start::
closeprocesses:
createrestorepoint:
ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {14cb2bd0-2375-3d10-9b5d-5e18865c8959} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2020-09-21] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {700866bb-c8e9-3e71-b359-abb28baed0e8} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2020-09-21] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {0cab5786-30e8-3185-9b3b-ccefbf1b8afe} => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.ShellExtension.DLL [2020-09-21] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
SearchScopes: HKU\.DEFAULT -> DefaultScope {F9176637-CF6A-42D8-A12E-3C1A091A9598} URL =
SearchScopes: HKU\.DEFAULT -> {F9176637-CF6A-42D8-A12E-3C1A091A9598} URL =
HKLM\...\StartupApproved\Run32: => "Avira SystrayStartTrigger"
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [704720 2020-10-09] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
Task: {08F7BDDF-B5D1-4DDA-BFED-303CAD859977} - System32\Tasks\AviraSystemSpeedupUpdate => C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [30106496 2020-10-15] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2718715299-2838987772-912226498-1001\...\MountPoints2: {72000b63-e1c3-11ea-83ec-2cf05d2de3f7} - "E:\setup.exe"
HKU\S-1-5-21-2718715299-2838987772-912226498-1001\...\MountPoints2: {b3474348-e25b-11ea-83ed-2cf05d2de3f7} - "J:\setup.exe"
Task: {5AC3F81C-84B0-4AD9-803B-18F3B884CD9F} - System32\Tasks\Avira_Security_Update => C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Common.Updater.exe [230632 2020-11-17] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
C:\Users\alexi\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll
C:\Users\alexi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
C:\Users\alexi\AppData\Roaming\Opera Software\Opera Stable\Extensions\dalelnnofafalcmkmnhdbigbjjkloabo
C:\Users\alexi\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngohaaocccbohaffogpbgfpmpgbcgccg
R2 AviraOptimizerHost; C:\Program Files (x86)\Avira\Optimizer Host\Avira.OptimizerHost.exe [2988544 2020-06-03] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AviraSecurity; C:\Program Files (x86)\Avira\Security\Avira.Spotlight.Service.exe [246424 2020-11-17] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S3 mracsvc; C:\Windows\System32\mracsvc.exe [20536992 2020-08-30] (Mail.Ru LLC -> LLC Mail.Ru)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv1.sys [19767024 2020-08-30] (Mail.Ru LLC -> LLC Mail.Ru)
S3 mhyprot2; \??\C:\Users\alexi\AppData\Local\Temp\mhyprot2.sys [X] <==== ATTENTION
2020-11-20 21:23 - 2020-08-21 20:56 - 000003714 _____ C:\Windows\system32\Tasks\Avira_Security_Update
C:\Program Files (x86)\Avira
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-image /Restorehealth
cmd: netsh advfirewall reset
emptytemp:
end::