CreateRestorePoint: CloseProcesses: EmptyTemp: Startup: C:\Users\pklim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk [2020-12-21] ShortcutTarget: Wysyłanie do programu OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation) GroupPolicy: Ograniczenia ? <==== UWAGA Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA Task: {0670272D-660C-4D4D-86D7-934D8FE36B5D} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {16675452-2480-4DA7-9081-2B9978191574} - System32\Tasks\Driver Booster SkipUAC (pklim) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe [7228176 2019-02-22] (IObit Information Technology -> IObit) Task: {18BD09FD-0C9D-467F-BBD1-A315349A5319} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {2212CECB-C351-488D-AC81-2DD8F99B11EE} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {29BAEC77-F56D-4A8E-98D3-637B05BCF26F} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {2DABA7DF-1573-4A81-85BB-1E4ED800AF16} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {31E02476-C646-4D8C-B4A6-552C2914DF4E} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {3AE62618-0817-4DCD-A679-A4E425B8BEB5} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {40C8778B-13BC-4426-9DC3-4E1D517D69E4} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {43238E24-3668-4D4B-9605-C278C2DD06EE} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {4A0CE33E-689C-45EE-A04D-AC469004682A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {6E1D8894-4023-4F40-85CE-57CED082E0E9} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {75BD41CB-DE90-4042-B477-D76813421D9C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {78B02FD3-52AE-49B0-9B70-83B2779C810E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {852CA464-7BA3-4F59-A486-E056A849D480} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {8A0ED08A-972A-486F-8D54-B5B4D90570A4} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe [79360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {916CD85F-8475-42B7-8400-7408D4A0963C} - System32\Tasks\Driver Booster SkipUAC (Przemysław) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe [7228176 2019-02-22] (IObit Information Technology -> IObit) Task: {91D90850-FFD6-4987-B47E-124DBC22D848} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {956CD04C-3957-4888-8AF5-57841419CEAD} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B0D20B3D-FE40-44D3-A271-CC5C22C05C09} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {B91B0128-C996-46D6-A626-C3C0A28D4552} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\Scheduler.exe [149776 2018-12-28] (IObit Information Technology -> IObit) Task: {C282F938-5828-4DFB-AD79-21BC794A8DD4} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {C48E9EE8-A1D0-4202-B17E-691E250A232A} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA Task: {D9712963-3BB7-4153-8A70-FF1182D063B1} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {EC120064-08F5-45A4-AD83-964F488463FA} - System32\Tasks\{43497522-DD41-47AC-A60E-B3EBDDA9AAB9} => C:\windows\system32\pcalua.exe -a E:\Nokia_Care_Suite_eng_web.exe -d E:\ Task: {F2226F4E-68F7-4520-9219-080C33E4281E} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe [271360 2015-09-05] (Microsoft Corporation) [Brak podpisu cyfrowego] Task: {F58ADDF9-B7C6-40B5-BD78-D3B071E6F595} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ProxyServer: [S-1-5-21-1978625630-1779754910-779616976-1001] => 192.168.49.1:8282 Tcpip\..\Interfaces\{375e99f4-5d1c-420c-88cb-eee0b4ee0055}: [DhcpNameServer] 37.8.214.2 31.11.202.254 Tcpip\..\Interfaces\{9a93cdfb-562a-46c5-93ae-a8badc0f93c8}: [DhcpNameServer] 37.8.214.2 31.11.202.254 Tcpip\..\Interfaces\{d596aa67-1f11-49d0-8dd6-ba04ae3db8ea}: [DhcpNameServer] 37.8.214.2 31.11.202.254 Tcpip\..\Interfaces\{d750855f-50cb-4fd9-98df-2d0745e7ece0}: [DhcpNameServer] 37.8.214.2 31.11.202.254 S2 MBAMInstallerService; C:\Users\pklim\AppData\Local\Temp\MBAMInstallerService.exe [6716872 2020-12-21] (Malwarebytes Inc -> Malwarebytes) <==== UWAGA CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{02F7DBAC-D436-4031-9ED7-E607DC57E6AF}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{2F9C3D44-6031-409A-A7DF-D8094E8EE214}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{46406D82-6EC0-47CC-8A75-1F33C6DEDBBE}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.35.442\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{540C17A8-04F2-4B66-95D7-B2FEF9A19B54}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.35.422\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{62634D95-960B-4834-8E71-A70408AD8FD9}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.34.7\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{6D264B70-DA18-401D-910C-B202D89670C6}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.36.32\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{84EB3779-151B-4C71-AEF0-A0FEE9481401}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.35.342\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{86508D42-E5D7-4D10-9C6F-D427AEEB85B5}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.34.11\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{8A589AFF-8DA8-49C5-B89B-20C9DF31F2B7}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.30.5\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{8CE51F0E-104A-4093-AA07-731C8F767B16}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{91A36EBD-7C85-44AF-92DC-0F32A900D0E3}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{9fe1e934-79dd-2a7a-b9c8-0409ac9d11957}\InprocServer32 -> 0xB8BFD110149DD3015D43439FFD12D501020000002F00000000000000 => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{A804CF1A-91E5-4F0C-9E8C-DB39E74056DD}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{C3720501-8085-416B-ACBD-297FE7D740B0}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{DBFB5768-408F-40A7-A292-178DD06896C9}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{DE236A7F-CC47-4818-A30F-42BE1946F6D5}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.35.452\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{EEAB6A34-3912-4381-A805-1032E3BAE2E5}\InprocServer32 -> C:\Users\pklim\AppData\Local\JetBrains\Installations\ReSharperPlatformVs15_0869ebdc\x64\JetBrains.Profiler.Windows.Core.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1978625630-1779754910-779616976-1001_Classes\CLSID\{EF076C91-DC9E-43E3-84ED-3D219E065A4F}\InprocServer32 -> C:\Users\pklim\AppData\Local\Google\Update\1.3.35.302\psuser_64.dll => Brak pliku ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll -> Brak pliku ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll -> Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll -> Brak pliku SearchScopes: HKU\S-1-5-21-1978625630-1779754910-779616976-1001 -> {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&s=RfgZpW1wbK1YYCZFK7Z5vfTQh4I?q={searchTerms} SearchScopes: HKU\S-1-5-21-1978625630-1779754910-779616976-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={BD496446-F5AA-4717-864F-7EC4FC3E40AB}&mid=7c9393364cf747cc8d9d2d0d2a13658e-faa664b0eceb007708849ac5c01c450f974bc5df&lang=pl&ds=AVG&coid=avgtbavg&cmpid=ZenTest_B_0&pr=fr&d=2016-12-11 09:21:02&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms} BHO: Brak nazwy -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> Brak pliku BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2021-01-27] (McAfee, LLC -> McAfee, LLC) BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2021-01-27] (McAfee, LLC -> McAfee, LLC) DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} RemoveProxy: Hosts: