Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 10-11-2025 Uruchomiony przez Gieni (11-11-2025 11:12:12) Run:1 Uruchomiony z C:\Users\Gieni\Downloads Załadowane profile: Gieni & WsiAccount Tryb startu: Normal ============================================== fixlist - zawartość: ***************** Start:: CreateRestorePoint: ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> Brak pliku C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.com.lnk SearchScopes: HKLM -> {CFB729F5-1603-4836-B77F-6F335E33FA9E} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5FcPortugueseode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {CFB729F5-1603-4836-B77F-6F335E33FA9E} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5FcPortugueseode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-2154322142-1083756757-1331411065-1001 -> {CFB729F5-1603-4836-B77F-6F335E33FA9E} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5FcPortugueseode=qs&index=aps&field-keywords={searchTerms} 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com HKU\S-1-5-18\...\Policies\Explorer: [SettingsPageVisibility] hide:appsfeatures HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-A658-80934ECCD7CB}] -> C:\Program Files (x86)\Internet Explorer\ScreenConnect.WindowsCredentialProvider.dll [2024-07-23] (Connectwise, LLC -> ) <==== UWAGA HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-D8A7-1F27744C1734}] -> C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.WindowsCredentialProvider.dll [2025-04-08] (Connectwise, LLC -> ) <==== UWAGA Lsa: [Authentication Packages] msv1_0 C:\Program Files (x86)\Internet Explorer\ScreenConnect.WindowsAuthenticationPackage.dll C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.WindowsAuthenticationPackage.dll Task: {CCF86EC2-0ACB-4FC9-BBDB-EC112F611148} - System32\Tasks\DCAgentUpdater => C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentupgrader.exe Task (Brak pliku) Task: {15A63A06-7032-4577-8B74-4A845BB4635B} - System32\Tasks\Meta\Messenger-SL-Helper-S-1-5-21-2154322142-1083756757-1331411065-1001 => C:\Users\Gieni\AppData\Local\Programs\Messenger\MessengerHelper.exe --lassie (Brak pliku) Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (Brak pliku) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Brak pliku) HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA R2 ScreenConnect Client (f54e48458ed500f5); C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.ClientService.exe [95512 2025-04-08] (Connectwise, LLC -> ) <==== UWAGA R2 ManRas; "C:\Program Files (x86)\Internet Explorer\ScreenConnect.ClientService.exe" "?e=Access&y=Guest&h=aszen.org&p=8041&s=381043c7-dc49-4e9a-8f98-4b37219f7460&k=BgIAAACkAABSU0ExAAgAAAEAAQA1CqNC3EdLM8HKZI6wSby1N31VyJTLn%2b4fSspm7dELQ1CuRC4uJVTMlYHxFkgGT%2bbBCsbgBUEYcrFTiE4%2bdqQivCSMibxFeLcxptl0fFdRv7CLyGlx8FDziuc5M8FriAqqv310GJr7l7Em%2fCKiH5oaTnbuKGIcYNjpsnuKd2sjN3x6MyjNvG9TMVn463SlI6b%2fjCgG4AagcQzczrxr13CF%2f%2bvWlv6d1SBmQQI5uFLYNyZKWow2kJnNNVC1uvpHfg0m%2bBXDW7Yf7pnTg07et6yCOjCiKkpRsTuUSWg4qHj74UsYzNw5%2fgt0xf8a8j3L4nmM4h%2bclaTKxOGUPhjEH3HD&v=AQAAANCMnd8BFdERjHoAwE%2fCl%2bsBAAAADSS9qw3JQkS2CWSdx%2fAbxAAAAAACAAAAAAAQZgAAAAEAACAAAACdlRJ6GA8iSnqbzgM9w%2bz6cF5OmuGXC8swaYuEkUHYLwAAAAAOgAAAAAIAACAAAAB5Xr5HqL2V%2fn9N40J2Str8L3QIBN38KCU%2bT1Z10H3wkqAEAAApccqlqYrej8X6pP5vTxwgBpGgleGNlw2MfeEQvi6zrwkmk4n8YnnjzMbe9YhddCO08fnpH6QMCoWnBvA9%2bplyocykoHzN0zKm8dO7AQI87hlyJwnW%2bLTw5CKCXJY%2fU1iKSkCyrc5lhLnMFQj1SuwxmQ5rr2mNcgPSvFwVpIDKCnqoxaqPhJyJTsO8EmBjKLkyNXGI3l%2bztv7pHJm8EYBRTTszAEDSv84i%2f5V7ezSUP5SpzE5jqDz6slSNaCy%2bszdGaC9bxYM%2f%2bl%2bunjfxzowKezLvRpGbXl9DmgQVy47YX4M71chOuqhQFT99KxuyvvswZAQ7Rof8TqMXajMbuaT6HWdtMGE1ONtJKBymKnw8WoBOPK%2b1BFLKUpmGat7yGoh0JlX6b9lIYoO%2bu7e6WfgdrKrori9VCSfB36EBHdQEYw50DNSaGF6w0g6ha%2bVkxxn19e3RSDhfmpRQP1EXNB8JML%2ftR45tdUt8sfn%2bkal2m69rdS2JYsHFExSi8J948pL6dEqfzDVCUL%2bheX2ZHVzRNRm9%2fkDvW%2fM81jMsEHIibzA8X3mGPLYOg22LV2EQR2Mo7yQjUifKuv1CeT9JrxwIn44p2n1wokbGW1lcxhz%2fZXPLvUS3l%2bFFhXP9zjN7IIKgXaJVkycWG7Ex3RNwJriQU9%2bxAdrN4z0BvEGzJWIpvVp7%2blwKbmcWOIxbRlw2F5sh1x28r58aF%2bxe%2bZusT%2fjHRfdJvjN0O%2btjc32Bb9BKmrJRP72yphIIJ%2bBI2iWbOLoY89M3n0OxshLijE3%2bmmhV3aNxDAAWokqpcwJHnGJYxr%2bpSXReBMtegsB9iZmp9U%2bfZEkmV7y32BUFJU%2bj7zCfVEMJtXRjlkfh2kbArlJPMb%2fsQmjamvrF6GqBQkn%2bmio5p2KCmxw61O1us6wtxjxAqDLlrUOwjJOfYdZAzkapY0tKEvxigk41whGxaspQfpWp9qklswOYGbKrvgZTI2ymNRT4rtaapYi2mCQNZReGopb6T7vzcai45Wp%2bI1b3mcf8Jkuqh2ZkRrFNyncyA9RUiSiHU6zWhYEkVOXCOfaFcF8ewYFvFvgdkF9I5VLhtTdOs%2bRV2SLniuPA1iWaH9UG5pE6v4DSrb%2b3MKPGP4BFRdYcxW%2bZhAyXe24m1n%2bfPZ4dx0iJfFjzgZZ%2bhWbPAJiBXMn10u2wgZnDXVGSVVaIPhQYpwaMP67a6tO0HrWykK1t%2fWtRMsxksf7MM3vrSbGrXo6smdsffiMa9sFZs0bp4pDW4HiAcqh4BnihKdMwUzOub6km85Fz5JBESdQ19S1Wlwnbib1AD6tTkfIzRbwya%2bE3htUvKiQdFElQ4pqfIM5tKD%2bCxRwxAcqzVBsgz7r0RIuIzxmjNqv1t%2fG0b%2fKFUL%2bptqZ0gVyt7PayQ3x%2bfa2IO3i5AoY%2bOhJbRv0lpogIQbevFCjzOeSEhYs5crmYoeQAdsHWmcwoL74UpgPRRxfCzrDz43qSu0%2fDbc5zZkven8viooxblqByEoGCGC5wNUdskNZ7TxS5rACNdjusekTwv0GKyjZaeMbXC%2bYLkpolTAdtewDLn7f%2fjrztmlCYMEAAAACRP3lBTW4%2ffOG%2bf5Zz82vtZ0i37Cfi7RO9SWnScl%2fsv0Qc3vRhnf3uInQW3MU5VrwEj4z4TZ%2bmpPlMXxorAxs%2b" [X] <==== UWAGA C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.com.lnk EmptyTemp: End:: ***************** Punkt przywracania został pomyślnie utworzony. HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ACE => pomyślnie usunięto HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} => pomyślnie usunięto C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.com.lnk => pomyślnie przeniesiono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFB729F5-1603-4836-B77F-6F335E33FA9E} => pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{CFB729F5-1603-4836-B77F-6F335E33FA9E} => pomyślnie usunięto HKU\S-1-5-21-2154322142-1083756757-1331411065-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFB729F5-1603-4836-B77F-6F335E33FA9E} => pomyślnie usunięto 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com => Błąd: Nie znaleziono automatycznej naprawy dla tego wejścia. "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\SettingsPageVisibility" => pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{6FF59A85-BC37-4CD4-A658-80934ECCD7CB} => pomyślnie usunięto HKLM\Software\Classes\CLSID\{6FF59A85-BC37-4CD4-A658-80934ECCD7CB} => pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{6FF59A85-BC37-4CD4-D8A7-1F27744C1734} => pomyślnie usunięto HKLM\Software\Classes\CLSID\{6FF59A85-BC37-4CD4-D8A7-1F27744C1734} => pomyślnie usunięto HKLM\System\CurrentControlSet\Control\Lsa\\"Authentication Packages"="msv1_0" => Wartość pomyślnie przywrócono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCF86EC2-0ACB-4FC9-BBDB-EC112F611148}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCF86EC2-0ACB-4FC9-BBDB-EC112F611148}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\DCAgentUpdater => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DCAgentUpdater" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15A63A06-7032-4577-8B74-4A845BB4635B}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15A63A06-7032-4577-8B74-4A845BB4635B}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Meta\Messenger-SL-Helper-S-1-5-21-2154322142-1083756757-1331411065-1001 => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Meta\Messenger-SL-Helper-S-1-5-21-2154322142-1083756757-1331411065-1001" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => pomyślnie usunięto HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer => pomyślnie usunięto ScreenConnect Client (f54e48458ed500f5) => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\ScreenConnect Client (f54e48458ed500f5) => pomyślnie usunięto ScreenConnect Client (f54e48458ed500f5) => serwis pomyślnie usunięto ManRas => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\ManRas => pomyślnie usunięto ManRas => serwis pomyślnie usunięto "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.com.lnk" => nie znaleziono =========== EmptyTemp: ========== FlushDNS => ukończone BITS transfer queue => 1048576 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 29681924 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 17174539 B Edge => 0 B Chrome => 854597452 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 288892 B Gieni => 89843473 B WsiAccount => 89843473 B RecycleBin => 3158151 B EmptyTemp: => 1 GB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 11:13:04 ====