CloseProcesses: CreateRestorePoint: EmptyTemp: CustomCLSID: HKU\S-1-5-21-3941894045-3464566092-1494290099-1001_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe /Automation => Brak pliku CustomCLSID: HKU\S-1-5-21-3941894045-3464566092-1494290099-1001_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe => Brak pliku ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Brak pliku ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Brak pliku ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Brak pliku ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Brak pliku C:\Users\Komp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Сhromе.lnk C:\Users\Komp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WоrldоfTanks.lnk C:\Users\Komp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Рrzeglądаrka Орerа.lnk C:\Users\Komp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооgle Chromе.lnk C:\Users\Komp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Рrzеglądarkа Opеrа.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Рrzeglądаrka Ореra.lnk IE trusted site: HKU\S-1-5-21-3941894045-3464566092-1494290099-1001\...\localhost -> localhost FirewallRules: [UDP Query User{2E1DC2B7-9285-4192-907F-09320411434A}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe Brak pliku FirewallRules: [TCP Query User{C4FEE07F-F8A7-46F2-B966-F42B30F5D0CE}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe Brak pliku FirewallRules: [{E738F581-AB0D-40EF-A190-C903865C9286}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe Brak pliku FirewallRules: [{0374F9C5-A1E8-4AC8-B2FB-588AB761ABF6}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe Brak pliku FirewallRules: [{7A16CF1F-AD86-486E-8856-5BA7DC412A37}] => (Allow) C:\Program Files\AVG\Antivirus\AvEmUpdate.exe Brak pliku FirewallRules: [{C3CAB23A-8748-4F6F-8CF8-81EBE4DB43A6}] => (Allow) C:\Program Files\AVG\Antivirus\AvEmUpdate.exe Brak pliku FirewallRules: [{06EC23B4-F6CD-47DF-B4ED-663EA4E4F7D3}] => (Allow) D:\Program Files (x86)\Codemasters\DiRT2\dirt2_game.exe Brak pliku FirewallRules: [{C7DA6B9E-6BA1-4A9E-BD50-4826E3A2719F}] => (Allow) D:\Program Files (x86)\Codemasters\DiRT2\dirt2_game.exe Brak pliku FirewallRules: [UDP Query User{507B0715-F79E-4538-BB43-0B2E99C8372D}D:\program files (x86)\driver san francisco\driver.exe] => (Block) D:\program files (x86)\driver san francisco\driver.exe Brak pliku FirewallRules: [TCP Query User{B23491DA-D3F6-4DC6-86D8-58647CFE561D}D:\program files (x86)\driver san francisco\driver.exe] => (Block) D:\program files (x86)\driver san francisco\driver.exe Brak pliku FirewallRules: [UDP Query User{06A5BE90-F036-4D10-A9FD-2C59922C61D7}C:\users\komp\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\komp\appdata\local\akamai\netsession_win.exe Brak pliku FirewallRules: [TCP Query User{BC73E2DF-AABE-442F-ADCE-AB5A6E5D9AE7}C:\users\komp\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\komp\appdata\local\akamai\netsession_win.exe Brak pliku FirewallRules: [UDP Query User{E9EF7093-756D-4FED-8881-17A032CFB147}C:\users\komp\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\komp\appdata\local\akamai\netsession_win.exe Brak pliku FirewallRules: [TCP Query User{579B240D-A76A-43D4-8564-618DE94B2196}C:\users\komp\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\komp\appdata\local\akamai\netsession_win.exe Brak pliku FirewallRules: [UDP Query User{37C72BF6-D6B3-4A10-99A3-1B5BF12FDE94}C:\program files (x86)\origin games\fifa 17\fifa17.exe] => (Block) C:\program files (x86)\origin games\fifa 17\fifa17.exe Brak pliku FirewallRules: [TCP Query User{FE470498-1434-4FF2-B340-03BBAB2FCEA7}C:\program files (x86)\origin games\fifa 17\fifa17.exe] => (Block) C:\program files (x86)\origin games\fifa 17\fifa17.exe Brak pliku FirewallRules: [UDP Query User{C0FC1488-129F-40E6-B7EA-8DF4C1F6D392}D:\program files (x86)\empire interactive\flatout\flatout.exe] => (Block) D:\program files (x86)\empire interactive\flatout\flatout.exe Brak pliku FirewallRules: [TCP Query User{58A0D5A3-AB49-49EE-BD79-F09FF7A2F259}D:\program files (x86)\empire interactive\flatout\flatout.exe] => (Block) D:\program files (x86)\empire interactive\flatout\flatout.exe Brak pliku FirewallRules: [UDP Query User{753E950F-644C-4BA1-AABB-5FB459DF79E6}C:\program files (x86)\origin games\fifa 17\fifa17.exe] => (Allow) C:\program files (x86)\origin games\fifa 17\fifa17.exe Brak pliku FirewallRules: [TCP Query User{DFF8A2B7-07DD-469A-B6BB-73E013770D8E}C:\program files (x86)\origin games\fifa 17\fifa17.exe] => (Allow) C:\program files (x86)\origin games\fifa 17\fifa17.exe Brak pliku FirewallRules: [{AF52942D-4456-4805-AD0F-C85C56C57CA2}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 17\FIFASetup\fifaconfig.exe Brak pliku FirewallRules: [{0D6C5146-943A-485C-8459-7EA76BC32076}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 17\FIFASetup\fifaconfig.exe Brak pliku FirewallRules: [{6C0C4F90-95FE-4639-885C-B5A4C9732CCF}] => (Allow) D:\Program Files (x86)\Rockstar Games\Grand Theft Auto V\GTA5.exe Brak pliku FirewallRules: [{A7A0895C-840F-46B9-841C-A1A9F7E1F65D}] => (Allow) D:\Program Files (x86)\Rockstar Games\Grand Theft Auto V\GTA5.exe Brak pliku FirewallRules: [{1A4216ED-A088-4642-A5A0-AC0B27D85464}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Origins\ACOrigins.exe Brak pliku FirewallRules: [{15C400FA-2F3B-470C-9ABE-BBEB037057BB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Origins\ACOrigins.exe Brak pliku FirewallRules: [TCP Query User{AE5A7097-4F2F-4300-8661-A2F1ED5790BB}C:\users\komp\desktop\train.simulator.2016\railworks.exe] => (Allow) C:\users\komp\desktop\train.simulator.2016\railworks.exe Brak pliku FirewallRules: [UDP Query User{CEBC3074-8526-4BBA-845A-FBA4893A979F}C:\users\komp\desktop\train.simulator.2016\railworks.exe] => (Allow) C:\users\komp\desktop\train.simulator.2016\railworks.exe Brak pliku FirewallRules: [TCP Query User{6E56F9DB-3BA2-4507-B44D-8B5F1DFC2314}D:\program files (x86)\empire interactive\flatout\flatout.exe] => (Block) D:\program files (x86)\empire interactive\flatout\flatout.exe Brak pliku FirewallRules: [UDP Query User{D6CB1142-DB55-4CBB-BCA7-D3CDD9BA83D2}D:\program files (x86)\empire interactive\flatout\flatout.exe] => (Block) D:\program files (x86)\empire interactive\flatout\flatout.exe Brak pliku FirewallRules: [{DCF00C9A-3E78-45B0-8439-58822FF91912}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe Brak pliku FirewallRules: [{AE251C79-2A40-41CC-82E8-1A60E2EBD2C4}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe Brak pliku FirewallRules: [{6EB19B7C-4BEA-49FD-A96F-1D58F297B11B}] => (Allow) C:\Games\World_of_Tanks\worldoftanks.exe Brak pliku FirewallRules: [{2E877897-13BF-40D8-9C31-1FF83F9C6B6E}] => (Allow) C:\Games\World_of_Tanks\worldoftanks.exe Brak pliku FirewallRules: [{391175D4-7E07-48E4-8A0C-AB14232485E0}] => (Allow) D:\Games\World_of_Tanks\WoTLauncher.exe Brak pliku FirewallRules: [{113F368D-BB59-498E-BEF2-1829E3F53B2E}] => (Allow) D:\Games\World_of_Tanks\WoTLauncher.exe Brak pliku FirewallRules: [{CE1C4578-8EA8-42AC-9D4A-773A24E19D0C}] => (Allow) D:\Games\World_of_Tanks\worldoftanks.exe Brak pliku FirewallRules: [{9EEC61B5-3B0C-4C08-874D-06B7B0026A57}] => (Allow) D:\Games\World_of_Tanks\worldoftanks.exe Brak pliku FirewallRules: [{A9C45C07-57E1-4ED1-BE6C-D19CB3B2E8C5}] => (Allow) C:\Program Files (x86)\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe Brak pliku FirewallRules: [{CC9953DD-1F39-4A18-B524-F78551795F88}] => (Allow) C:\Program Files (x86)\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe Brak pliku FirewallRules: [{34DE2FC4-19FD-41D5-BFB9-09F0A52B9B0C}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe Brak pliku FirewallRules: [{2DEC1698-8741-43F0-96C3-7ED12A5297A6}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe Brak pliku FirewallRules: [{0EECCAA2-EB5D-4440-B3D1-C14215893D2C}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe Brak pliku FirewallRules: [{302F7463-5807-484A-A446-DF39449476E9}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe Brak pliku FirewallRules: [{90E8E8F9-0B50-4740-81D1-45F1D02678CC}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Brak pliku FirewallRules: [{04CEF671-9E38-4C94-8AD9-6724C0781F2C}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Brak pliku FirewallRules: [{8EC41F9A-DD8F-487C-987A-978EF17E824E}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe Brak pliku FirewallRules: [{0E3528B8-C69C-48E6-8A0D-748B417FBF2D}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe Brak pliku FirewallRules: [{B958B2FD-BAFE-4218-9258-5BCBDCA64DEA}] => (Allow) D:\Program Files (x86)\Rockstar Games\EFLC\LaunchEFLC.exe Brak pliku FirewallRules: [{6D8D2F0D-1675-46C5-969A-A701BA6EA33C}] => (Allow) D:\Program Files (x86)\Rockstar Games\EFLC\LaunchEFLC.exe Brak pliku FirewallRules: [TCP Query User{CDC80CBC-900A-4664-95AA-371829A33865}D:\program files (x86)\rockstar games\eflc\eflc.exe] => (Allow) D:\program files (x86)\rockstar games\eflc\eflc.exe Brak pliku FirewallRules: [UDP Query User{B07ACE0C-96B1-4F14-8B53-16623870CF13}D:\program files (x86)\rockstar games\eflc\eflc.exe] => (Allow) D:\program files (x86)\rockstar games\eflc\eflc.exe Brak pliku FirewallRules: [TCP Query User{074B63E4-AAD2-4833-963A-AFC86A3112BF}D:\program files (x86)\anno 1404 gold edition\tools\anno4web.exe] => (Allow) D:\program files (x86)\anno 1404 gold edition\tools\anno4web.exe Brak pliku FirewallRules: [UDP Query User{4C8364E6-A906-4B05-BDF6-6A52622ED720}D:\program files (x86)\anno 1404 gold edition\tools\anno4web.exe] => (Allow) D:\program files (x86)\anno 1404 gold edition\tools\anno4web.exe Brak pliku FirewallRules: [TCP Query User{82FA959B-8465-4766-A0BB-38C4BD4E074F}D:\program files (x86)\anno 1404 gold edition\tools\addonweb.exe] => (Block) D:\program files (x86)\anno 1404 gold edition\tools\addonweb.exe Brak pliku FirewallRules: [UDP Query User{6A87671A-44D4-4088-BA58-71812FCCA661}D:\program files (x86)\anno 1404 gold edition\tools\addonweb.exe] => (Block) D:\program files (x86)\anno 1404 gold edition\tools\addonweb.exe Brak pliku HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-3941894045-3464566092-1494290099-1001\...\Policies\Explorer: [] HKU\S-1-5-21-3941894045-3464566092-1494290099-1001\...\MountPoints2: {66e50133-459c-11e9-88e3-fcaa14124bdc} - "H:\HiSuiteDownLoader.exe" HKU\S-1-5-21-3941894045-3464566092-1494290099-1001\...\MountPoints2: {7aef911a-8f9c-11e8-888d-fcaa14124bdc} - "F:\HiSuiteDownLoader.exe" CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA Task: {0498B126-E375-46C1-BF00-21141F4D8D7F} - System32\Tasks\34CB39D8-9461-8A1C-388A-A6D42EFECD1F => C:\WINDOWS\SysWOW64\regsvr32.exe /n /s /i:"/61bb524745de0496 /q" "C:\PROGRA~3\B328B1~1\{C2D1D~1." Task: {6B1B2179-6BB2-4C09-AAEA-A0587E519F6A} - System32\Tasks\Opera scheduled Autoupdate 1499811917 => C:\Program Files\Opera\launcher.exe [1493592 2019-06-05] (Opera Software AS -> Opera Software) Task: {AAE990EA-F162-42BC-92FA-E49F971EE5E7} - System32\Tasks\TR_FastScan_Daily_Komp => C:\Program Files (x86)\Trojan Remover\Trjscan.exe [3309088 2018-12-01] (Simply Super Software -> Simply Super Software) Task: {AB067CF9-72B6-49AD-9A41-4866933BC2BA} - System32\Tasks\TR_AntiHijack => C:\Program Files (x86)\Trojan Remover\TRAntiHJ.exe Task: {ABA00229-E040-4F24-8FEE-5C6423CA84C3} - System32\Tasks\TR_Updater => C:\Program Files (x86)\Trojan Remover\Trupd.exe [2506776 2019-03-24] (Simply Super Software -> Simply Super Software) Task: {AE1A9912-E032-4752-88E8-5F2D2A7FC3AF} - System32\Tasks\TR_FastScan_AtLogon => C:\Program Files (x86)\Trojan Remover\Trjscan.exe [3309088 2018-12-01] (Simply Super Software -> Simply Super Software) Task: {F41BFEE8-2B46-41AA-93B6-2F5C5C463A6E} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2314008 2019-06-04] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) Tcpip\..\Interfaces\{0d9ccef5-affe-46a9-bdd3-fd080966ddc0}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{3fa24376-daaa-11e7-ab49-806e6f6e6963}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{5c2e38be-2e96-4ce8-bb3d-0bd783196860}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{9333811f-a26c-4bd8-85f1-27aa16fb54ca}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{b826a51e-8c48-4455-aaf6-93932c98769e}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{b826a51e-8c48-4455-aaf6-93932c98769e}: [DhcpNameServer] 8.8.8.8 Tcpip\..\Interfaces\{ce37d6eb-2f18-494f-84b9-9b9f45041a20}: [NameServer] 8.8.8.8 Tcpip\..\Interfaces\{DFC0F465-1529-43DA-8903-710B4501EBB6}: [NameServer] 8.8.8.8 SearchScopes: HKU\S-1-5-21-3941894045-3464566092-1494290099-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://pl.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10454__180621__yaie&p={searchTerms} CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hp&ts=1419305429&from=smt&uid=SAMSUNGXHD103SI_S2C4J90Z808460","hxxp://www.google.com/","hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki","hxxp://www.mystartsearch.com/?type=hp&ts=1446397921&z=1f3fdf554e82c35ae4118ffg8zez8q8c9tdm8tdoeg&from=cor&uid=samsungxhd103si_s2c4j90z808460","hxxp://www.gazeta.pl/0,0.html?p=190","hxxps://www.google.com/" CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx S2 rcdll; C:\Users\Komp\AppData\Local\Temp\rcdll.exe [X] <==== UWAGA S3 HWiNFO; \??\C:\Users\Komp\AppData\Local\Temp\HWiNFO64A.SYS [X] <==== UWAGA S1 ovsacuiw; \??\C:\WINDOWS\system32\drivers\ovsacuiw.sys [X] S1 vluworki; \??\C:\WINDOWS\system32\drivers\vluworki.sys [X] 2019-06-06 16:54 - 2018-10-04 12:06 - 000004000 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1499811917 2018-03-04 09:36 - 2015-09-17 22:06 - 000020552 _____ ( ) C:\Program Files (x86)\ApplyXSL.exe HOSTS: