CloseProcesses: CreateRestorePoint: EmptyTemp: HKU\S-1-5-21-224422581-2469904219-4089960627-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-26] (Google Inc.) BHO-x32: Brak nazwy -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> Brak pliku BHO-x32: Brak nazwy -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> Brak pliku U4 AppMgmt; Brak ImagePath U4 CscService; Brak ImagePath U4 napagent; Brak ImagePath S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X] S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X] U4 PeerDistSvc; Brak ImagePath 2016-11-23 18:13 - 2019-01-05 12:54 - 000000166 _____ () C:\Users\aniak\AppData\Roaming\sp_data.sys 2018-10-17 03:08 - 2018-10-17 03:08 - 000000000 ____H () C:\Users\aniak\AppData\Local\BIT928E.tmp 2018-10-17 03:07 - 2018-10-17 03:07 - 000000000 _____ () C:\Users\aniak\AppData\Local\{4B9687A3-2904-4572-A672-3D851AEDDB30} CustomCLSID: HKU\S-1-5-21-224422581-2469904219-4089960627-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\aniak\AppData\Local\Microsoft\OneDrive\18.222.1104.0007\amd64\FileSyncShell64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-224422581-2469904219-4089960627-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\aniak\AppData\Local\Microsoft\OneDrive\18.222.1104.0007\amd64\FileSyncShell64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-224422581-2469904219-4089960627-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\aniak\AppData\Local\Microsoft\OneDrive\18.222.1104.0007\amd64\FileSyncShell64.dll => Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku Task: {C25AB999-C7DE-489C-9F0A-6AAF25F34616} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA FirewallRules: [{3A701780-EB8A-4594-876B-61D9AC9D8066}] => (Allow) D:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe Brak pliku FirewallRules: [{D38C94E1-D153-440A-9128-BC032AC78368}] => (Allow) D:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe Brak pliku FirewallRules: [TCP Query User{E6E47162-D770-409C-ABEE-1B36F88C859F}C:\users\aniak\appdata\local\temp\i1482049778\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\aniak\appdata\local\temp\i1482049778\windows\resource\jre\bin\javaw.exe Brak pliku FirewallRules: [UDP Query User{21F40EB9-22B7-4D31-B6C3-B89A37A6DB3E}C:\users\aniak\appdata\local\temp\i1482049778\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\aniak\appdata\local\temp\i1482049778\windows\resource\jre\bin\javaw.exe Brak pliku FirewallRules: [TCP Query User{57C11A76-9CAD-4674-AB27-351D28BE6724}C:\users\aniak\appdata\local\temp\i1482050008\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\aniak\appdata\local\temp\i1482050008\windows\resource\jre\bin\javaw.exe Brak pliku FirewallRules: [UDP Query User{BB08B5B7-F8C4-44BC-8394-FC6FA0501ED1}C:\users\aniak\appdata\local\temp\i1482050008\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\aniak\appdata\local\temp\i1482050008\windows\resource\jre\bin\javaw.exe Brak pliku FirewallRules: [{4598B209-887F-4A7C-87A8-C41803CFA704}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe Brak pliku FirewallRules: [{5FA78D84-D02F-45EC-B800-5014F7D58EDB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe Brak pliku FirewallRules: [{20DA1623-BD01-4EDF-BA48-150A5B8164DC}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe () FirewallRules: [{CBCA8CA4-A508-4004-84BB-E6D18E8FBFAF}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe Brak pliku FirewallRules: [{90D308DB-0D82-4D7B-A161-D95F2617D5D3}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe Brak pliku FirewallRules: [{6DAD5D3B-58E3-4CC4-97F1-AD66598E8CD8}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe Brak pliku FirewallRules: [{3798FB09-B304-4B06-A423-B453B9A58BA5}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.admin.exe Brak pliku FirewallRules: [{E37760C0-8CF5-4405-A279-683B42C67828}] => (Allow) C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Brak pliku FirewallRules: [{93116363-8B96-41BD-9C06-38752ACD7976}] => (Allow) C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Brak pliku FirewallRules: [{31607B2C-95CC-493C-ABA6-839854E6229B}] => (Allow) C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Brak pliku FirewallRules: [{1A9033A9-565C-4BDF-91F5-0849B4E8B217}] => (Allow) C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Brak pliku FirewallRules: [TCP Query User{4623FE34-A807-43FD-AF69-3B54AD884DDD}C:\program files (x86)\allplayer remote\allplayerremotecontrol.exe] => (Block) C:\program files (x86)\allplayer remote\allplayerremotecontrol.exe Brak pliku FirewallRules: [UDP Query User{101FC866-F307-43A0-A86C-9FAAF78FB46B}C:\program files (x86)\allplayer remote\allplayerremotecontrol.exe] => (Block) C:\program files (x86)\allplayer remote\allplayerremotecontrol.exe Brak pliku FirewallRules: [{FAC51B25-6EB2-4FFF-A936-BC286C4233F9}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe Brak pliku FirewallRules: [{B0F87501-52D0-45C6-9228-EED530E723FC}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe Brak pliku FirewallRules: [{6DDD912C-E257-45DA-BCA8-FB9D9B931421}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe Brak pliku FirewallRules: [{E10B476C-DD4C-41F3-8BD0-13233242512E}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe Brak pliku FirewallRules: [{6D849B6A-54E8-4BB5-B354-DFC39C505AAD}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe Brak pliku FirewallRules: [{E11C4BEC-6724-4C1D-8B05-09B34BBB93D7}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe Brak pliku FirewallRules: [TCP Query User{BA484F30-0B37-4C5A-8AD7-6FDADA0873A2}C:\program files (x86)\world of warcraft\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\utils\wowvoiceproxy.exe Brak pliku FirewallRules: [UDP Query User{6D4A4EA9-FF0D-4400-A31E-D5A36DC35BDA}C:\program files (x86)\world of warcraft\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\utils\wowvoiceproxy.exe Brak pliku C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911\The Elder Scrolls V Skyrim\The Elder Scrolls V Skyrim.lnk C:\Users\aniak\Desktop\Windows 10 Update Assistant.lnk C:\Users\aniak\Desktop\Ania\gry\The Sims 4.lnk C:\Users\aniak\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9b8438e69742281a\League of Legends.lnk Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}