CloseProcesses: CreateRestorePoint: EmptyTemp: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-1339903630-2656126393-1155978586-1000\...\MountPoints2: E - E:\HiSuiteDownLoader.exe HKU\S-1-5-21-1339903630-2656126393-1155978586-1000\...\MountPoints2: {f051b52b-1113-11e9-8940-9cad972272de} - E:\HiSuiteDownLoader.exe FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA Task: {BB6FB3A5-2801-4B00-8A4F-7534690BAAE9} - System32\Tasks\{9N18UZO2-QD0H-AJQ0-2POF-HS3HV8ESF36S} => explorer "hxxp://porilman.com/cl/?guid=keye8s5vttwawxhhv14oe4hhm408f51b&prid=1&pid=11_1415_0" <==== UWAGA Task: C:\Windows\Tasks\{9N18UZO2-QD0H-AJQ0-2POF-HS3HV8ESF36S}.job => explorerUhttp /porilman com cl/?guid keye8s5vttwawxhhv14oe4hhm408f51b prid pid 11_1415_0BasiaThis is comment00 Tcpip\..\Interfaces\{97BAC49D-721D-4FB0-8321-954F84FA4A10}: [DhcpNameServer] 8.8.8.8 8.8.4.4 HKU\S-1-5-21-1339903630-2656126393-1155978586-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYpEu3RR10aNOov0OBbF6Alkhr91RAlBeG6DYbttreUGjhmuOflF0SOHy8Cr0ghztkXbKdlyf2OCbg-YTIf0FDFsz661kWIfvASpGSJVktLIMZZ9sFf4u6S4k7oMeiTmrWhsUYPm_7jhFx73Jqq6XhVSpwRxA,,&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope - brak wartości FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku] StartMenuInternet: Firefox-2C61A631E9098E2D - C:\Users\Basia\AppData\Local\Mozilla Firefox\firefox.exe FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\autoconfig.js [2019-05-04] <==== UWAGA (Linkuje do pliku *.cfg) FF ExtraCheck: C:\Program Files\mozilla firefox\mozilla.cfg [2019-05-04] <==== UWAGA CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx S3 SmbDrvI; system32\DRIVERS\Smb_driver_Intel.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] 2019-07-04 20:33 - 2019-05-04 13:48 - 000000378 _____ C:\Windows\Tasks\{9N18UZO2-QD0H-AJQ0-2POF-HS3HV8ESF36S}.job 2019-06-20 23:02 - 2019-05-04 13:48 - 000003378 _____ C:\Windows\System32\Tasks\{9N18UZO2-QD0H-AJQ0-2POF-HS3HV8ESF36S} 2019-05-04 13:56 - 2019-05-04 14:07 - 000000004 _____ () C:\ProgramData\lock.dat 2019-05-04 13:56 - 2019-05-04 13:56 - 000000008 _____ () C:\ProgramData\ts.dat 2019-05-04 13:41 - 2019-05-04 13:41 - 007931392 _____ () C:\Users\Basia\AppData\Local\agent.dat 2019-05-04 13:41 - 2019-05-04 13:41 - 000054272 _____ () C:\Users\Basia\AppData\Local\ApplicationHosting.dat 2018-08-29 14:57 - 2019-07-04 21:20 - 001734163 _____ () C:\Users\Basia\AppData\Local\BTServer.log 2019-05-04 13:41 - 2019-05-04 13:41 - 000070992 _____ () C:\Users\Basia\AppData\Local\Config.xml 2019-05-04 13:41 - 2019-05-04 13:41 - 000140800 _____ () C:\Users\Basia\AppData\Local\installer.dat 2019-05-04 13:41 - 2019-05-04 13:41 - 000126464 _____ () C:\Users\Basia\AppData\Local\lobby.dat 2019-05-04 13:41 - 2019-05-04 13:41 - 000005568 _____ () C:\Users\Basia\AppData\Local\md.xml 2019-05-04 13:41 - 2019-05-04 13:41 - 000126464 _____ () C:\Users\Basia\AppData\Local\noah.dat 2019-05-04 13:41 - 2019-05-04 13:41 - 002038132 _____ () C:\Users\Basia\AppData\Local\Sailstock.tst 2019-05-04 13:41 - 2019-05-04 13:41 - 000722944 _____ () C:\Users\Basia\AppData\Local\sha.db 2019-05-04 13:41 - 2019-05-04 13:41 - 000072787 _____ () C:\Users\Basia\AppData\Local\Tanhome.tst 2019-05-04 13:41 - 2019-05-04 13:41 - 000032038 _____ () C:\Users\Basia\AppData\Local\uninstall_temp.ico ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Chrоmе.lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnet Explоrеr Вrоwser.lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firеfох.lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Gоogle Сhromе.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firеfох.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intеrnet Еxplоrer.lnk AlternateDataStreams: C:\ProgramData\TEMP:430C6D84 [127] AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [105] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firеfох.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intеrnet Еxplоrer.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrer (Nо Аdd-оns).lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Chrоmе.lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnet Explоrеr Вrоwser.lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firеfох.lnk C:\Users\Basia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Gоogle Сhromе.lnk Hosts: RemoveProxy: