Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 08-10-2017 Uruchomiony przez Wojtek (08-10-2017 22:07:22) Run:1 Uruchomiony z D:\Pobrane\FRST Załadowane profile: Wojtek (Dostępne profile: Wojtek & Ewa) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: CustomCLSID: HKU\S-1-5-21-1415446754-3198373632-3723623690-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {187DF4CA-9468-D082-9C64-0CE985889A47} => Brak pliku CustomCLSID: HKU\S-1-5-21-1415446754-3198373632-3723623690-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {58AD1D9A-9468-D082-CC8D-DCA985889A47} => Brak pliku CustomCLSID: HKU\S-1-5-21-1415446754-3198373632-3723623690-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Wojtek\AppData\Local\Citrix\GoToMeeting\4628\G2MOutlookAddin64.dll => Brak pliku Task: {243C128E-D8C6-487A-AF09-0400697FAF5A} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Brak pliku <==== UWAGA Task: {0A4A9412-7651-4316-BF96-B0D362FC846A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA Task: {326470D3-5250-49CB-892C-024019B3871C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA Task: {3ACD5F94-48AD-4260-B3E9-2E85B704FF63} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA Task: {4C393FDD-3743-4534-A3FA-A0C50C986FF2} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA Task: {51C53C5F-6FD1-49DB-83CC-64D227A21036} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA Task: {95EB6F3C-F0A2-4AE4-82C6-21B0733FD0FB} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA Task: {9F997FC8-675D-44B4-A7AF-97EC364EE683} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA Task: {AEF9A10D-2D70-4B09-B156-64715931E4E0} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA Task: {BAED3869-D434-4AF7-9B78-4AEFCEC0C2D2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA Task: {C7D841D4-012A-435C-BAB8-BE2F9BC7BCF9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA Task: {FFFE8971-0FFF-4623-9505-236BE13BDDF1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 0 HKLM\...\Policies\Explorer: [NoInstrumentation] 1 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [NoPreviewPane] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [HideSCANetwork] 0 HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\...\Policies\Explorer: [HideSCAVolume] 0 HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <==== UWAGA BootExecute: autocheck autochk * sdnclean64.exe GroupPolicyUsers\S-1-5-21-1415446754-3198373632-3723623690-1002\User: Ograniczenia <==== UWAGA HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = C:\Users\Julia i Pati.Wojtek-laptop\AppData\Roaming\ClassicShell\Pinned\startscreen.lnk C:\Users\Wojtek\Desktop\Media Player Classic (x64).lnk C:\Users\Wojtek\Desktop\S Note.lnk DeleteKey: HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains IE Session Restore: HKU\S-1-5-21-1415446754-3198373632-3723623690-1001 -> [funkcja włączona] CMD: dir /a "C:\WINDOWS\system32\Drivers\etc" CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Admin\AppData\Local CMD: dir /a C:\Users\Admin\AppData\LocalLow CMD: dir /a C:\Users\Admin\AppData\Roaming Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} Hosts: EmptyTemp: ̩ ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKU\S-1-5-21-1415446754-3198373632-3723623690-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B} => klucz pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850} => klucz pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{243C128E-D8C6-487A-AF09-0400697FAF5A} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{243C128E-D8C6-487A-AF09-0400697FAF5A} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0A4A9412-7651-4316-BF96-B0D362FC846A} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0A4A9412-7651-4316-BF96-B0D362FC846A} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{326470D3-5250-49CB-892C-024019B3871C} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{326470D3-5250-49CB-892C-024019B3871C} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3ACD5F94-48AD-4260-B3E9-2E85B704FF63} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3ACD5F94-48AD-4260-B3E9-2E85B704FF63} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4C393FDD-3743-4534-A3FA-A0C50C986FF2} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C393FDD-3743-4534-A3FA-A0C50C986FF2} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{51C53C5F-6FD1-49DB-83CC-64D227A21036} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51C53C5F-6FD1-49DB-83CC-64D227A21036} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{95EB6F3C-F0A2-4AE4-82C6-21B0733FD0FB} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95EB6F3C-F0A2-4AE4-82C6-21B0733FD0FB} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F997FC8-675D-44B4-A7AF-97EC364EE683} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F997FC8-675D-44B4-A7AF-97EC364EE683} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AEF9A10D-2D70-4B09-B156-64715931E4E0} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEF9A10D-2D70-4B09-B156-64715931E4E0} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BAED3869-D434-4AF7-9B78-4AEFCEC0C2D2} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BAED3869-D434-4AF7-9B78-4AEFCEC0C2D2} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C7D841D4-012A-435C-BAB8-BE2F9BC7BCF9} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7D841D4-012A-435C-BAB8-BE2F9BC7BCF9} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FFFE8971-0FFF-4623-9505-236BE13BDDF1} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFFE8971-0FFF-4623-9505-236BE13BDDF1} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => klucz pomyślnie usunięto HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => klucz pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRecentDocsNetHood => Wartość pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation => Wartość pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoPreviewPane => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCANetwork => Wartość pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAVolume => Wartość pomyślnie usunięto HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Wartość pomyślnie przywrócono C:\WINDOWS\system32\GroupPolicyUsers\S-1-5-21-1415446754-3198373632-3723623690-1002\User => pomyślnie przeniesiono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono C:\Users\Julia i Pati.Wojtek-laptop\AppData\Roaming\ClassicShell\Pinned\startscreen.lnk => pomyślnie przeniesiono C:\Users\Wojtek\Desktop\Media Player Classic (x64).lnk => pomyślnie przeniesiono C:\Users\Wojtek\Desktop\S Note.lnk => pomyślnie przeniesiono HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains => klucz pomyślnie usunięto HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains => klucz pomyślnie usunięto HKU\S-1-5-21-1415446754-3198373632-3723623690-1001\Software\Microsoft\Internet Explorer\ContinuousBrowsing => klucz pomyślnie usunięto ========= dir /a "C:\WINDOWS\system32\Drivers\etc" ========= Volume in drive C is System Volume Serial Number is BC6E-2E4D Directory of C:\WINDOWS\system32\Drivers\etc 2017-10-02 22:42