CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-866429875-1388168272-3903809281-1001\...\MountPoints2: {d5576fca-02e1-11e8-9e77-7085c2380cf5} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-866429875-1388168272-3903809281-1001\...\MountPoints2: {d5576fdc-02e1-11e8-9e77-7085c2380cf5} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-866429875-1388168272-3903809281-1001\...\MountPoints2: {d5576fe5-02e1-11e8-9e77-7085c2380cf5} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-866429875-1388168272-3903809281-1001\...\MountPoints2: {d5577116-02e1-11e8-9e77-7085c2380cf5} - "F:\HiSuiteDownLoader.exe" HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== UWAGA (Ograniczenia - ProxySettings) ProxyEnable: [HKLM] => Proxy [funkcja włączona] ProxyEnable: [HKLM-x32] => Proxy [funkcja włączona] ProxyServer: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080 ProxyServer: [HKLM-x32] => http=127.0.0.1:8080;https=127.0.0.1:8080 AutoConfigURL: [HKLM] => http=127.0.0.1:8080;https=127.0.0.1:8080 ProxyEnable: [S-1-5-21-866429875-1388168272-3903809281-1001] => Proxy [funkcja włączona] ProxyServer: [S-1-5-21-866429875-1388168272-3903809281-1001] => http=127.0.0.1:8080;https=127.0.0.1:8080 Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 172.16.78.1 82.160.1.1 Tcpip\..\Interfaces\{ed4ae7eb-54b0-4c68-b24e-9070b6506394}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{ed4ae7eb-54b0-4c68-b24e-9070b6506394}: [DhcpNameServer] 10.0.0.1 172.16.78.1 82.160.1.1 ManualProxies: 1http=127.0.0.1:8080;https=127.0.0.1:8080 HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA SearchScopes: HKU\S-1-5-21-866429875-1388168272-3903809281-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = CHR DefaultSearchURL: Default -> hxxps://www.tunnelbear.com 2018-02-03 17:01 - 2018-02-03 17:02 - 000000000 ____D C:\AdwCleaner ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Brak pliku ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Brak pliku AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [432] HKU\S-1-5-21-866429875-1388168272-3903809281-1001\...\StartupApproved\Run: => "MyComGames" EmptyTemp: RemoveProxy: Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}