HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-10-31] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-10-31] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-2494090995-947898825-4045838511-1003\...\Run: [MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3891624 2022-10-29] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2494090995-947898825-4045838511-1003\...\Run: [GoogleChromeAutoLaunch_A5B343D047FD8BD2F268B0EA0F8DBD7C] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [3217176 2022-10-26] (Google LLC -> Google LLC) Lsa: [Notification Packages] scecli "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" Task: {241DE746-00E5-48F9-9AF1-C988CE3C0D89} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File) Task: {3700C63B-5EB8-4B85-A280-FE8B7D257EC9} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe -pscn 0 (No File) Task: {3755493B-8642-4A68-AF9F-F787ACB752D5} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe /RestartRecording (No File) Task: {3B78CDC3-2C96-46D7-837A-E9C96BC2D4CB} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2287472 2022-05-24] (AVG Technologies USA, LLC -> AVG Technologies) Task: {45DC34F0-04C3-4B74-9CD4-5D0C4FC2B5A6} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File) Task: {7571DF58-458F-4222-A0B1-CBE2C1C7A4B4} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File) Task: {79D63C81-35B2-46A3-9B77-6770925A1C7D} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File) Task: {8046BC1F-E1F8-4A48-B9E7-41E45AA2D3AD} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File) Task: {858A0D97-E482-465D-888D-B999EDC10D68} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe /PBDADiscovery (No File) Task: {90A3DA29-6DCE-4AB1-BB6B-AA178F8A06DF} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe /DRMInit (No File) Task: {94190FDA-B410-4BCE-ACD0-8CB85A6E0F04} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe -crl -hms -pscn 15 (No File) Task: {98C88774-C977-4AA0-A1BC-B8A5D201D64C} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe $(Arg0) (No File) Task: {9DFB6922-93F2-4644-B773-F5655BB2A0F6} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe /OCURActivate (No File) Task: {A060F7BD-C8B0-44CF-A9FC-395D00C727E2} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {A21DA9C6-2ECC-4B36-8A71-60009A9632C5} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe -PvrSchedule (No File) Task: {A38731AE-0347-4979-AE17-9530C898BE7D} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File) Task: {B4961E1B-F09D-47E4-9068-F94596A60F53} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File) Task: {B957A03C-659E-405A-A771-48787F7135E9} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File) Task: {BC44CE4E-8493-4630-9BC3-06BBA86B706F} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -PvrRecoveryTask (No File) Task: {C6DBF053-00DC-4791-9111-7666AF62D189} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File) Task: {CB531407-13FF-442C-B5D6-EC8E8CB7DE1A} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File) Task: {D742D6BF-24AC-40CC-B792-BB9AC755EF65} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File) Task: {E054FEAA-99C0-4997-9BEB-58B2BD6D5D7E} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File) Task: {E332D4E4-D60E-4362-B31B-A17C38E77B27} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File FirewallRules: [{51DDEE1E-22B2-4D85-8D06-48ED181D0720}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe => No File FirewallRules: [{B7FBF0DF-FA7E-4F78-AAA0-E1002B119398}] => (Allow) E:\Network\EpsonNetSetup\ENEasyApp.exe => No File FirewallRules: [{8A46E546-8071-438B-ACB0-C3EA746974E9}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe => No File FirewallRules: [{0C286CAD-1205-442D-B0BB-FFF717E716CF}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe => No File FirewallRules: [{3BDC4358-789A-4D3D-8EE7-51636159FF50}] => (Allow) C:\Program Files\PreSonus\Studio One 3\Studio One.exe => No File FirewallRules: [{C4265F33-FC3D-4288-9D2F-D0CFA046C2D4}] => (Allow) C:\Program Files (x86)\Dell\Dell Printer Manager\uninstall.exe => No File FirewallRules: [{1647560B-AE52-4A98-B9B5-4099F72BF5A2}] => (Allow) C:\Program Files (x86)\Dell\Dell Printer Manager\uninstall.exe => No File FirewallRules: [{F291C2B2-3437-490D-BBFC-956C51E065D2}] => (Allow) C:\Program Files (x86)\Dell\Dell B1160w Mono Laser Printer\TORDER\uninstall.exe => No File FirewallRules: [{5FC54622-E36B-4C3E-88ED-3855D9232B5A}] => (Allow) C:\Program Files (x86)\Dell\Dell B1160w Mono Laser Printer\TORDER\uninstall.exe => No File FirewallRules: [{3AD2B4F6-8713-485C-90C9-9FCDE91A1EFA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe => No File FirewallRules: [{87C22761-FE5C-4347-ACFE-E2B71B09D3FA}] => (Allow) C:\Program Files\PreSonus\Studio One 3\Studio One.exe => No File FirewallRules: [{450D4299-B455-4B7F-924E-A738C871E9A4}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe => No File FirewallRules: [{6A419DF9-5A6A-435F-BEF2-DE53CBA4B70F}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe => No File FirewallRules: [{BBEB3DA7-CC67-41E6-99FF-4DD192D70F89}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe => No File FirewallRules: [{0AAC38FC-9084-4CEF-87EF-38E70871593A}] => (Allow) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService\BASupSrvc.exe (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) FirewallRules: [{1B582306-1A03-4580-A736-979B40D46A80}] => (Allow) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService\BASupSrvc.exe (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) C:\Program Files (x86)\AVG CMD: DISM /Online /Cleanup-Image /RestoreHealth CMD: SFC /scannow CMD: findstr /c:"[SR]" \windows\logs\cbs\cbs.log CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" Reboot: