CloseProcesses: CreateRestorePoint: EmptyTemp: HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA Task: {F4A698DE-6362-43AC-ABA3-D91D10AC64A4} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_krzysztof.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe Task: {1576E01C-3D49-4E12-8F51-3B7F08C9ED2C} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe Tcpip\..\Interfaces\{60f8b413-9585-46ff-a250-0b71290c88a5}: [DhcpNameServer] 192.168.2.1 C:\WINDOWS\system32\Drivers\asw*.tmp CHR Profile: C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default [2021-04-11] CHR HomePage: Default -> hxxp://www.google.pl/ CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Extension: (Prezentacje) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-21] CHR Extension: (Dokumenty) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-21] CHR Extension: (Dysk Google) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-02] CHR Extension: (YouTube) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-21] CHR Extension: (Muzyka Google Play) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2021-04-08] CHR Extension: (Arkusze) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-21] CHR Extension: (Dokumenty Google offline) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-08] CHR Extension: (Web Scrobbler) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhinaapppaileiechjoiifaancjggfjm [2021-04-08] CHR Extension: (BrowserStack Local) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfiddfehmfdojjfdpfngagldgaaafcfo [2020-02-25] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-08] CHR Extension: (Gmail) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-03-14] CHR Extension: (Chrome Media Router) - C:\Users\cole8\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-08] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} CustomCLSID: HKU\S-1-5-21-1257285104-4154543642-1035547870-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> F:\Program Files\Autodesk\3ds Max 2022\Inventor Server\Bin\TestServer.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1257285104-4154543642-1035547870-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> F:\Program Files\Autodesk\3ds Max 2022\Inventor Server\Bin\TestServer.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1257285104-4154543642-1035547870-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> F:\Program Files\Autodesk\3ds Max 2022\Inventor Server\Bin\TestServer.dll => Brak pliku AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] FirewallRules: [{DAC0E22B-F5B9-403C-8EE3-84BF8A494BED}] => (Allow) LPort=2869 FirewallRules: [{6122846E-CABF-4ADF-9677-7F6B562F8EBB}] => (Allow) LPort=1900 FirewallRules: [{4DA12BCA-DD26-4554-B4C1-8BD4F1197650}] => (Allow) C:0\Program Files (x86)\Steam\SteamApps\common\RailWorks\RailWorks64.exe => Brak pliku FirewallRules: [{51B1C50B-6F6F-4462-816F-F119494E7F4B}] => (Allow) C:0\Program Files (x86)\Steam\SteamApps\common\RailWorks\RailWorks64.exe => Brak pliku FirewallRules: [{6FC1E444-703E-46B0-9445-0CA63D3B0DF8}] => (Allow) C:0\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => Brak pliku FirewallRules: [{47E385EF-3ABF-4E96-8CF4-1F701B25FC4F}] => (Allow) C:0\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => Brak pliku FirewallRules: [{89962C4C-C9E1-44AE-8AE3-048F259BDCBB}] => (Block) F:\Program Files\GRAPHISOFT\ARCHICAD 20 v2\\CineRender\CineRender 64bit.exe => Brak pliku DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server C:\USERS\COLE8\APPDATA\LOCAL\GOOGLE\CHROME RemoveProxy: Hosts: