CreateRestorePoint: CloseProcesses: EmptyTemp: File: C:\Users\Łukasz\AppData\Roaming\.dllbackups\data\modules\dll-host\downloads\xmrig-cpu\xmrig.exe File: C:\Users\Łukasz\AppData\Roaming\.dllbackups\dllruntime.exe (www.xmrig.com) [Brak podpisu cyfrowego] C:\Users\Łukasz\AppData\Roaming\.dllbackups\data\modules\dll-host\downloads\xmrig-cpu\xmrig.exe HKLM\...\Run: [HotKeysCmds] => "C:\WINDOWS\system32\hkcmd.exe" (Brak pliku) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-522389376-2815821715-2955199978-1001\...\Run: [electron.app.dllservices] => C:\Users\Łukasz\AppData\Roaming\.dllbackups\dllruntime.exe [63924677 2021-12-14] (Microsoft Corporation) [Brak podpisu cyfrowego] Tcpip\..\Interfaces\{25a3b0ff-e7f3-452c-ac3c-1d9254f292ec}: [DhcpNameServer] 87.204.204.204 62.233.233.233 Tcpip\..\Interfaces\{3ad44536-100e-44e5-82fd-c709d70766fc}: [DhcpNameServer] 192.168.0.1 2021-12-14 12:43 - 2021-12-15 19:26 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\dll-propagation 2021-12-14 12:38 - 2021-12-15 15:32 - 000000000 ____D C:\Users\Łukasz\AppData\Roaming\dllservices 2021-12-14 12:38 - 2021-12-14 14:09 - 000000000 ___HD C:\Users\Łukasz\AppData\Roaming\.dllbackups AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]