CloseProcesses: CreateRestorePoint: HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA HKU\S-1-5-21-12795608-1557185064-1478637801-1000\...\Run: [BingSvc] => C:\Users\Weronika\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-11] (© 2015 Microsoft Corporation) HKU\S-1-5-21-12795608-1557185064-1478637801-1000\...\MountPoints2: {d98ed33f-8a72-11e7-b8cb-642737ae7542} - "E:\LG_PC_Programs.exe" BootExecute: autocheck autochk * HKU\S-1-5-21-12795608-1557185064-1478637801-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://vaioportal.sony.eu HKU\S-1-5-21-12795608-1557185064-1478637801-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://sony.msn.com/ URLSearchHook: HKU\S-1-5-21-12795608-1557185064-1478637801-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll Brak pliku URLSearchHook: HKU\S-1-5-21-12795608-1557185064-1478637801-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Brak pliku SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-12795608-1557185064-1478637801-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-12795608-1557185064-1478637801-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-12795608-1557185064-1478637801-1000 -> {8BD4D120-94BF-4985-BFA4-93991D798B29} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices Toolbar: HKU\S-1-5-21-12795608-1557185064-1478637801-1000 -> Brak nazwy - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Brak pliku CHR HomePage: Default -> msn.com CHR DefaultSearchURL: Default -> hxxps://pl.search.yahoo.com/search?fr=mcafee_uninternational&type=C210PL649D20150523&p={searchTerms} CHR DefaultSearchKeyword: Default -> mcafee CHR HKU\S-1-5-21-12795608-1557185064-1478637801-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx U3 idsvc; Brak ImagePath Booking.com version 1.1.0.5019 (HKLM-x32\...\{F9B4E180-69C1-4414-81E6-DF79F5F971B1}_is1) (Version: 1.1.0.5019 - Booking.com) <==== UWAGA ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> Brak pliku Task: {2D930FFC-1806-403B-8C97-BF2FC5A7344F} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Brak pliku <==== UWAGA Task: {3DBF9E2A-FC59-40B6-971D-760FAF68BF89} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA Task: {43ECFE2E-56BF-48A5-999B-FC5A9C01F647} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA Task: {63D26760-4FCB-4519-AFAB-B330DF57C83F} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Brak pliku <==== UWAGA Task: {71C1D227-F2E0-4C54-98E2-E29FD33D4279} - \Microsoft\Windows\Setup\gwx\rundetector -> Brak pliku <==== UWAGA Task: {7E73AB4B-B8D7-4556-99EE-B20BE1347818} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Brak pliku <==== UWAGA Task: {82FCC534-C862-42DB-85B7-EC2749DE8D2D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA Task: {8C3430A4-3734-4A4B-8F07-FEEEBD66A6F3} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Brak pliku <==== UWAGA Task: {8F872F96-2B32-4F3E-A333-154126B41B0D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA Task: {A47DF0C8-B288-48ED-90D7-B58E27952484} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA Task: {A9BBBA97-E77E-4CA5-B889-8BE5CFF3F285} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA Task: {AF99F5ED-6800-4A85-AA03-962E7FD76561} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA Task: {B0691DA6-B035-4F43-B763-15FD3BEEBE51} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Brak pliku <==== UWAGA Task: {B2D67AC1-9B55-4452-9127-52E6247CEFA6} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA Task: {B5EB6A74-E556-4B3F-9265-4263D7222CF3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA Task: {CC4C07CF-227A-4B92-A1C5-11DE645738DB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA Task: {EF4574FE-B100-42FD-8A9D-F0907B80323B} - \Microsoft\Windows\Setup\EOONotify -> Brak pliku <==== UWAGA Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asystent aktualizacji do systemu Windows 10.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asystent uaktualnienia do systemu Windows 10.lnk -> C:\Windows10Upgrade\Windows10UpgraderApp.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care.lnk -> C:\Program Files\Sony\VAIO Care\VAIOCare.exe (Brak pliku) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care\VAIO Care.lnk -> C:\Program Files\Sony\VAIO Care\VAIOCare.exe (Brak pliku) Shortcut: C:\Users\Weronika\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence\ByteFence Anti-Malware.lnk -> C:\Program Files\ByteFence\ByteFence.exe (Brak pliku) InternetURL: C:\Users\Weronika\Favorites\Sony-Recommended Sites\McAfee Store.url -> URL: hxxp://uk.mcafee.com/root/campaign.asp?cid=42372 Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} EmptyTemp: