Task: {558D2EF5-075C-45C2-BC86-2D1A0DEB6C1D} - System32\Tasks\{CBA03FE9-B76B-46A5-8743-1727B04188F8} => pcalua.exe -a C:\Users\Kasia\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
C:\Users\Kasia\AppData\Roaming\mystartsearch
Task: {812A4334-2917-4A95-AC29-5216B549DD35} - System32\Tasks\Plugin Experience2 => Rundll32.exe "C:\Users\Kasia\AppData\Local\Plugin Experience\{7609664D-FD54-B092-3127-0201429E9E3E}\yehwq.dll",#1 <==== ATTENTION
C:\Users\Kasia\AppData\Local\Plugin Experience
Task: {DD05B43E-4624-4523-8D11-2A319FA0F8E5} - System32\Tasks\Plugin Experience => Rundll32.exe "C:\Users\Kasia\AppData\Local\Plugin Experience\{7609664D-FD54-B092-3127-0201429E9E3E}\PluginExperience.dll",#1 <==== ATTENTION
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKU\S-1-5-21-2320930405-3972802875-2868239731-1000\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [3670472 2015-07-28] (ALLPlayer Group Ltd.)
HKU\S-1-5-21-2320930405-3972802875-2868239731-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Kasia\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
{99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll No File
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 2 (GFS Stub)]
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll No File
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
{920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll No File
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 3 (GFS Folder)]
{16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll No File
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll No File
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll No File [ ]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2320930405-3972802875-2868239731-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
BHO: No Name
{9030D464-4C02-4ABF-8ECC-5164760863C6}
No File
BHO-x32: No Name
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
No File
BHO-x32: Groove GFS Browser Helper
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll => No File
BHO-x32: No Name
{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}
No File
BHO-x32: No Name
{9030D464-4C02-4ABF-8ECC-5164760863C6}
No File
BHO-x32: No Name
{F586CB96-7091-42ec-9829-F5D5CE65AFC1}
No File
S4 ANSYS, Inc. License Manager; "D:\ANSYS Inc\Shared Files\Licensing\winx64\ansysli_server.exe" -nodaemon -k runservice [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U4 klkbdflt2; system32\DRIVERS\klkbdflt2.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
EmptyTemp: