CloseProcesses: CreateRestorePoint: EmptyTemp: HKU\S-1-5-21-3261834350-1903923468-2875364868-1001\...\MountPoints2: {5d2ad190-8e14-11e6-a7ab-806e6f6e6963} - "E:\LoaderPrawkoS.exe" SearchScopes: HKU\S-1-5-21-3261834350-1903923468-2875364868-1001 -> DefaultScope {922D1579-97A2-4738-8EBB-740332A15EFB} URL = SearchScopes: HKU\S-1-5-21-3261834350-1903923468-2875364868-1001 -> {922D1579-97A2-4738-8EBB-740332A15EFB} URL = Toolbar: HKLM-x32 - Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.8.0.50\Exts\Chrome.crx [2017-01-24] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.8.0.50\Exts\Chrome.crx [2017-01-24] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\Adobe Flash Player PPAPI Notifier" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\Adobe Flash Player Updater" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\CCleanerSkipUAC" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\MSI LEDBar Controller" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\MSIOSDx64_Host" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\MSIOSDx86_Host" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(10): schtasks.exe -> /Change /TN "\MSISW_Host" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(11): schtasks.exe -> /Change /TN "\Nahimic2Svc32Run" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(12): schtasks.exe -> /Change /TN "\Nahimic2Svc64Run" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(13): schtasks.exe -> /Change /TN "\Nahimic2UILauncherRun" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(14): schtasks.exe -> /Change /TN "\Norton WSC Integration" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(15): schtasks.exe -> /Change /TN "\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(16): schtasks.exe -> /Change /TN "\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(17): schtasks.exe -> /Change /TN "\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(18): schtasks.exe -> /Change /TN "\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(19): schtasks.exe -> /Change /TN "\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(20): schtasks.exe -> /Change /TN "\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(21): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-3261834350-1903923468-2875364868-1001" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(22): schtasks.exe -> /Change /TN "\PDVDServ12 Task" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(23): schtasks.exe -> /Change /TN "\User_Feed_Synchronization-{A7102D57-168F-4190-A9BC-AB53864C5340}" /ENABLE Task: {0CBC5492-8D11-4F7A-B057-CC1747B3252E} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(24): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE Task: {1EB127A2-4D02-4E11-8DD1-F385D8DA2E08} - System32\Tasks\S-1-5-21-3261834350-1903923468-2875364868-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation) Task: {D4BA585A-F0F8-44F3-B39A-789C6F4145A3} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA AlternateDataStreams: C:\Users\Public\AppData:CSM [480] HKU\S-1-5-21-3261834350-1903923468-2875364868-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk" HKU\S-1-5-21-3261834350-1903923468-2875364868-1001\...\StartupApproved\Run: => "AvastBrowserAutoLaunch_F5850685EA13F5FDC6C5D2B388119507" CMD: netsh advfirewall reset