CloseProcesses: CreateRestorePoint: EmptyTemp: VirusTotal: C:\ProgramData\msbftbgnm.exe HKLM-x32\...\RunOnce: [] => [X] HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\Policies\Explorer: [] HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {478ab8c4-e05d-11e7-be88-b8763f9fdb8e} - "G:\Setup.exe" HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {487e5227-cef4-11e6-be8c-b8763f9fdb8e} - "F:\autorun.exe" HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {c853757c-0361-11e8-be88-b8763f9fdb8e} - "H:\autorun.exe" HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {c8537587-0361-11e8-be88-b8763f9fdb8e} - "H:\autorun.exe" Tcpip\..\Interfaces\{3B79996C-3219-4CC1-8163-8D6C46D62BC6}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{76E471E9-3FCC-4313-81F1-B79177EA5F48}: [DhcpNameServer] 212.87.0.72 193.0.71.130 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=HPNTDFJS Toolbar: HKU\S-1-5-21-3145501433-2751271693-2052433869-1001 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => -> Brak pliku Task: {3439DF23-41E5-4315-9359-3E617B4FCCF9} - System32\Tasks\{F2C41152-7938-4D07-A213-B8D3B6664DB4} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\setup.exe" -c /z-uninstall Startup: C:\Users\shitter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk [2017-11-09] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}