CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-306714878-3748668911-3957027355-1019\...\MountPoints2: {baad68bd-f478-11e7-97f5-00dbdf669bd1} - "H:\Start.exe" HKU\S-1-5-18\...\Run: [] => [X] GroupPolicy: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA HKU\S-1-5-21-306714878-3748668911-3957027355-1019\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gazeta.pl/0,0.html?p=190 SearchScopes: HKU\S-1-5-21-306714878-3748668911-3957027355-1019 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku Task: {10F15E2D-9A45-4CC0-A40A-B9126D3A9ED0} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA Task: {DAE97A1A-FFAE-4A5C-B7BA-A71FB193256E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Brak pliku <==== UWAGA Task: C:\WINDOWS\Tasks\TrackerAutoUpdate.job => C:\Program Files\Tracker Software\Update\TrackerUpdate.exe-CheckUpdate(Tracker Software Products (Canada) Ltd.Kee AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0] EmptyTemp: Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}