CloseProcesses:
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => -> Brak pliku
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4100255193-85970089-1516296512-1001 -> DefaultScope {60094293-A583-407B-8350-CF1ECD5E9E01} URL =
hxxp://www.bing.com/search?q={searchTerms}&form=BIE9DF&pc=BIE9&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4100255193-85970089-1516296512-1001 -> {60094293-A583-407B-8350-CF1ECD5E9E01} URL =
hxxp://www.bing.com/search?q={searchTerms}&form=BIE9DF&pc=BIE9&src=IE-SearchBox
S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 iMSPQMn; \??\C:\Users\Radziu\AppData\Local\Temp\iMSPQMn.sys [X] <==== UWAGA
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
Shortcut: C:\Users\Agata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk -> C:\Users\Kamilaa\AppData\Roaming\HPReyos\ReyosStarter3.exe (Brak pliku) <===== Cyrillic
Shortcut: C:\Users\Agata\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnеt Ехрlоrеr (Nо Аdd-оns).lnk -> C:\Users\Kamilaa\AppData\Roaming\HPReyos\ReyosStarter3.exe (Brak pliku) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Users\Kamilaa\AppData\Roaming\HPReyos\ReyosStarter3.exe (Brak pliku) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk -> C:\Users\Kamilaa\AppData\Roaming\HPReyos\ReyosStarter3.exe (Brak pliku) <===== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ореrа.lnk -> C:\Users\Kamilaa\AppData\Roaming\HPReyos\ReyosStarter3.exe (Brak pliku) <===== Cyrillic
AlternateDataStreams: C:\ProgramData\TEMP:A1EDB939 [121]
AlternateDataStreams: C:\Users\Radziu\Desktop\5d4d87f62c0441e0742cea11f2e85843.mp4:TOC.WMV [130]
AlternateDataStreams: C:\Users\Radziu\Desktop\851bdc249138d85b2ab85975f7586fe9.mp4:TOC.WMV [130]
AlternateDataStreams: C:\Users\Radziu\Downloads\Cash Cash - Overtime.mp3:TOC.WMV [130]
AlternateDataStreams: C:\Users\Radziu\Downloads\DuckSense Intro - 20.mp4:TOC.WMV [130]
EmptyTemp: