CloseProcesses: CreateRestorePoint: EmptyTemp: HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-2396947154-3508570587-140613579-1001\...\MountPoints2: {eefac237-7622-11e8-9d9c-60a44c570006} - "G:\setup.exe" HKU\S-1-5-21-2396947154-3508570587-140613579-1001\...\Winlogon: [Shell] %comspec% <==== UWAGA HKU\S-1-5-21-2396947154-3508570587-140613579-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist "C:\Users\setny\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" ( start /MIN "" "C:\Users\setny\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== UWAGA Tcpip\..\Interfaces\{152d359c-4754-4a6e-a640-9c7b2434ae9e}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{152d359c-4754-4a6e-a640-9c7b2434ae9e}: [DhcpNameServer] 192.168.0.1 2018-07-10 08:50 - 2018-07-10 08:50 - 000004636 _____ () C:\Users\setny\AppData\Roaming\VoiceMeeterDefault.xml 2019-01-21 23:09 - 2019-01-21 23:09 - 007850088 _____ (Microsoft Corporation) C:\Users\setny\AppData\Local\Temp\BingBarSetup-Partner.exe ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe AlternateDataStreams: C:\ProgramData:NT [40] AlternateDataStreams: C:\ProgramData:NT2 [766] AlternateDataStreams: C:\Users\All Users:NT [40] AlternateDataStreams: C:\Users\All Users:NT2 [766] AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT [40] AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2 [766] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [766] AlternateDataStreams: C:\Users\Public\AppData:CSM [221] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476] AlternateDataStreams: C:\Users\setny\Dane aplikacji:NT [40] AlternateDataStreams: C:\Users\setny\Dane aplikacji:NT2 [766] AlternateDataStreams: C:\Users\setny\AppData\Roaming:NT [40] AlternateDataStreams: C:\Users\setny\AppData\Roaming:NT2 [766] FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe () Hosts: RemoveProxy: