CloseProcesses: CreateRestorePoint: EmptyTemp: Tcpip\..\Interfaces\{09C15CB7-8E91-4370-B7D8-F26BDE94D745}: [DhcpNameServer] 185.170.226.34 185.170.226.2 CHR HomePage: Default -> hxxp://www.gazeta.pl/0,0.html?p=190 CHR StartupUrls: Default -> "hxxp://www.gazeta.pl/0,0.html?p=190" CHR Extension: (d8yI+Hf7rX) - C:\Users\Kondi\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\fagdgogbckdojokbbpbkefgcnhppcjlk [2020-09-13] OPR Extension: (book_helper) - C:\Users\Kondi\AppData\Roaming\Opera Software\Opera Stable\Extensions\fagdgogbckdojokbbpbkefgcnhppcjlk [2020-09-13] C:\Users\Kondi\AppData\Roaming\Opera Software\Opera Stable\Extensions\fagdgogbckdojokbbpbkefgcnhppcjlk C:\Users\Kondi\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\fagdgogbckdojokbbpbkefgcnhppcjlk 2020-09-14 22:10 - 2020-09-15 19:21 - 000000008 __RSH C:\ProgramData\ntuser.pol 2020-09-14 22:10 - 2020-09-15 18:55 - 000000008 __RSH C:\Users\Kondi\ntuser.pol File: C:\Windows\system32\dllhost.exe DomainProfile\AuthorizedApplications: [D:\Program Files\Gry.!\Valofe\CombatArms\CombatArms.exe] => Enabled:CombatArms.exe DomainProfile\AuthorizedApplications: [D:\Program Files\Gry.!\Valofe\CombatArms\Engine.exe] => Enabled:Engine.exe DomainProfile\AuthorizedApplications: [D:\Program Files\Gry.!\Valofe\CombatArms\NMService.exe] => Enabled:NMService.exe StandardProfile\AuthorizedApplications: [D:\Program Files\Gry.!\Valofe\CombatArms\CombatArms.exe] => Enabled:CombatArms.exe StandardProfile\AuthorizedApplications: [D:\Program Files\Gry.!\Valofe\CombatArms\Engine.exe] => Enabled:Engine.exe StandardProfile\AuthorizedApplications: [D:\Program Files\Gry.!\Valofe\CombatArms\NMService.exe] => Enabled:NMService.exe RemoveProxy: Hosts: