Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-01-2023 Ran by [removed] (22-01-2023 14:43:19) Running from C:\Users\[removed]\Desktop Microsoft Windows 10 Home Version 22H2 19045.2486 (X64) (2022-10-28 13:33:42) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-2007841477-1455595398-3338308244-500 - Administrator - Disabled) danie (S-1-5-21-2007841477-1455595398-3338308244-1001 - Administrator - Enabled) => C:\Users\danie Gość (S-1-5-21-2007841477-1455595398-3338308244-501 - Limited - Disabled) Konto domyślne (S-1-5-21-2007841477-1455595398-3338308244-503 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-2007841477-1455595398-3338308244-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Premiere Pro 2022 (HKLM-x32\...\PPRO_22_5) (Version: 22.5 - Adobe Inc.) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.7 - Sereby Corporation) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Discord (HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Discord) (Version: 1.0.9007 - Discord Inc.) Epic Games Launcher (HKLM-x32\...\{264464DC-63A7-40C9-92C8-A3EB54AFD72C}) (Version: 1.3.51.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Epic Online Services (HKLM-x32\...\{19695986-25CE-41AC-9C6F-54794653EDBA}) (Version: 2.0.36.0 - Epic Games, Inc.) Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden League of Legends (HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc) Lightshot-5.5.0.7 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.7 - Skillbrains) Malwarebytes version 4.5.20.230 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.20.230 - Malwarebytes) Microsoft .NET 6.0 Templates 6.0.402 (x64) (HKLM\...\{DD0D888D-24A2-49BB-B920-B9AD24E383CF}) (Version: 24.7.52714 - Microsoft Corporation) Hidden Microsoft .NET AppHost Pack - 6.0.10 (x64) (HKLM\...\{15B69F1B-AABD-420A-B018-57694A8A68E9}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET AppHost Pack - 6.0.10 (x64_arm) (HKLM\...\{46E941B5-1E02-48F7-A7E4-89868C51EBA8}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET AppHost Pack - 6.0.10 (x64_arm64) (HKLM\...\{40E534C5-0392-417B-BF5C-2A751C85AEBB}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET AppHost Pack - 6.0.10 (x64_x86) (HKLM\...\{A85F3456-E80F-4A0F-B1C3-FDD74FA803E9}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM-x32\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM-x32\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM-x32\...\M979906) (Version: - ) Microsoft .NET Host - 6.0.10 (x64) (HKLM\...\{0222FFF1-57A3-48A6-9AD2-0D6B5D0172B3}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 6.0.10 (x64) (HKLM\...\{A93C4E12-1BAB-4CFB-ADBC-9CE0B93176FF}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 6.0.10 (x64) (HKLM\...\{A2A39CB9-677D-4299-8537-C00B99F3D4A4}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET SDK 6.0.402 (x64) (HKLM-x32\...\{fa68849d-84fd-4845-baa8-77851cb42a17}) (Version: 6.4.222.47626 - Microsoft Corporation) Microsoft .NET Standard Targeting Pack - 2.1.0 (x64) (HKLM\...\{A7036CFB-B403-4598-85FF-D397ABB88173}) (Version: 24.0.28113 - Microsoft Corporation) Hidden Microsoft .NET Targeting Pack - 6.0.10 (x64) (HKLM\...\{793CAC7F-F5AA-4CA4-927C-C27DB80EF0D5}) (Version: 48.43.48869 - Microsoft Corporation) Hidden Microsoft .NET Toolset 6.0.402 (x64) (HKLM\...\{6E998BA5-3FBF-4093-A766-6D2B1ED06BC2}) (Version: 24.5.52714 - Microsoft Corporation) Hidden Microsoft ASP.NET Core 6.0.10 Shared Framework (x64) (HKLM\...\{FE63330E-ED15-3B1D-B577-06106A457D1D}) (Version: 6.0.10.22476 - Microsoft Corporation) Hidden Microsoft ASP.NET Core 6.0.10 Targeting Pack (x64) (HKLM\...\{51257750-1F86-30F0-8D6D-AF6C74CC2EDB}) (Version: 6.0.10.22476 - Microsoft Corporation) Hidden Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 109.0.1518.61 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\OneDriveSetup.exe) (Version: 22.253.1204.0001 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{80F1AF52-7AC0-42A3-9AF0-689BFB271D1D}) (Version: 3.68.0.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.32.31332 (HKLM-x32\...\{3746f21b-c990-4045-bb33-1cf98cff7a68}) (Version: 14.32.31332.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31332 (HKLM-x32\...\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}) (Version: 14.32.31332.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.32.31332 (HKLM\...\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.32.31332 (HKLM\...\{3407B900-37F5-4CC2-B612-5CD5D580A163}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31332 (HKLM-x32\...\{8972AC25-452E-4FFE-945A-EB9E28C20322}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31332 (HKLM-x32\...\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}) (Version: 14.32.31332 - Microsoft Corporation) Hidden Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft Windows Desktop Runtime - 6.0.10 (x64) (HKLM\...\{3EC7701F-54F2-491D-AFD1-0395F465BC5A}) (Version: 48.43.48870 - Microsoft Corporation) Hidden Microsoft Windows Desktop Targeting Pack - 6.0.10 (x64) (HKLM\...\{B615B92C-E705-4016-AA1A-A024AC7037F8}) (Version: 48.43.48870 - Microsoft Corporation) Hidden Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft.NET.Sdk.Android.Manifest-6.0.300 (HKLM\...\{F4E591C2-810D-4D36-B4F9-DC55103019D1}) (Version: 128.75.16384 - Microsoft Corporation) Hidden Microsoft.NET.Sdk.iOS.Manifest-6.0.300 (HKLM\...\{BBA9C60D-75E7-44EE-922D-069AA85C8EC1}) (Version: 125.191.42208 - Microsoft Corporation) Hidden Microsoft.NET.Sdk.MacCatalyst.Manifest-6.0.300 (HKLM\...\{FEB76EC8-02F4-46E6-8031-BE403766D13A}) (Version: 125.191.42208 - Microsoft Corporation) Hidden Microsoft.NET.Sdk.macOS.Manifest-6.0.300 (HKLM\...\{F590F859-2F6A-4559-9D09-A8FC442AF16B}) (Version: 100.255.42208 - Microsoft Corporation) Hidden Microsoft.NET.Sdk.Maui.Manifest-6.0.300 (HKLM\...\{C2863251-07E7-44A0-B2F8-4C4E2AF08937}) (Version: 24.78.0 - Microsoft Corporation) Hidden Microsoft.NET.Sdk.tvOS.Manifest-6.0.300 (HKLM\...\{69B1631F-5F98-4C6C-B757-46B0ECC8EDBB}) (Version: 125.191.42208 - Microsoft Corporation) Hidden Microsoft.NET.Workload.Emscripten.Manifest (HKLM\...\{7CBF3451-2A94-4DFD-8355-6B97C5EABB26}) (Version: 48.27.39026 - Microsoft Corporation) Hidden Microsoft.NET.Workload.Mono.Toolchain.Manifest (HKLM\...\{DBB48387-294D-4179-81CB-B06A97F8CD8E}) (Version: 48.3.40665 - Microsoft Corporation) Hidden NVIDIA FrameView SDK 1.3.8107.31782123 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.3.8107.31782123 - NVIDIA Corporation) NVIDIA GeForce Experience 3.26.0.160 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.26.0.160 - NVIDIA Corporation) NVIDIA Oprogramowanie systemu PhysX 9.21.0713 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.21.0713 - NVIDIA Corporation) NVIDIA Sterownik graficzny 516.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 516.94 - NVIDIA Corporation) Opera GX Stable 94.0.4606.69 (HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Opera GX 94.0.4606.69) (Version: 94.0.4606.69 - Opera Software) Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9205.1 - Realtek Semiconductor Corp.) Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.67.1178 - Rockstar Games) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.1.6.5 - Rockstar Games) Spotify (HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\Spotify) (Version: 1.2.3.1115.gd61a8f5c - Spotify AB) Sprawdzanie kondycji komputera z systemem Windows (HKLM\...\{41E85393-7ED3-4C54-AC25-51F8CDF39CDF}) (Version: 3.6.2204.08001 - Microsoft Corporation) Środowisko uruchomieniowe Microsoft Edge WebView2 (HKLM-x32\...\Microsoft EdgeWebView) (Version: 109.0.1518.52 - Microsoft Corporation) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) WinRAR 6.11 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH) Packages: ========= NVIDIA Control Panel -> C:\Program Files\WindowsApps\nvidiacorp.nvidiacontrolpanel_8.1.963.0_x64__56jybvy8sckqj [2022-10-28] (NVIDIA Corp.) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.22.240.0_x64__dt26b99r8h8gj [2022-10-28] (Realtek Semiconductor Corp) Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.15.12020.0_x64__8wekyb3d8bbwe [2023-01-01] (Microsoft Studios) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\rarext.dll [2022-03-14] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\rarext32.dll [2022-03-14] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => D:\malwarebytes\mbshlext.dll [2022-12-11] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_ee20464bb4ac57f4\nvshext.dll [2022-08-23] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => D:\malwarebytes\mbshlext.dll [2022-12-11] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => D:\rarext.dll [2022-03-14] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => D:\rarext32.dll [2022-03-14] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2022-10-28 19:49 - 2022-11-10 07:19 - 134859776 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libcef.dll 2022-10-28 19:49 - 2022-11-07 11:17 - 000387072 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libegl.dll 2022-10-28 19:49 - 2022-11-07 11:17 - 008052736 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libglesv2.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 000331776 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\glew32.dll 2022-12-26 20:28 - 2022-12-26 20:20 - 008223760 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\hackpro.dll 2022-12-26 20:28 - 2022-10-31 19:14 - 001738240 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\hackproldr.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 001761280 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\libcocos2d.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 000287232 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\libExtensions.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 000525312 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\libtiff.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 000539648 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\sqlite3.dll 2022-12-26 20:28 - 2022-10-31 19:14 - 000092672 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\XINPUT9_1_0.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 000077824 _____ () [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\zlib1.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 001466880 _____ (Firelight Technologies) [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\fmod.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 000077879 _____ (Open Source Software community project) [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\pthreadVCE2.dll 2022-10-28 19:49 - 2022-11-07 11:17 - 000992256 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\chrome_elf.dll 2022-12-26 20:02 - 2022-12-26 20:02 - 001185792 _____ (The cURL library, hxxp://curl.haxx.se/) [File not signed] D:\SteamLibrary\steamapps\common\Geometry Dash\libcurl.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [6966] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AutorunsDisabled => "AlternateShell"="cmd.exe" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-12-07 10:14 - 2019-12-07 10:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.31.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess" HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_E0359248083FDB44B7852C7D3585D0D2" HKU\S-1-5-21-2007841477-1455595398-3338308244-1001\...\StartupApproved\Run: => "EpicGamesLauncher" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{F8C6818C-6428-4153-83C1-C92FB2FA8A29}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{ECED1EEC-2BF6-47CE-8F9C-2E08F53AF69A}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{EB47B4E5-829E-4213-AA3C-F8AC278CC42D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{1170A654-6DB7-43D6-B783-23E8C4A03929}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{82AEDC21-767B-47A8-8936-A642D4D0B47F}] => (Allow) D:\SteamLibrary\steamapps\common\SCP Secret Laboratory\SCPSL.exe (Hubert Moszka Northwood -> ) FirewallRules: [{E984723A-A47E-4019-B1EB-557E2BC8C1B5}] => (Allow) D:\SteamLibrary\steamapps\common\SCP Secret Laboratory\SCPSL.exe (Hubert Moszka Northwood -> ) FirewallRules: [{0CD16A01-1C77-4D5F-90D6-02F8F9C537FF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{DEB2E559-98BA-4081-B99A-42EDA4FD96A1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{09674388-5280-44E3-BC22-568DA309ED77}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{46017083-41D1-4824-8CAD-4E9D7D440F9D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.92.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{D7A09127-4624-40D9-9D15-C53065354A5F}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\109.0.1518.52\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{E84340D2-F000-4AC2-80A1-8FF02C0A5BDE}] => (Allow) D:\SteamLibrary\steamapps\common\Devour\DEVOUR.exe () [File not signed] FirewallRules: [{C9904603-E2B1-44FC-BED5-98BEA8B0A509}] => (Allow) D:\SteamLibrary\steamapps\common\Devour\DEVOUR.exe () [File not signed] FirewallRules: [{F2EBD576-01DD-4D27-9E2E-216F63985C32}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin64\dontstarve_steam_x64.exe () [File not signed] FirewallRules: [{3B26E679-255C-4619-BD9A-65AC6F0EFC65}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin64\dontstarve_steam_x64.exe () [File not signed] FirewallRules: [{3D1B572A-5BA9-4142-B428-2105FAC94D75}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe () [File not signed] FirewallRules: [{EA4B2559-AD62-4B3D-9805-4510609F6A18}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe () [File not signed] FirewallRules: [{CAB5F0E4-46F3-46DA-BF92-43287A53A235}] => (Allow) D:\SteamLibrary\steamapps\common\Albion Online\launcher\AlbionLauncher.exe (Sandbox Interactive GmbH -> Sandbox Interactive GmbH) FirewallRules: [{609946E5-ECB4-4A5C-88A3-F4E7045D153D}] => (Allow) D:\SteamLibrary\steamapps\common\Albion Online\launcher\AlbionLauncher.exe (Sandbox Interactive GmbH -> Sandbox Interactive GmbH) ==================== Restore Points ========================= 10-01-2023 16:27:29 Zaplanowany punkt kontrolny 12-01-2023 17:14:59 Instalator modułów systemu Windows ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (01/21/2023 09:22:25 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GeometryDash.exe, version: 0.0.0.0, time stamp: 0x5a13638c Faulting module name: libcocos2d.dll, version: 0.0.0.0, time stamp: 0x5a1360bc Exception code: 0xc0000005 Fault offset: 0x0005fbf0 Faulting process ID: 0x71b4 Faulting application start time: 0x01d92db918166a56 Faulting application path: D:\SteamLibrary\steamapps\common\Geometry Dash\GeometryDash.exe Faulting module path: D:\SteamLibrary\steamapps\common\Geometry Dash\libcocos2d.dll Report ID: c9d453cc-0441-4327-a466-7dbaca439825 Faulting package full name: Faulting package-relative application ID: Error: (01/21/2023 06:49:03 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimiser couldn't complete ograniczenie ponowne on dane (D:) because: Żądana operacja nie jest obsługiwana przez sprzęt obsługujący wolumin. (0x8900002A) Error: (01/18/2023 06:23:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RuntimeBroker.exe, version: 10.0.19041.746, time stamp: 0x5b78739c Faulting module name: ntdll.dll, version: 10.0.19041.2130, time stamp: 0xb5ced1c6 Exception code: 0xc0000409 Fault offset: 0x000000000008c67f Faulting process ID: 0x3abc Faulting application start time: 0x01d92b4fb745c1e9 Faulting application path: C:\Windows\System32\RuntimeBroker.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report ID: fe7279a5-c0ac-49ad-b1c6-60f81990c479 Faulting package full name: Microsoft.Windows.Search_1.14.7.19041_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: runtimebroker07f4358a809ac99a64a67c1 Error: (01/17/2023 06:52:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RuntimeBroker.exe, version: 10.0.19041.746, time stamp: 0x5b78739c Faulting module name: ntdll.dll, version: 10.0.19041.2130, time stamp: 0xb5ced1c6 Exception code: 0xc0000374 Fault offset: 0x00000000000ff6a9 Faulting process ID: 0x177c Faulting application start time: 0x01d92a88f51d6d5e Faulting application path: C:\Windows\System32\RuntimeBroker.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report ID: aa784cf5-94d0-4965-aa59-bd1ba9174079 Faulting package full name: Microsoft.Windows.Search_1.14.7.19041_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: runtimebroker07f4358a809ac99a64a67c1 Error: (01/14/2023 09:26:25 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program SCPSL.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 2d20 Start Time: 01d92852fceeb18e Termination Time: 5 Application Path: D:\SteamLibrary\steamapps\common\SCP Secret Laboratory\SCPSL.exe Report Id: b38b9792-0104-4dcf-9411-4470f93898b9 Faulting package full name: Faulting package-relative application ID: Hang type: Unknown Error: (01/14/2023 07:30:34 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimiser couldn't complete ograniczenie ponowne on dane (D:) because: Żądana operacja nie jest obsługiwana przez sprzęt obsługujący wolumin. (0x8900002A) Error: (01/08/2023 03:19:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RuntimeBroker.exe, version: 10.0.19041.746, time stamp: 0x5b78739c Faulting module name: windows.storage.dll, version: 10.0.19041.2311, time stamp: 0x02ad31cf Exception code: 0xc0000005 Fault offset: 0x00000000000bb948 Faulting process ID: 0x9e0 Faulting application start time: 0x01d9236994ea97f0 Faulting application path: C:\Windows\System32\RuntimeBroker.exe Faulting module path: C:\WINDOWS\SYSTEM32\windows.storage.dll Report ID: e3fabaab-a7c6-43ce-994f-bd38494c9824 Faulting package full name: Microsoft.Windows.Search_1.14.7.19041_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: runtimebroker07f4358a809ac99a64a67c1 Error: (01/07/2023 08:35:04 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: ) Description: The storage optimiser couldn't complete ograniczenie ponowne on dane (D:) because: Żądana operacja nie jest obsługiwana przez sprzęt obsługujący wolumin. (0x8900002A) System errors: ============= Error: (01/22/2023 01:59:08 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server Microsoft.MicrosoftOfficeHub_18.2301.1131.0_x64__8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub.AppXvhez9tbpytkh6zv5q0bx5fj12yay14wg.mca did not register with DCOM within the required timeout. Error: (01/22/2023 01:59:05 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout. Error: (01/22/2023 01:59:05 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout. Error: (01/21/2023 09:24:40 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server Windows.Media.Capture.Internal.AppCaptureShell did not register with DCOM within the required timeout. Error: (01/21/2023 05:54:47 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: ZARZĄDZANIE NT) Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone. Error: (01/21/2023 03:57:33 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout. Error: (01/21/2023 03:57:33 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout. Error: (01/21/2023 03:57:33 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-JO1MHFN) Description: The server {FD06603A-2BDF-4BB1-B7DF-5DC68F353601} did not register with DCOM within the required timeout. Windows Defender: ================ Date: 2022-11-02 22:10:36 Description: Program antywirusowy Microsoft Defender has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=VirTool:Win32/DefenderTamperingRestore&threatid=2147741622&enterprise=0 Name: VirTool:Win32/DefenderTamperingRestore Severity: Poważny Category: Narzędzie Path: regkeyvalue:_hklm\software\policies\microsoft\windows defender\\DisableAntiSpyware Detection Origin: Nieznane Detection Type: Konkretne Detection Source: System Process Name: Unknown Security intelligence Version: AV: 1.377.1203.0, AS: 1.377.1203.0, NIS: 1.377.1203.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 22:10:08 Description: Program antywirusowy Microsoft Defender has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Defendercontrol.D&threatid=2147798153&enterprise=0 Name: HackTool:Win32/Defendercontrol.D Severity: Wysoki Category: Narzędzie Path: CmdLine:_C:\Users\Public\d.exe /TI 1 Detection Origin: Nieznane Detection Type: Konkretne Detection Source: System Process Name: Unknown Security intelligence Version: AV: 1.377.1203.0, AS: 1.377.1203.0, NIS: 1.377.1203.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 21:10:23 Description: Program antywirusowy Microsoft Defender has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=VirTool:Win32/DefenderTamperingRestore&threatid=2147741622&enterprise=0 Name: VirTool:Win32/DefenderTamperingRestore Severity: Poważny Category: Narzędzie Path: regkeyvalue:_hklm\software\policies\microsoft\windows defender\\DisableAntiVirus Detection Origin: Nieznane Detection Type: Konkretne Detection Source: System Process Name: Unknown Security intelligence Version: AV: 1.377.1203.0, AS: 1.377.1203.0, NIS: 1.377.1203.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 21:10:01 Description: Program antywirusowy Microsoft Defender has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Defendercontrol.D&threatid=2147798153&enterprise=0 Name: HackTool:Win32/Defendercontrol.D Severity: Wysoki Category: Narzędzie Path: CmdLine:_C:\Users\Public\d.exe /TI 1 Detection Origin: Nieznane Detection Type: Konkretne Detection Source: System Process Name: Unknown Security intelligence Version: AV: 1.377.1203.0, AS: 1.377.1203.0, NIS: 1.377.1203.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Date: 2022-11-02 20:30:22 Description: Program antywirusowy Microsoft Defender has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=VirTool:Win32/DefenderTamperingRestore&threatid=2147741622&enterprise=0 Name: VirTool:Win32/DefenderTamperingRestore Severity: Poważny Category: Narzędzie Path: regkeyvalue:_hklm\software\policies\microsoft\windows defender\\DisableAntiSpyware Detection Origin: Nieznane Detection Type: Konkretne Detection Source: System Process Name: Unknown Security intelligence Version: AV: 1.377.1203.0, AS: 1.377.1203.0, NIS: 1.377.1203.0 Engine Version: AM: 1.1.19700.3, NIS: 1.1.19700.3 Event[0]: Date: 2022-10-28 20:35:29 Description: Program antywirusowy Microsoft Defender has encountered an error trying to upload a suspicious file for further analysis. Filename: C:\Users\danie\Downloads\OperaGXSetup.exe Sha256: 9456b3cf6fe17a28f0c670d6d69796ebde44c78ce3ca1cdf70c24d1c9a2b08e7 Current security intelligence Version: AV: 1.377.940.0, AS: 1.377.940.0 Current Engine Version: 1.1.19700.3 Error code: 0x80071112 CodeIntegrity: =============== Date: 2023-01-22 13:58:40 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\malwarebytes\MBAMService.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends International, LLC. F8 06/18/2021 Motherboard: Gigabyte Technology Co., Ltd. B560 HD3 Processor: Intel(R) Core(TM) i3-10100 CPU @ 3.60GHz Percentage of memory in use: 68% Total physical RAM: 8061.28 MB Available physical RAM: 2525.33 MB Total Virtual: 16765.28 MB Available Virtual: 7057.57 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:237.85 GB) (Free:144.13 GB) (Model: ADATA SX8200PNP) NTFS Drive d: (dane) (Fixed) (Total:931.39 GB) (Free:683.16 GB) (Model: TOSHIBA DT01ACA100) NTFS \\?\Volume{a339ed44-d4f6-45b5-b3ed-fad67af06d66}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS \\?\Volume{298fccbc-da74-40fd-8131-b48d6f5e062c}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Protective MBR) (Size: 238.5 GB) (Disk ID: 00000000) Partition: GPT. ========================================================== Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt =======================