Client Manager Startup.lnk" HKLM\...\StartupApproved\StartupFolder: => "AnyDesk.lnk" HKLM\...\StartupApproved\Run: => "RtkAudUService" HKLM\...\StartupApproved\Run: => "SoftEther VPN Client UI Helper" HKLM\...\StartupApproved\Run: => "Riot Vanguard" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "BrStsInd00" HKLM\...\StartupApproved\Run32: => "ControlCenter4" HKLM\...\StartupApproved\Run32: => "BrStsMon00" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Lightshot" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\StartupFolder: => "Wysyłanie do programu OneNote.lnk" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "GalaxyClient" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "IDMan" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "Battle.net" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "iCloudDrive" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "iCloudServices" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "EADM" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "RiotClient" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "FACEIT" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "electron.app.BlueStacks Services" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "e-file [ID] - Asystent" HKU\S-1-5-21-253548459-3443913753-2107736815-1001\...\StartupApproved\Run: => "PC" ==================== Reguły Zapory systemu Windows (filtrowane) ================ (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [UDP Query User{A0065E68-B0AD-46E8-8261-E87945688636}C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monero-wallet-gui.exe] => (Allow) C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monero-wallet-gui.exe () [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{FE091760-1423-4815-84CA-D376FD86A410}C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monero-wallet-gui.exe] => (Allow) C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monero-wallet-gui.exe () [Brak podpisu cyfrowego] FirewallRules: [UDP Query User{2BAECF36-145A-4FED-BC15-389EA964ACB2}C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monerod.exe] => (Allow) C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monerod.exe () [Brak podpisu cyfrowego] FirewallRules: [TCP Query User{E57BF20D-D459-456B-80B6-B80056F551F5}C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monerod.exe] => (Allow) C:\users\pc\desktop\monero-gui-win-x64-v0.18.3.4\monero-gui-v0.18.3.4\monerod.exe () [Brak podpisu cyfrowego] FirewallRules: [{3743ADFC-D0A7-4B0D-85D1-1823B0D2E117}] => (Allow) C:\Program Files\PowerToys\PowerToys.MouseWithoutBorders.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{80F2BCE1-DC18-47CB-8AC5-D1B82972DC6C}] => (Allow) LPort=32682 FirewallRules: [{BADB89D5-A8BE-46A7-9A00-FBB4499F67D8}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{9929C3DB-7AC1-475D-B59F-9771C257DEA2}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [UDP Query User{DB4E819F-A092-48E8-90AE-917C149D1416}C:\users\pc\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\pc\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [TCP Query User{55502CC9-80BF-494B-9359-76DFA91E9FF4}C:\users\pc\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\pc\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [UDP Query User{3F1951BF-52D7-4BF4-9187-33435BEEA0B5}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{57302A3A-0FB5-4361-9A5E-068FCDDCDBB2}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{DC247CDB-EEC3-42D4-857C-9D38FA16C4E3}C:\users\pc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\pc\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{7150E060-452E-478F-8E02-96518DC23817}C:\users\pc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\pc\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{9B677E84-9F0B-4B22-A129-2348C285E2A6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{7DA01190-06BE-4393-9453-757256BE35EA}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{75A8BA3F-3CA0-45AC-B982-E722AA5D48AA}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{2A6D0172-0B6B-4A65-8282-1D443199D1DD}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [TCP Query User{90B35163-1CBA-4E52-9A8F-2AC88F3B0D2D}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [UDP Query User{7A3E988A-5ACA-4A84-84CA-FCCA36F4AF54}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [TCP Query User{50CC7097-C83E-43AD-9950-544C91B20427}C:\users\pc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\pc\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{C09AFA8F-F318-4635-BB32-906B9F5F9A19}C:\users\pc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\pc\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{854DCD98-6BC1-4959-9848-6A3CFFB6D11F}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{929957EA-EA4F-44AD-AB93-9C78EF365913}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{FB0B50C9-DAD6-4CBE-B362-534F0BB1DCBB}C:\program files (x86)\aliwangwang\aliim.exe] => (Allow) C:\program files (x86)\aliwangwang\aliim.exe (TAOBAO (CHINA) SOFTWARE CO.,LTD. -> Alibaba Group) FirewallRules: [UDP Query User{3B1C30EF-AB57-442C-BCAC-4DE9CED4F368}C:\program files (x86)\aliwangwang\aliim.exe] => (Allow) C:\program files (x86)\aliwangwang\aliim.exe (TAOBAO (CHINA) SOFTWARE CO.,LTD. -> Alibaba Group) FirewallRules: [TCP Query User{7AA203B6-590F-4F63-965B-8D35ADB3DC7D}C:\users\pc\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\pc\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [UDP Query User{5A741462-5DF8-441C-B9E9-F957992B7E75}C:\users\pc\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\pc\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [TCP Query User{A7EA5562-ECF6-4D09-8623-7BECCCCB6BAD}E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe] => (Allow) E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{8F99DFA2-B313-43C9-8E64-E53E68384C4C}E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe] => (Allow) E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{5B671E7E-1DB8-4E84-B362-A8F04756B597}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{091D62E7-EB69-4CED-84C4-A93A057F0342}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{F602955B-63DB-46C7-9A49-9845293555E1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{596D75F9-CDFE-4F40-B0A2-69B8704DC636}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.131.3202.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{8D182292-1F83-43F6-ADAB-698AAA54AB15}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24277.3102.3183.2670_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{AF8B6C10-C1B9-4ECF-90A3-808CFCC4B7B3}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24277.3102.3183.2670_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{6D7401CC-D2A3-4366-9E75-4F5F2673D23D}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24277.3507.3205.5228_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{E18D3E2D-CDAC-44E5-A9F4-A4D99E1E8872}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24277.3507.3205.5228_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{2A296E10-4D0E-4D7B-979C-979C130ACEC0}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{80D232A5-5653-43E0-A60C-1E97D0BCE7BA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{560A64F8-320C-4E0F-B5A1-75D6CD90B974}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{A01F909D-D4BF-401B-A383-ED9E8C05B10F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{B8E9A702-756D-4FC5-9948-FC26FDE81273}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FirewallRules: [{16C065E7-B93B-4D9B-BE33-CD0F17A6F047}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FirewallRules: [{1F1D7D07-1C97-4C40-AAD1-FD91657D29F5}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe (Now.gg, INC -> Bluestack Systems, Inc.) FirewallRules: [{4B314BBB-2D28-4C50-A04F-C982EC13C7CC}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe (Now.gg, INC -> BlueStack Systems) FirewallRules: [{E7471F44-1317-46DB-ADD2-BDF2C8FE8069}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe (Now.gg, INC -> The Qt Company Ltd.) FirewallRules: [{4CE47E45-8727-4CC5-B2DE-33BD5487EAC6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe (Valve Corp. -> Valve) FirewallRules: [{D909BD8B-620E-4223-9A88-11C1E78DF551}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe (Valve Corp. -> Valve) FirewallRules: [TCP Query User{F5034473-3938-433C-8830-5A4EE237C387}C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe] => (Allow) C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe (e-file sp. z o.o. -> e-file sp. z o.o. sp. k.) FirewallRules: [UDP Query User{C104B3F0-21C6-4A82-9691-11BA992473F7}C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe] => (Allow) C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe (e-file sp. z o.o. -> e-file sp. z o.o. sp. k.) FirewallRules: [{CACA1DFC-E15E-45B6-B9B9-F57416A180B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\game\bin\win64\cs2.exe (Valve Corp. -> ) FirewallRules: [{7000448F-8388-4D21-9A55-5EC1C072CD05}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\game\bin\win64\cs2.exe (Valve Corp. -> ) FirewallRules: [TCP Query User{37D93B49-BF8D-4C08-ACBA-584D22F503B3}E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe] => (Allow) E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [UDP Query User{6AEC6FEC-1593-4F82-A4CD-DB9BB40FC6C0}E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe] => (Allow) E:\grand theft auto - san andreas (the definitive edition) (build 10416362) (2023.02.16).7z\grand theft auto - san andreas (the definitive edition)\gameface\binaries\win64\sanandreas.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [TCP Query User{6D544403-798F-478C-A479-20E453E7B46A}C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe] => (Allow) C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe (e-file sp. z o.o. -> e-file sp. z o.o. sp. k.) FirewallRules: [UDP Query User{62B4457C-BF68-4D72-9551-2A0EC362BBF9}C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe] => (Allow) C:\program files (x86)\e-file\e-pity\efileid\efileidasystent.exe (e-file sp. z o.o. -> e-file sp. z o.o. sp. k.) FirewallRules: [{F7141DC9-2055-4567-90BA-4C07E4BCCF91}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZLauncher.exe (BOHEMIA INTERACTIVE a.s. -> Bohemia Interactive a.s.) FirewallRules: [{6FF18411-FA63-4E54-B2EA-3AC5085B14B6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZLauncher.exe (BOHEMIA INTERACTIVE a.s. -> Bohemia Interactive a.s.) FirewallRules: [{6335BD83-742E-49C6-9F15-6BE949CE4EF5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe (BOHEMIA INTERACTIVE a.s. -> BattlEye Innovations) FirewallRules: [{29D02FFF-E8E0-4006-BC30-B67DB6469FB3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe (BOHEMIA INTERACTIVE a.s. -> BattlEye Innovations) FirewallRules: [{5BBCA460-FA6A-476E-AD9B-08C6B77E7FB1}] => (Allow) E:\gta 5\Grand Theft Auto V Enhanced\GTA5_Enhanced.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [{E3533AD8-209E-4FF6-BA4D-7A0D61131C9C}] => (Allow) E:\gta 5\Grand Theft Auto V Enhanced\GTA5_Enhanced.exe (Rockstar Games, Inc. -> Rockstar Games) FirewallRules: [FPS-SpoolWorker-In-TCP] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [FPS-SpoolWorker-In-TCP-V2] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [FPS-SpoolWorker-In-TCP-NoScope] => (Allow) C:\WINDOWS\system32\spoolsvworker.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [TCP Query User{2B08511C-4172-438C-BA11-341755F43C9B}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [UDP Query User{678CE781-C3D3-47F2-9531-FDA3AB45FE1B}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [{6C270C6F-7B57-4834-BD2C-9F0A50DE9AD3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_x64.exe (BOHEMIA INTERACTIVE a.s. -> Bohemia Interactive a.s.) FirewallRules: [{D484BB57-39AC-4E7D-879F-69EEEF538B92}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_x64.exe (BOHEMIA INTERACTIVE a.s. -> Bohemia Interactive a.s.) FirewallRules: [{0A64D12F-F195-45FA-9CCD-44B41796E714}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{009F6B4A-3446-49DB-B390-E0479FDC34ED}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{2D300ADD-96CD-41B1-A0A1-BA8C4F11C36A}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{B069FFF0-0A07-4C96-8966-67F59529A3AF}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{1FF20FFE-1FA9-4F67-B5E3-B3B0056B9265}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{0E2D2641-8AA6-4681-B1D0-A03677EE0F59}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{19F17376-FF63-4A27-B84D-10B76A601D94}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{843498D8-587E-4156-ABD9-818FFEFE219A}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{2D2B1CAD-D5BC-4A45-988B-C525559A00FB}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{FA8CF564-E117-42F3-B629-CA586313786F}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{51DFFA25-5DAC-4BCB-947B-90B09B326D5C}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{13687A65-189D-4341-9161-EE7E961D07D5}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{203818C8-49A2-416A-9BDC-186F52AA0C63}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{8276CF23-64F6-40D6-A319-8532F401DB1C}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{88E86C69-15A7-46E8-B53E-7912B799E509}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{7221CE27-FDEC-40BD-B90C-E48768747698}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{A78CF41D-D2DF-489A-B744-554090D04A48}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\138.0.7204.6\remoting_host.exe (Google LLC -> Google LLC) FirewallRules: [{03C15885-08B8-411A-9F2A-87C8E58D7D0E}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{27190B66-C92E-4C28-AA01-502716AFB30C}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{73E9C95F-D37C-4764-9806-2AAA1BEB8402}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{6971C163-FF80-4224-B3A3-1656E254A1CD}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAConnect_microsoft.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{4671C9CE-0012-4656-904F-265C79B31FF7}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{B911BBE0-77D7-4076-AD3A-EDA0ADC5E21A}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EADesktop.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{A26E3E92-4435-4A7E-9563-0F49257EC06F}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{6DB8C9B5-D591-4E89-8DF4-BDA5B76AB20C}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EAGEP.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{08064853-3CE7-45D1-BAC7-EAF56B9C25E2}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{D6B885A4-F93A-4631-95F8-B84DEB65ACE7}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALocalHostSvc.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{6CD60650-862B-4B6C-9722-93C6D3987804}] => (Allow) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALaunchHelper.exe (Electronic Arts, Inc. -> Electronic Arts) FirewallRules: [{2A6DB81C-D7D2-4A8F-92CB-0E52D05C8077}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\137.0.3296.93\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{607FFEAC-B5C2-4A68-8457-A1DBB1D1126C}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{37359E4E-0DFA-433D-B8F9-A913D40419EB}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{5EE013CB-1E59-4709-B9C3-E83CC019E425}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{06670536-F07C-46E0-B02E-A0A43E0EF599}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{EAFAA0D2-62B5-408E-89E0-D2F64276D8BF}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{CCCC077A-1637-4D92-8266-DBCD6EB1E299}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{1A6DAECD-CC92-4736-8757-B2400568262B}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{39285C90-B8AD-4745-9F8D-34DFBDA0B822}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\WindowsBackupClient.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{DBF8C213-2777-4A14-85CA-AEBDC6AACD2F}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{1C71F70F-A012-4CD2-A6EC-A1D778E4455D}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{6ED8A142-7738-498F-BF1B-167AAC2E88B4}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{A137C3EF-7167-47DE-95BB-B6222C54DC87}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{C42B0C30-546A-44F3-A23C-A4B330D601AB}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{24C02765-33BD-4639-ADB1-15326E69BE1C}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{79641F90-31B0-4A06-AFFD-4F24B785E32C}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{810D9E55-2210-4860-946F-0F889B149420}] => (Allow) C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy\OobeHostApp.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{FC72961C-4C31-4DC4-B7B4-95E63A8B3C9A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Delta Force\Launcher\df_launcher.exe (PROXIMA BETA PTE. LIMITED -> Tencent) FirewallRules: [{065B433C-EB12-4AB8-896F-4679E55B1C23}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Delta Force\Launcher\df_launcher.exe (PROXIMA BETA PTE. LIMITED -> Tencent) FirewallRules: [{98CC29D6-F84C-4C20-96AB-3D8F0F35D08A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{DBDF5717-A028-4A48-A6CB-61394766185D}] => (Allow) LPort=32683 FirewallRules: [{2F63A595-D346-4BA1-B5FD-94AFC6319725}] => (Allow) LPort=33683 FirewallRules: [{28CCF235-1ED2-43AE-8648-89C40696C4B9}] => (Allow) LPort=26822 ==================== Punkty Przywracania systemu ========================= 28-06-2025 22:17:16 Installed AMD_Chipset_Drivers. ==================== Wadliwe urządzenia w Menedżerze urządzeń ============ Name: TAP-Windows Adapter V9 Description: TAP-Windows Adapter V9 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TAP-Windows Provider V9 Service: tap0901 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Błędy w Dzienniku zdarzeń: ======================== Dziennik Aplikacja: ================== Error: (06/30/2025 09:42:52 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: ZARZĄDZANIE NT) Description: System Windows nie może załadować biblioteki DLL rozszerzalnego licznika „C:\WINDOWS\system32\sysmain.dll” (kod błędu systemu Win32: 126). Error: (06/29/2025 12:30:45 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-BA5V5FP) Description: Nazwa aplikacji powodującej błąd: tbs_browser.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x676e6923 Nazwa modułu powodującego błąd: qbcore.dll, wersja: 94.0.80.81, sygnatura czasowa: 0x615e3a26 Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x0000000002f702f4 Identyfikator procesu błędu: 0x3f48 Czas uruchomienia aplikacji powodującej błąd: 0x1dbe8e0de947ee2 Faulting ścieżka aplikacji: C:\Program Files (x86)\Steam\steamapps\common\Delta Force\Launcher\Service\tbs_browser.exe Faulting ścieżka modułu: C:\Program Files (x86)\Steam\steamapps\common\Delta Force\Launcher\Service\qbcore.dll Report Id: 0bf22151-9c96-44e1-b906-20f4abd629f2 Faulting pełna nazwa pakietu: Faulting identyfikator aplikacji względnej dla pakietu: Error: (06/29/2025 11:03:56 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: ZARZĄDZANIE NT) Description: System Windows nie może załadować biblioteki DLL rozszerzalnego licznika „C:\WINDOWS\system32\sysmain.dll” (kod błędu systemu Win32: 126). Error: (06/29/2025 12:40:04 AM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-BA5V5FP) Description: Nazwa aplikacji powodującej błąd: tbs_browser.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x676e6923 Nazwa modułu powodującego błąd: qbcore.dll, wersja: 94.0.80.81, sygnatura czasowa: 0x615e3a26 Kod wyjątku: 0x80000003 Przesunięcie błędu: 0x0000000002f702f4 Identyfikator procesu błędu: 0x1f78 Czas uruchomienia aplikacji powodującej błąd: 0x1dbe87d96692d85 Faulting ścieżka aplikacji: C:\Program Files (x86)\Steam\steamapps\common\Delta Force\Launcher\Service\tbs_browser.exe Faulting ścieżka modułu: C:\Program Files (x86)\Steam\steamapps\common\Delta Force\Launcher\Service\qbcore.dll Report Id: 63ecd58d-9f8c-4278-85ea-2af2935ef556 Faulting pełna nazwa pakietu: Faulting identyfikator aplikacji względnej dla pakietu: Error: (06/28/2025 05:07:00 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-BA5V5FP) Description: Nazwa aplikacji powodującej błąd: tlou-ii.exe, wersja: 1.0.10402.1014, sygnatura czasowa: 0x00000000 Nazwa modułu powodującego błąd: tlou-ii.exe, wersja: 1.0.10402.1014, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00000000019c5940 Identyfikator procesu błędu: 0x32c4 Czas uruchomienia aplikacji powodującej błąd: 0x1dbe827e3413011 Faulting ścieżka aplikacji: E:\The Last of Us Part II Remastered\tlou-ii.exe Faulting ścieżka modułu: E:\The Last of Us Part II Remastered\tlou-ii.exe Report Id: f3519019-5923-4130-8132-2584f2f9e632 Faulting pełna nazwa pakietu: Faulting identyfikator aplikacji względnej dla pakietu: Error: (06/28/2025 05:06:52 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-BA5V5FP) Description: Nazwa aplikacji powodującej błąd: crs-video.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x67a150be Nazwa modułu powodującego błąd: crs-video.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x67a150be Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000007053 Identyfikator procesu błędu: 0x1d90 Czas uruchomienia aplikacji powodującej błąd: 0x1dbe827e3aa5b2b Faulting ścieżka aplikacji: E:\The Last of Us Part II Remastered\crs-video.exe Faulting ścieżka modułu: E:\The Last of Us Part II Remastered\crs-video.exe Report Id: 75e4a923-8f46-44e7-b29f-23c5c1846d53 Faulting pełna nazwa pakietu: Faulting identyfikator aplikacji względnej dla pakietu: Error: (06/28/2025 02:25:58 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-BA5V5FP) Description: Nazwa aplikacji powodującej błąd: tlou-ii.exe, wersja: 1.0.10402.1014, sygnatura czasowa: 0x00000000 Nazwa modułu powodującego błąd: tlou-ii.exe, wersja: 1.0.10402.1014, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x000000000128dd09 Identyfikator procesu błędu: 0x439c Czas uruchomienia aplikacji powodującej błąd: 0x1dbe8272d58f20e Faulting ścieżka aplikacji: E:\The Last of Us Part II Remastered\tlou-ii.exe Faulting ścieżka modułu: E:\The Last of Us Part II Remastered\tlou-ii.exe Report Id: 39e38983-365b-4f75-95f3-c1df953742e1 Faulting pełna nazwa pakietu: Faulting identyfikator aplikacji względnej dla pakietu: Error: (06/28/2025 02:25:58 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-BA5V5FP) Description: Nazwa aplikacji powodującej błąd: crs-video.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x67a150be Nazwa modułu powodującego błąd: crs-video.exe, wersja: 0.0.0.0, sygnatura czasowa: 0x67a150be Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x0000000000007053 Identyfikator procesu błędu: 0x3fb4 Czas uruchomienia aplikacji powodującej błąd: 0x1dbe8272de9bed4 Faulting ścieżka aplikacji: E:\The Last of Us Part II Remastered\crs-video.exe Faulting ścieżka modułu: E:\The Last of Us Part II Remastered\crs-video.exe Report Id: 98630ca6-015d-4820-ad57-11bfe85dc902 Faulting pełna nazwa pakietu: Faulting identyfikator aplikacji względnej dla pakietu: Dziennik System: ============= Error: (07/01/2025 03:49:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Usługa Google Update (gupdate) z powodu następującego błędu: Usługa nie odpowiada na sygnał uruchomienia lub sygnał sterujący w oczekiwanym czasie. Error: (07/01/2025 03:49:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Usługa Google Update (gupdate). Error: (07/01/2025 03:47:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa GameInput Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 6. Error: (07/01/2025 03:47:25 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa GameInput Service zakończyła działanie; wystąpił następujący błąd: Plik złożony GameInput Service został utworzony za pomocą nowszej wersji magazynu. Error: (07/01/2025 03:47:25 PM) (Source: Microsoft-Windows-Windows Firewall With Advanced Security) (EventID: 2042) (User: ZARZĄDZANIE NT) Description: 18-2147024662 Error: (07/01/2025 03:47:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa GameInput Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 5. W przeciągu 1000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (07/01/2025 03:47:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Usługa GameInput Service zakończyła działanie; wystąpił następujący błąd: Plik złożony GameInput Service został utworzony za pomocą nowszej wersji magazynu. Error: (07/01/2025 03:47:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa GameInput Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 4. W przeciągu 1000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Windows Defender: ================ Date: 2025-06-30 06:42:01 Description: Program antywirusowy Microsoft Defender şĉдή ђдś ъëĕή şтõρρêđ ьêƒóгє ċοмрŀзťįǿй.%ň %τŚ¢ǻⁿ ΊĐ:%ь{5A1EAFFA-F138-40BA-8520-3B57A4874365}%л %ťŚċªņ Ŧγφė:%ъNarzędzia chroniące przed złośliwym oprogramowaniem%π %ŧЅçап Ρäřãмзτёяš:%вSzybkie skanowanie%й %тÛşéґ:%ъZARZĄDZANIE NT\SYSTEM%ή %ŧŚŧóφ Яëàšόⁿ:%вΓΡČ ćōňйэĉŧïőπ ŕϋŋðőωή Date: 2025-06-27 06:44:09 Description: Program antywirusowy Microsoft Defender şĉдή ђдś ъëĕή şтõρρêđ ьêƒóгє ċοмрŀзťįǿй.%ň %τŚ¢ǻⁿ ΊĐ:%ь{AEF4A999-D54C-4237-8087-0F08F2EB0283}%л %ťŚċªņ Ŧγφė:%ъNarzędzia chroniące przed złośliwym oprogramowaniem%π %ŧЅçап Ρäřãмзτёяš:%вSzybkie skanowanie%й %тÛşéґ:%ъZARZĄDZANIE NT\SYSTEM%ή %ŧŚŧóφ Яëàšόⁿ:%вΓΡČ ćōňйэĉŧïőπ ŕϋŋðőωή Date: 2025-06-26 06:44:40 Description: Program antywirusowy Microsoft Defender şĉдή ђдś ъëĕή şтõρρêđ ьêƒóгє ċοмрŀзťįǿй.%ň %τŚ¢ǻⁿ ΊĐ:%ь{DA1E9980-A01D-41C7-B510-A3AA27CAC43B}%л %ťŚċªņ Ŧγφė:%ъNarzędzia chroniące przed złośliwym oprogramowaniem%π %ŧЅçап Ρäřãмзτёяš:%вSzybkie skanowanie%й %тÛşéґ:%ъZARZĄDZANIE NT\SYSTEM%ή %ŧŚŧóφ Яëàšόⁿ:%вΓΡČ ćōňйэĉŧïőπ ŕϋŋðőωή Date: 2025-06-25 06:47:40 Description: Program antywirusowy Microsoft Defender şĉдή ђдś ъëĕή şтõρρêđ ьêƒóгє ċοмрŀзťįǿй.%ň %τŚ¢ǻⁿ ΊĐ:%ь{3D2D3BF0-0E09-41A9-806E-0979E1CCC619}%л %ťŚċªņ Ŧγφė:%ъNarzędzia chroniące przed złośliwym oprogramowaniem%π %ŧЅçап Ρäřãмзτёяš:%вSzybkie skanowanie%й %тÛşéґ:%ъZARZĄDZANIE NT\SYSTEM%ή %ŧŚŧóφ Яëàšόⁿ:%вΓΡČ ćōňйэĉŧïőπ ŕϋŋðőωή Date: 2025-06-24 06:44:35 Description: Program antywirusowy Microsoft Defender şĉдή ђдś ъëĕή şтõρρêđ ьêƒóгє ċοмрŀзťįǿй.%ň %τŚ¢ǻⁿ ΊĐ:%ь{7762A13D-68B1-44B0-9073-D5675E592E10}%л %ťŚċªņ Ŧγφė:%ъNarzędzia chroniące przed złośliwym oprogramowaniem%π %ŧЅçап Ρäřãмзτёяš:%вSzybkie skanowanie%й %тÛşéґ:%ъZARZĄDZANIE NT\SYSTEM%ή %ŧŚŧóφ Яëàšόⁿ:%вΓΡČ ćōňйэĉŧïőπ ŕϋŋðőωή Event[0] Date: 2025-02-01 16:24:05 Description: Produkt Program antywirusowy Microsoft Defender napotkał błąd podczas próby aktualizacji analizy zabezpieczeń. Nowa wersja analizy zabezpieczeń: Poprzednia wersja analizy zabezpieczeń: 1.421.1630.0 Źródło aktualizacji: Serwer usługi Microsoft Update Typ analizy zabezpieczeń: Oprogramowanie antywirusowe Typ aktualizacji: Pełne Użytkownik: ZARZĄDZANIE NT\SYSTEM Bieżąca wersja aparatu: Poprzednia wersja aparatu: 1.1.24090.11 Kod błędu: 0x8007043c Opis błędu: Tej usługi nie można uruchomić w trybie awaryjnym Date: 2025-02-01 16:14:01 Description: Agent ochrony w czasie rzeczywistym produktu Program antywirusowy Microsoft Defender wykrył błąd i jego uruchomienie nie powiodło się. Funkcja: Przy dostępie Kod błędu: 0x8007043c Opis błędu: Tej usługi nie można uruchomić w trybie awaryjnym Przyczyna: Analiza zabezpieczeń dla oprogramowania chroniącego przed złośliwym kodem przestała działać z nieznanej przyczyny. W niektórych przypadkach problem można rozwiązać, uruchamiając ponownie usługę. Date: 2025-01-24 15:29:31 Description: Produkt Program antywirusowy Microsoft Defender napotkał błąd podczas próby aktualizacji analizy zabezpieczeń. Nowa wersja analizy zabezpieczeń: Poprzednia wersja analizy zabezpieczeń: 1.421.1501.0 Źródło aktualizacji: Serwer usługi Microsoft Update Typ analizy zabezpieczeń: Oprogramowanie antywirusowe Typ aktualizacji: Pełne Użytkownik: ZARZĄDZANIE NT\SYSTEM Bieżąca wersja aparatu: Poprzednia wersja aparatu: 1.1.24090.11 Kod błędu: 0x8024402c Opis błędu: Podczas sprawdzania aktualizacji wystąpił nieoczekiwany problem. Aby uzyskać informacje na temat instalowania aktualizacji i rozwiązywania problemów z nimi, zobacz Pomoc i obsługę techniczną. Date: 2025-01-13 07:28:29 Description: Produkt Program antywirusowy Microsoft Defender napotkał błąd podczas próby aktualizacji analizy zabezpieczeń i podejmie próbę powrotu do poprzedniej wersji. Analiza zabezpieczeń objęta próbą: Bieżące Kod błędu: 0x80070003 Opis błędu: System nie może odnaleźć określonej ścieżki. Wersja analizy zabezpieczeń: 0.0.0.0;0.0.0.0 Wersja aparatu: 0.0.0.0 Date: 2024-12-22 18:48:17 Description: Agent ochrony w czasie rzeczywistym produktu Program antywirusowy Microsoft Defender wykrył błąd i jego uruchomienie nie powiodło się. Funkcja: Przy dostępie Kod błędu: 0x8007043c Opis błędu: Tej usługi nie można uruchomić w trybie awaryjnym Przyczyna: Analiza zabezpieczeń dla oprogramowania chroniącego przed złośliwym kodem przestała działać z nieznanej przyczyny. W niektórych przypadkach problem można rozwiązać, uruchamiając ponownie usługę. CodeIntegrity: =============== Date: 2025-07-01 15:49:27 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements. Date: 2025-07-01 15:49:25 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements. Date: 2025-07-01 15:48:57 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. ==================== Statystyki pamięci =========================== BIOS: American Megatrends International, LLC. A.I5 09/06/2024 Płyta główna: Micro-Star International Co., Ltd B450-A PRO (MS-7B86) Procesor: AMD Ryzen 7 5700X3D 8-Core Processor Procent pamięci w użyciu: 34% Całkowita pamięć fizyczna: 32693.56 MB Dostępna pamięć fizyczna: 21264.85 MB Całkowita pamięć wirtualna: 34741.56 MB Dostępna pamięć wirtualna: 20265.21 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:464.5 GB) (Free:27.18 GB) (Model: CT500MX500SSD1) NTFS Drive e: (DATA) (Fixed) (Total:476.94 GB) (Free:50.05 GB) (Model: INTEL SSDPEKNU512GZ) NTFS \\?\Volume{5d5eec61-2b57-4be3-88d2-b2853ce2e20e}\ (Odzyskiwanie) (Fixed) (Total:0.49 GB) (Free:0.47 GB) NTFS \\?\Volume{402bb611-040b-418d-8f95-478c7392074a}\ () (Fixed) (Total:0.66 GB) (Free:0.07 GB) NTFS \\?\Volume{504254ce-573f-4594-a9f2-5aed12980651}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32 ==================== MBR & Tablica partycji ==================== ========================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 7CE51699) Partition: GPT. ========================================================== Disk: 1 (Size: 476.9 GB) (Disk ID: 50E5A6A3) Partition: GPT. ==================== Koniec Addition.txt =======================