CreateRestorePoint: CloseProcesses: EmptyTemp: HKLM-x32\...\Run: [] => [X] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\Run: [BingSvc] => C:\Users\Kinga\AppData\Local\Microsoft\BingSvc\BingSvc.exe [146312 2020-08-15] (Microsoft Corporation -> © 2015 Microsoft Corporation) HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {1ac24e78-c3a4-11e5-827b-d0534904f46e} - "F:\Startme.exe" HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {5e17970d-f79b-11e6-82a2-d0534904f46e} - "F:\Lenovo_Suite.exe" HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {5f1f1549-3c02-11e9-832c-d0534904f46e} - "G:\autorun.exe" HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {63dc8654-a044-11e5-826e-d0534904f46e} - "F:\LaunchU3.exe" -a HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {8f8a8421-13e1-11e7-82ac-d0534904f46e} - "F:\AutoRun.exe" HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {a91aac31-5b69-11e7-82bb-d0534904f46e} - "F:\Startme.exe" HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\MountPoints2: {e1a427b2-ef88-11e5-8289-d0534904f46e} - "F:\windows\Install\Install.exe" HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA Task: {35C815C0-7A45-44DD-A2F8-24B7E955A19B} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [265640 2015-10-27] (Maxthon (Asia) Limited. -> Maxthon International ltd.) Task: {9CFBE55F-3930-44A4-9C1D-7D147C73C0D1} - System32\Tasks\{584C4397-9485-40E9-BC15-8CF62E190185} => C:\WINDOWS\system32\pcalua.exe -a "c:\program files\bytefence\ByteFence.exe" -c /uninstall Task: {C4783416-0889-4214-9DF0-1D0D9BD6F1FD} - System32\Tasks\Opera scheduled Autoupdate 1500236537 => C:\Users\Kinga\AppData\Local\Programs\Opera\launcher.exe Tcpip\..\Interfaces\{297C7A39-0304-474E-BE1D-56037EAD3AFB}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{5B992D92-8491-40CE-8CA0-D38F9F034476}: [DhcpNameServer] 192.168.1.1 192.168.2.1 Tcpip\..\Interfaces\{A6024219-026A-4ADF-8E59-FE9C13FB1433}: [DhcpNameServer] 192.168.10.10 192.168.1.1 Tcpip\..\Interfaces\{C9F15921-1D3F-4E4B-A989-C1C083642832}: [NameServer] 213.158.199.1 213.158.199.5 FF Extension: (Bing Search) - C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\3rv5dspa.default\Extensions\bingsearch.full@microsoft.com.xpi [2015-12-27] [Przestarzałe] FF Extension: (Brak nazwy) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [nie znaleziono] FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\3rv5dspa.default\extensions\defsearchp@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\3rv5dspa.default\extensions\deskCutv2@gmail.com => nie znaleziono FF HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\...\Firefox\Extensions: [KVAllmytube@KeepVid.com] - C:\Program Files (x86)\Keepvid\KeepVid Pro (Desktop)\BrowserPlugin\kvallmytube@keepvid.com_xpi => nie znaleziono R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1880864 2018-02-16] (Maxthon (Asia) Limited. -> Maxthon) S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [80920 2015-07-02] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, Inc.) S3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [529080 2015-06-28] (McAfee, Inc. -> McAfee, Inc.) S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [109728 2015-06-28] (McAfee, Inc. -> McAfee, Inc.) S1 wfdrvr_vw_1_10_0_28; system32\drivers\wfdrvr_vw_1_10_0_28.sys [X] 2021-01-08 00:09 - 2017-07-16 21:22 - 000004106 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1500236537 ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=SL5M&ocid=SL5MDHP&osmkt=pl-pl HKU\S-1-5-21-3074636978-2418565961-1654846339-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3074636978-2418565961-1654846339-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms} SearchScopes: HKU\S-1-5-21-3074636978-2418565961-1654846339-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms} SearchScopes: HKU\S-1-5-21-3074636978-2418565961-1654846339-1001 -> {43A4BBA9-A55B-4735-BC00-6220F37DCE50} URL = SearchScopes: HKU\S-1-5-21-3074636978-2418565961-1654846339-1001 -> {9f7967c1-7f73-4306-a03c-e96772657105} URL = hxxp://globallysearch.com?q={searchTerms}&srcid=100_FF&src=pt_1_y17w28 Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - Brak pliku Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - Brak pliku StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1446573686&z=c1fe8bbf99624f2abf20f9agbz3z4qaw4mec1z3g8z&from=cor&uid=KINGSTONXSV300S37A120G_50026B725800A4D6