@iJuliusz dziękuję za zainteresowanie sprawą. Poniżej wklejam wyniki wyszukiwania z komendy:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe
DisableExceptionChainValidation REG_DWORD 0x0
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcrobatInfo.exe
(Default) REG_SZ
DisableExceptionChainValidation REG_DWORD 0x0
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroCEF.exe
DisableExceptionChainValidation REG_DWORD 0x0
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroServicesUpdater.exe
DisableExceptionChainValidation REG_DWORD 0x0
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe
UseFilter REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe\3d65e696_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\client\appvlp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe
MaxLoaderThreads REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\clview.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cnfnot32.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllhost.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drvinst.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ehexthost32.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe
UseFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\excel.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excelcnv.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ExtExport.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
DisableExceptionChainValidation REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\graph.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ie4uinit.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieinstal.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ielowutil.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieUnatt.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
DisableExceptionChainValidation REG_DWORD 0x0
DisableUserModeCallbackFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lync.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MiracastView.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MRT.exe
CFGOptions REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe
UseFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msaccess.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvw.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfeedssync.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshta.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiregister.exe
UseFilter REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiregister.exe\2cb36d85_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\msi\msiregister\msiregister.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe
CFGOptions REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoev.exe
UseFilter REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoev.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msoev.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msohtmed.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msosrec.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msosync.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msotd.exe
UseFilter REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msotd.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msotd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe
UseFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe\138c4634_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\msoxmled.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msqry32.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngen.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngentask.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenotem.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\orgchart.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\orgwiz.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\osfinstaller.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe
UseFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\powerpnt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PresentationHost.exe
MitigationOptions REG_QWORD 0x111111
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintDialog.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PrintIsolationHost.exe
MitigationOptions REG_QWORD 0x200000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\projimpt.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runtimebroker.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanost.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpst.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotocolhost.exe
DisableExceptionChainValidation REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\selfcert.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe
UseFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\setlang.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\splwow64.exe
MitigationOptions REG_QWORD 0x200000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe
MitigationOptions REG_QWORD 0x200000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe
MinimumStackCommitInBytes REG_DWORD 0x8000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SystemSettings.exe
MitigationOptions REG_QWORD 0x100000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tlimpt.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe
UseFilter REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe\2cb36d85_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\msi\msiregister\unins000.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\visio.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpreview.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winproj.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe
UseFilter REG_DWORD 0x1
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\2a33dc50_PD
Debugger REG_SZ “C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe”
FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\winword.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wordconv.exe
MitigationOptions REG_QWORD 0x100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe
DisableExceptionChainValidation REG_DWORD 0x3