CloseProcesses: CreateRestorePoint: EmptyTemp: HKU\S-1-5-21-2034617936-65545164-3351714256-1001\...\Run: [bidiCore] => rundll32 "C:\Users\salon\AppData\Roaming\Microsoft\ApphdWSD\bootrvps.dll",DllRegisterServer HKU\S-1-5-21-2034617936-65545164-3351714256-1001\...\Run: [APHotenc] => rundll32 "C:\Users\salon\AppData\Roaming\Microsoft\AcWiedDS\AppIpapi.dll",DllRegisterServer Tcpip\..\Interfaces\{391DD243-80DE-4E84-9894-99331D26A287}: [DhcpNameServer] 192.168.15.1 62.233.233.233 87.204.204.204 Tcpip\..\Interfaces\{F6D5B1D9-25FE-4B71-9E24-0847F87BB484}: [DhcpNameServer] 192.168.81.1 URLSearchHook: [S-1-5-21-2034617936-65545164-3351714256-1000] UWAGA => Brak domyślnego URLSearchHook SearchScopes: HKU\S-1-5-21-2034617936-65545164-3351714256-1001 -> {FAC6CA01-F74E-48C2-9045-F09168A13765} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} cmd: reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" cmd: reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices" cmd: reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce" cmd: reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" cmd: reg query "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" cmd: reg query "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce" cmd: reg query "HKCU\Software\Classes\mssccfile" cmd: reg query "HKCU\Software\Classes" /v "mssccfile" cmd: reg query "HKLM\Software\Classes\mssccfile" cmd: reg query "HKLM\Software\Classes" /v "mssccfile"