Odinstaluj:
VideoPerformer
Yontoo 1.10.02
Uzyj
https://www.bleepingcomputer.com/download/adwcleaner/
Zrob tez pelny skan przy pomocy mbam i usun to co wykryje:
https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
Wykonaj Fixlist.txt dla FRST:
CloseProcesses:
HKLM-x32\...\Run: [BCU] => C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [375000 2009-10-26] (DeviceVM Inc. -> DeviceVM, Inc.)
HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [353104 2017-12-22] (RealNetworks, Inc. -> RealNetworks, Inc.)
HKLM-x32\...\Run: [RealDownloader] => c:\program files (x86)\real\RealDownloader\downloader2.exe [1268048 2017-11-29] (RealNetworks, Inc. -> )
HKU\S-1-5-21-3737458919-2164987103-1403913886-1000\...\Run: [Google Update] => C:\Users\Darki\AppData\Local\Google\Update\1.3.34.11\GoogleUpdateCore.exe [410920 2019-05-17] (Google Inc -> Google LLC)
HKU\S-1-5-21-3737458919-2164987103-1403913886-1000\...\Run: [World of Tanks] => D:\World_of_Tanks\WargamingGameUpdater.exe [3139872 2018-01-05] (Wargaming PCL -> Wargaming.net)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2012-03-08]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2017-12-22]
ShortcutTarget: RealTimes.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc. -> RealNetworks, Inc.)
Startup: C:\Users\Darki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2011-12-11]
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () [File not signed]
GroupPolicy: Restriction - Chrome <==== ATTENTION
Task: {0DDD8205-B131-4AF6-AC19-4514A0DFB465} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {18564A58-FAE7-482A-A9BD-3670B0CC7E70} - System32\Tasks\ASUS\ASUS RegRun Loader => C:\Program Files (x86)\ASUS\AASP\1.01.02\AsLoader.exe [803968 2009-12-28] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {1FFEDAC3-B774-4F8A-9867-988CA812CDFF} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {25005552-E332-4B07-8A3F-4D4188671D4A} - System32\Tasks\ExtFixer21400 => C:\Windows\TEMP\44162_updater.exe <==== ATTENTION
Task: {27694C2A-D5E1-446B-9E48-0728E16BF378} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3737458919-2164987103-1403913886-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [122880 2017-11-29] (RealNetworks, Inc.) [File not signed]
Task: {2D753E18-812E-4C32-ADF0-DA465FD5627C} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Darki\Downloads\esetonlinescanner_enu.exe [7969304 2019-08-09] (ESET, spol. s r.o. -> ESET spol. s r.o.)
Task: {2EA494E9-99F8-448C-94B4-4F735C9121FD} - System32\Tasks\{CA9603AA-C6BE-4103-8203-29799A6E9F2D} => "c:\users\darki\appdata\local\google\chrome\application\chrome.exe"
hxxp://ui.skype.com/ui/0/7.6.85.105/pl/abandoninstall?page=tsProgressBar
Task: {39AE781E-FC81-4C32-80C5-DDA932C2FCF4} - System32\Tasks\SpeedyPC Registration3 => C:\Windows\system32\rundll32.exe "C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\UUS3.dll" RunUns <==== ATTENTION
Task: {3AA1A388-001A-4B6F-BA06-63B59152BB3B} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {43F46706-3A14-4376-9B1B-2FFCEFEAA551} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {464E5F92-7DB2-4791-86F3-CFC320D01393} - System32\Tasks\{A5811E73-4582-406E-8F35-75AEF20E2067} => C:\Windows\system32\pcalua.exe -a E:\HALF-L~1\HALF-L~1\UNWISE.EXE -c E:\HALF-L~1\HALF-L~1\INSTALL.LOG
Task: {4F57BBF8-0D0F-48F3-B0A1-8A8F8D9B6223} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {5137645A-3F67-46B4-AD92-25C8E4C64B77} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Darki\Downloads\esetonlinescanner_enu.exe [7969304 2019-08-09] (ESET, spol. s r.o. -> ESET spol. s r.o.)
Task: {5AE636E6-DB47-4A50-9242-029584B63D4C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {5E7D9B32-D268-48F0-AA5C-C20E2EE9C73F} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {604B3FBD-5D2F-4359-9AE0-5750AE7A4DC1} - System32\Tasks\SuperLyrics-16-updater => C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-updater.exe <==== ATTENTION
Task: {66ADDE1C-B9C0-4080-B096-676E1681F730} - System32\Tasks\SuperLyrics-16-codedownloader => C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-codedownloader.exe <==== ATTENTION
Task: {78BF57DC-2521-4B59-8C2A-D43FB1731BCF} - System32\Tasks\{446B7369-C01F-433E-870A-1ECC7845F4C6} => "c:\users\darki\appdata\local\google\chrome\application\chrome.exe"
hxxp://ui.skype.com/ui/0/7.23.85.105/pl/abandoninstall?page=tsMain
Task: {841F289A-B93B-4B99-A514-F9994A29EBA8} - System32\Tasks\Dealply => C:\Users\Darki\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {847D3AB6-5808-4E7B-83E0-0056A1960B9B} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3737458919-2164987103-1403913886-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [122880 2017-11-29] (RealNetworks, Inc.) [File not signed]
Task: {8FADE1C4-B1BE-4F96-B82F-7134F064959F} - System32\Tasks\1215avUpdateInfo => C:\ProgramData\Avg_Update_1215av\1215av_AVG-Secure-Search-Update.exe [2784656 2015-11-22] (AVG Technologies CZ, s.r.o. -> )
Task: {928896BB-17C7-4557-B47B-E2EC45B71B44} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {9F0EBE4B-6A36-448D-AEBD-931558096A2F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {B61063CD-1022-4F4C-9540-C7A898CB0CA1} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {CD03538D-7452-4D59-8654-29FC4F124096} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3737458919-2164987103-1403913886-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [122880 2017-11-29] (RealNetworks, Inc.) [File not signed]
Task: {D1462CFE-A98B-4F5B-9ECD-6D30093DABE3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {D86881DC-385B-4DCE-862E-9BDFAC3D8F6C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {DB7997C0-2AA9-492F-A772-D74D0E619655} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {DBBBAABE-AE8D-45C3-B3DB-7F978CB98AD9} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3737458919-2164987103-1403913886-1000 => C:\program files (x86)\real\RealDownloader\RealUpgrade.exe [135504 2017-11-29] (RealNetworks, Inc. -> RealNetworks, Inc.)
Task: {DBDB5756-907D-4D93-A341-D26C6513560F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {E3947B1C-858D-4DEE-B468-4D9C6290B0E8} - System32\Tasks\SuperLyrics-16-enabler => C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-enabler.exe <==== ATTENTION
Task: {ED3764E4-B38A-48FB-8C76-B8922926AE82} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3737458919-2164987103-1403913886-1000 => C:\program files (x86)\real\RealDownloader\RealUpgrade.exe [135504 2017-11-29] (RealNetworks, Inc. -> RealNetworks, Inc.)
Task: {FB8F720E-51BD-49F1-966D-D304B090322B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {FF8D7A21-DE2C-459C-8462-BA5DC3A903F0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\1215avUpdateInfo.job => C:\ProgramData\Avg_Update_1215av\1215av_AVG-Secure-Search-Update.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Dealply.job => C:\Users\Darki\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\WINDOWS\Tasks\ExtFixer21400.job => C:\Windows\TEMP\44162_updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\SpeedyPC Registration3.job => rundll32.exe C:\Program Files (x86)\Common Files\SpeedyPC Software\UUS3\UUS3.dll <==== ATTENTION
Task: C:\WINDOWS\Tasks\SuperLyrics-16-codedownloader.job => C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-codedownloader.exeLj/reinstallapp /agentregpath='SuperLyrics-16' /appid=44162 /srcid='000574' /subid='1060-2080' /zdata='d:gui.doneopen.net' /bic=BE66332A751A4BFCA5A6E10BC8042785IE /verifier=a7f920f352b0dc2dac868e983c7ee0aa /installerversion=1_29_153 /installerfullversion=1.29.153.0 /installationtime=1382196830 /statsdomain=hxxp:/stats.srvmystats.com /errorsdomain=hxxp:/errors.srvmystats.com /codedownloaddomain=hxxp:/app-static.crossrider.com <==== ATTENTION
Task: C:\WINDOWS\Tasks\SuperLyrics-16-enabler.job => C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-enabler.exeƝ/enablebho /agentregpath='SuperLyrics-16' /appid=44162 /srcid='000574' /subid='1060-2080' /zdata='d:gui.doneopen.net' /bic=BE66332A751A4BFCA5A6E10BC8042785IE /verifier=a7f920f352b0dc2dac868e983c7ee0aa /installerversion=1_29_153 /installationtime=1382196830 /statsdomain=hxxp:/stats.srvmystats.com /errorsdomain=hxxp:/errors.srvmystats.com <==== ATTENTION
Task: C:\WINDOWS\Tasks\SuperLyrics-16-updater.job => C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-updater.exeǾ/runupdater /agentregpath='SuperLyrics-16' /appid=44162 /srcid='000574' /subid='1060-2080' /zdata='d:gui.doneopen.net' /bic=BE66332A751A4BFCA5A6E10BC8042785IE /verifier=a7f920f352b0dc2dac868e983c7ee0aa /installerversion=1_29_153 /installationtime=1382196830 /statsdomain=hxxp:/stats.srvmystats.com /errorsdomain=hxxp:/errors.srvmystats.com /monetizationdomain=hxxp:/stats.syncstatsdata.com /geoserviceurl=hxxp:/ipgeoapi.com/ /updatejsondomain=hxxp:/update.srvmystats.com <==== ATTENTION
URLSearchHook: HKU\S-1-5-21-3737458919-2164987103-1403913886-1004 - SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch64.dll (DeviceVM Inc. -> DeviceVM, Inc.)
URLSearchHook: HKU\S-1-5-21-3737458919-2164987103-1403913886-1004 - SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM Inc. -> DeviceVM, Inc.)
SearchScopes: HKLM-x32 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3106777
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3106777
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> DefaultScope {2C8A17E3-A959-489b-A7C2-9BC58C65794C} URL =
hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=EGMB
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=96EA20CF307F6DED&affID=119794&tsp=5001
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> {2C8A17E3-A959-489b-A7C2-9BC58C65794C} URL =
hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=EGMB
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL =
hxxps://mysearch.avg.com/search?cid={CC6900B7-0B80-4E71-A57E-6661F7C707AC}&mid=9e452186170c47d18eb9f186769b841e-e95f7db7e513b0af88f0d46c48dd90c7d32e8acf&lang=en&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2016-03-20 08:36:51&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3106777
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> {B5D856E6-F2BB-44CE-8E6D-2E5D031493FD} URL =
hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=3F2DA6A5-5DE4-4E3A-BD7E-BBCC640CAF1A&apn_sauid=2DACB2D6-980B-4B56-A9C3-0CC77C1FEA4C
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> {CEF7CA24-B9DC-4a02-A7FE-F619274E5E4A} URL =
hxxp://www.google.com/custom?client=pub-37942...%3BGIMP%3A0000FF%3BFORID%3A1&hl=en&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1001 -> DefaultScope {5A5B5CD1-5AA3-4ecc-B7D2-3A30DA3B5EFC} URL =
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1004 -> DefaultScope {1FAA240F-1049-4f75-8C24-B021220F9EA9} URL =
hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=EGMB
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1004 -> {1FAA240F-1049-4f75-8C24-B021220F9EA9} URL =
hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=EGMB
SearchScopes: HKU\S-1-5-21-3737458919-2164987103-1403913886-1004 -> {AA99E351-3E79-4bda-87ED-006F3DDE36FA} URL =
hxxp://www.google.com/custom?client=pub-37942...%3BGIMP%3A0000FF%3BFORID%3A1&hl=en&q={searchTerms}
BHO: SuperLyrics-16 -> {11111111-1111-1111-1111-110411411162} -> C:\Program Files (x86)\SuperLyrics-16\SuperLyrics-16-bho64.dll => No File
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: No Name -> {11111111-1111-1111-1111-110411411162} -> No File
BHO-x32: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> No File
BHO-x32: No Name -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> No File
Toolbar: HKU\S-1-5-21-3737458919-2164987103-1403913886-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\system\ole db\MSDAIPP.DLL [1999-12-02] (Microsoft Corporation) [File not signed]
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
C:\Users\Darki\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com
FF HKLM-x32\...\Firefox\Extensions: [speedanalysis@SpeedAnalysis.com] - C:\Users\Darki\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com
FF Extension: (SpeedAnalysis.com) - C:\Users\Darki\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com [2013-03-24] [Legacy] [not signed]
FF HKU\S-1-5-21-3737458919-2164987103-1403913886-1000\...\Firefox\Extensions: [speedanalysis@SpeedAnalysis.com] - C:\Users\Darki\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com
CHR HomePage: Default ->
hxxp://www2.delta-search.com/?babsrc=HP_ss&am...6EA20CF307F6DED&affID=119794&tsp=5001
C:\Users\Darki\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfcbmgbfdbijmjgjihagbomfbjfjmgon
CHR Extension: (SpeedAnalysis.com) - C:\Users\Darki\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfcbmgbfdbijmjgjihagbomfbjfjmgon [2013-09-08] [UpdateUrl:hxxps://dl.addonupdater.com/speedanalysis/update.chrome.xml] <==== ATTENTION
C:\Users\Darki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocblcnaofikinigmceddfghppkkjbog
CHR Extension: (Cool Smiley Bar for Facebook) - C:\Users\Darki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocblcnaofikinigmceddfghppkkjbog [2013-09-08] [UpdateUrl:hxxps://dl.addonupdater.com/pluswinks/update.chrome.xml] <==== ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [cfcbmgbfdbijmjgjihagbomfbjfjmgon] - C:\Users\Darki\AppData\Roaming\SpeedanAlysis\speedanalysis.crx [2013-02-14]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKLM-x32\...\Chrome\Extension: [mocblcnaofikinigmceddfghppkkjbog] - C:\Users\Darki\AppData\Roaming\PlusWinks\pluswinks.crx [2013-03-20]
CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files (x86)\Yontoo\YontooLayers.crx <not found>
2019-08-09 22:20 - 2019-08-09 22:20 - 000000000 ____D C:\Users\Darki\Downloads\FRST-OlderVersion
2019-07-29 20:53 - 2019-07-29 20:53 - 000003820 _____ C:\WINDOWS\System32\Tasks\SuperLyrics-16-updater
2019-07-29 20:53 - 2019-07-29 20:53 - 000003726 _____ C:\WINDOWS\System32\Tasks\SuperLyrics-16-codedownloader
2019-07-29 20:53 - 2019-07-29 20:53 - 000003626 _____ C:\WINDOWS\System32\Tasks\SuperLyrics-16-enabler
2019-07-29 20:53 - 2019-07-29 20:53 - 000002900 _____ C:\WINDOWS\System32\Tasks\SpeedyPC Registration3
2019-07-29 20:53 - 2019-07-29 20:53 - 000002774 _____ C:\WINDOWS\System32\Tasks\Dealply
2019-07-29 20:53 - 2019-07-29 20:53 - 000002296 _____ C:\WINDOWS\System32\Tasks\1215avUpdateInfo
2019-07-29 20:53 - 2019-07-29 20:53 - 000002290 _____ C:\WINDOWS\System32\Tasks\ExtFixer21400
2019-07-29 20:53 - 2019-07-29 20:53 - 000002278 _____ C:\WINDOWS\System32\Tasks\{A5811E73-4582-406E-8F35-75AEF20E2067}
2019-07-29 20:53 - 2019-07-29 20:53 - 000002266 _____ C:\WINDOWS\System32\Tasks\{CA9603AA-C6BE-4103-8203-29799A6E9F2D}
2019-07-29 20:53 - 2019-07-29 20:53 - 000002254 _____ C:\WINDOWS\System32\Tasks\{446B7369-C01F-433E-870A-1ECC7845F4C6}