CloseProcesses: CreateRestorePoint: EmptyTemp: HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: F - F:\SETUP.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: G - G:\_AUTORUN\AUTORUN.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: H - H:\SETUP.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: I - I:\SETUP.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {04f1e910-83e3-11e6-9258-4061861e42d2} - H:\SETUP.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {04f1e913-83e3-11e6-9258-4061861e42d2} - I:\SETUP.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {0f6e1f0d-f976-11e5-91e5-4061861e42d2} - F:\setup.exe HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {9b1ded1c-5b9b-11e5-abc1-4061861e42d2} - G:\_AUTORUN\AUTORUN.EXE HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {e3d6c09e-0cd1-11e8-bcdc-4061861e42d2} - F:\HiSuiteDownLoader.exe HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {e3d6c0c3-0cd1-11e8-bcdc-4061861e42d2} - F:\HiSuiteDownLoader.exe HKU\S-1-5-21-3197927303-3268197940-2276980429-1000\...\MountPoints2: {e3d6c0d1-0cd1-11e8-bcdc-4061861e42d2} - F:\HiSuiteDownLoader.exe Tcpip\..\Interfaces\{E4F8C661-55EB-423A-AB1C-7ADC757F72FA}: [DhcpNameServer] 192.168.0.1 SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKU\S-1-5-21-3197927303-3268197940-2276980429-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://www.google.com/search?q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Brak pliku] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft -> Alcohol Soft Development Team) S2 MxService; C:\Program Files (x86)\Maxthon\Bin\MxService.exe [X] CustomCLSID: HKU\S-1-5-21-3197927303-3268197940-2276980429-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-3197927303-3268197940-2276980429-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-3197927303-3268197940-2276980429-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-3197927303-3268197940-2276980429-1000_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\MSI\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll => Brak pliku ContextMenuHandlers2-x32: [AlcoholShellEx] -> {32020A01-506E-484D-A2A8-BE3CF17601C3} => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxShlex.dll [2014-09-06] (Alcohol Soft -> Alcohol Soft Development Team) ContextMenuHandlers2-x32: [AlcoholShellEx64] -> {AF67B665-D752-424E-9A03-C7C218F2844F} => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxShlEx64.dll [2014-09-06] (Alcohol Soft -> Alcohol Soft Development Team) ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Brak pliku ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Brak pliku ContextMenuHandlers1_S-1-5-21-3197927303-3268197940-2276980429-1000: [GGDriveMenu] -> {E68D0A55-3C40-4712-B90D-DCFA93FF2534} => C:\Users\MSI\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll -> Brak pliku ContextMenuHandlers4_S-1-5-21-3197927303-3268197940-2276980429-1000: [GGDriveMenu] -> {E68D0A55-3C40-4712-B90D-DCFA93FF2534} => C:\Users\MSI\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll -> Brak pliku ContextMenuHandlers5_S-1-5-21-3197927303-3268197940-2276980429-1000: [GGDriveMenu] -> {E68D0A55-3C40-4712-B90D-DCFA93FF2534} => C:\Users\MSI\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll -> Brak pliku Task: {32E00E47-D78C-41E2-916F-F3BB19BC00E0} - System32\Tasks\{5725557E-1105-4F2B-A486-48FB82A44464} => C:\Program Files\Rockstar Games\GTA San Andreas\samp.exe () [Brak podpisu cyfrowego] Task: {5BD35C31-6068-45D1-A74F-F85A99783860} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\MxEidolon.exe (Maxthon (Asia) Limited. -> Maxthon MxEidolo) Task: {7E70FA50-BB9C-4809-B0B1-AF5115CF6386} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) AlternateDataStreams: C:\ProgramData:NT [40] AlternateDataStreams: C:\ProgramData:NT2 [322] AlternateDataStreams: C:\Users\All Users:NT [40] AlternateDataStreams: C:\Users\All Users:NT2 [322] AlternateDataStreams: C:\ProgramData\Application Data:NT [40] AlternateDataStreams: C:\ProgramData\Application Data:NT2 [322] AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT [40] AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2 [322] AlternateDataStreams: C:\Users\MSI\Dane aplikacji:NT [40] AlternateDataStreams: C:\Users\MSI\Dane aplikacji:NT2 [322] AlternateDataStreams: C:\Users\MSI\AppData\Roaming:NT [40] AlternateDataStreams: C:\Users\MSI\AppData\Roaming:NT2 [322] FirewallRules: [TCP Query User{55E27E8A-7805-42DB-ADFD-C4C7AE628004}C:\users\msi\downloads\fifa 15\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe] => (Block) C:\users\msi\downloads\fifa 15\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe Brak pliku FirewallRules: [UDP Query User{93BAF2D5-28A1-49E3-9E11-91FDFD86FACA}C:\users\msi\downloads\fifa 15\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe] => (Block) C:\users\msi\downloads\fifa 15\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe Brak pliku FirewallRules: [TCP Query User{7A92A7BC-FFF9-4F28-BB3B-8666B102CAEF}C:\users\msi\downloads\fifa 14\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe] => (Block) C:\users\msi\downloads\fifa 14\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe Brak pliku FirewallRules: [UDP Query User{B8A2D35B-926E-48CC-B4D7-F908339F94BF}C:\users\msi\downloads\fifa 14\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe] => (Block) C:\users\msi\downloads\fifa 14\fifa 14 ultimate edition multi14-fullunlocked\fifa 14\game\fifa14.exe Brak pliku FirewallRules: [TCP Query User{4BF4DDE5-BFB0-4871-AF7F-0BBDC5D3A72C}C:\program files\rockstar games\proxy_sa.exe] => (Allow) C:\program files\rockstar games\proxy_sa.exe Brak pliku FirewallRules: [UDP Query User{A55A7BBF-B718-4336-9F71-1C2B51502E18}C:\program files\rockstar games\proxy_sa.exe] => (Allow) C:\program files\rockstar games\proxy_sa.exe Brak pliku FirewallRules: [TCP Query User{C806D6CC-2FD5-4078-8A1A-0517EDC089AF}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe Brak pliku FirewallRules: [UDP Query User{50B8D3B0-240C-4DA3-B018-AD3762A1ACA8}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe Brak pliku FirewallRules: [{6D304EE1-0E65-49F3-BA4A-8F27C01AE390}] => (Allow) LPort=2869 FirewallRules: [{59B8B199-0BA0-4C09-B6E2-06B4221339B8}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{B94DC176-3DE6-465C-ADCB-DC991FEF06BC}D:\left 4 dead\gra\left4dead.exe] => (Block) D:\left 4 dead\gra\left4dead.exe Brak pliku FirewallRules: [UDP Query User{FCBEE7CD-1952-482A-AF50-8A6D1FB36171}D:\left 4 dead\gra\left4dead.exe] => (Block) D:\left 4 dead\gra\left4dead.exe Brak pliku FirewallRules: [{2A4CE58B-3710-476C-AE2C-0F006B29C758}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) FirewallRules: [{5D67C67B-0ABA-4D01-8AA0-934AD7D68B3A}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) FirewallRules: [{C1034EDE-6053-4FE2-B6CF-875D5483F449}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) FirewallRules: [{3DBD5189-BB26-4263-9B9F-BF803BC14525}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) FirewallRules: [TCP Query User{3D36E1EE-896A-48A6-AD99-A3C8C9F904D6}C:\program files (x86)\vivid games s.a\real boxing\binaries\win32\realboxing.exe] => (Allow) C:\program files (x86)\vivid games s.a\real boxing\binaries\win32\realboxing.exe Brak pliku FirewallRules: [UDP Query User{834707AB-3D5A-4847-9177-8BBDC9364EE8}C:\program files (x86)\vivid games s.a\real boxing\binaries\win32\realboxing.exe] => (Allow) C:\program files (x86)\vivid games s.a\real boxing\binaries\win32\realboxing.exe Brak pliku FirewallRules: [TCP Query User{84F29780-8AEA-4384-9F02-B40D1E9C658F}D:\counter-strike 1.6 v48\hl.exe] => (Allow) D:\counter-strike 1.6 v48\hl.exe Brak pliku FirewallRules: [UDP Query User{21EAE789-F628-487B-B733-A528599BB664}D:\counter-strike 1.6 v48\hl.exe] => (Allow) D:\counter-strike 1.6 v48\hl.exe Brak pliku FirewallRules: [{84F7AF01-03DB-4C93-AB2F-12AB54716F5C}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) FirewallRules: [{118866D9-5CE4-477B-9978-64206D5FB94B}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.) FirewallRules: [{C61DCE6C-AC3C-49B7-8D28-058F31999620}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe Brak pliku FirewallRules: [{961E90C8-3ED0-43F5-9ECB-563344759B49}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe Brak pliku FirewallRules: [{241F9A51-5102-4984-B5B9-DF08B1B57D48}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe Brak pliku FirewallRules: [{17C7B125-3E45-46F9-B621-A015997D776F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe Brak pliku FirewallRules: [{A493DDA8-960C-4888-824C-EFC5DA03F96C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe Brak pliku FirewallRules: [{528AECE8-8441-4B88-A8CD-5C54C3B8D4F5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe Brak pliku FirewallRules: [{92A5EAB9-B1B2-4A34-9516-D23F5C7DC641}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe Brak pliku FirewallRules: [{6A1937BB-2001-4A15-90AB-680B76C15A7B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe Brak pliku FirewallRules: [{DADE4545-3242-468F-9EAE-8A372F087550}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe Brak pliku FirewallRules: [{09C018D6-628E-44EC-828D-115F29203FBA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe Brak pliku FirewallRules: [{E5DF6993-02D5-437C-A384-759877D4FE91}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe Brak pliku FirewallRules: [{7F510D50-59E2-4CE8-9B48-2DC5F72CEB6D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe Brak pliku FirewallRules: [{EB3814A0-EFAA-4EC3-96D2-0B935578BF83}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe Brak pliku FirewallRules: [{4D9A728C-3297-4C74-A625-6005D09B6FD8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe Brak pliku FirewallRules: [{8823E444-48A6-404D-9069-0F1F81E49920}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe Brak pliku FirewallRules: [{6B02E9E4-45DB-476E-ACFE-821017C5B8D9}] => (Allow) C:\Program Files (x86)\Sports Interactive\Football Manager 2011\fm.exe Brak pliku FirewallRules: [{42861305-F96C-42C1-AD93-98EDB4E11708}] => (Allow) C:\Program Files (x86)\Sports Interactive\Football Manager 2011\fm.exe Brak pliku RemoveProxy: HOSTS: