Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 01-07-2025 Uruchomiony przez Administrator (administrator) MIECHOZO-5V8B63 (Dell Inc. Precision 5820 Tower) (01-07-2025 14:32:05) Uruchomiony z C:\Users\Administrator\Downloads\Piosenki słońce lato wakacje\FRST64.exe Załadowane profile: Administrator Platforma: Microsoft Windows 11 Pro for Workstations Wersja 23H2 22631.5472 (X64) Język: Polski (Polska) Domyślna przeglądarka: Edge Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Brother Industries, Ltd. -> Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe ->) (Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe (C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe ->) (Brother Industries, Ltd. -> Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\swriter.exe (C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.UserProcess.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> ) C:\Program Files (x86)\Dell\UpdateService\DCF\Dell.Update.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> ) C:\Program Files\Dell\DTP\DiagnosticsSubAgent\Dell.TechHub.Diagnostics.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TechHub\Dell.CoreServices.Client.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\AnalyticsSubAgent\Dell.TechHub.Analytics.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\DataManagerSubAgent\Dell.TechHub.DataManager.SubAgent.exe (C:\Program Files\Dell\TechHub\Dell.TechHub.exe ->) (Dell Technologies Inc. -> Dell, Inc.) C:\Program Files\Dell\DTP\InstrumentationSubAgent\Dell.TechHub.Instrumentation.SubAgent.exe (C:\Program Files\LibreOffice\program\soffice.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin (C:\Program Files\LibreOffice\program\swriter.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe (C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3> (C:\Program Files\Tablet\Wacom\WacomHost.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_UpdateUtil.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> Wacom Co., Ltd.) C:\Program Files\Tablet\Wacom\WacomHost.exe (C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.15301.20.0_x64__cw5n1h2txyewy\WidgetBoard.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\137.0.3296.93\msedgewebview2.exe <7> (explorer.exe ->) (Canon Inc. -> Canon INC.) C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2504.62.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <52> (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Open Source Developer, Noriyuki MIYAZAKI -> Crystal Dew World) C:\Program Files\CrystalDiskInfo\DiskInfo64.exe (services.exe ->) () [Brak podpisu cyfrowego] C:\Program Files\Photopia Software Updater\UpdateService.exe (services.exe ->) (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Browny02\BrYNSvc.exe (services.exe ->) (Dell Technologies Inc. -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe (services.exe ->) (Dell Technologies Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe (services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe (services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe (services.exe ->) (Dell Technologies Inc. -> Dell) C:\Program Files\Dell\TechHub\Dell.TechHub.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\TbtP2pShortcutService.exe (services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\NisSrv.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdw.inf_amd64_a19248ee5419ef52\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvdw.inf_amd64_a19248ee5419ef52\NVWMI\nvWmi64.exe <2> (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (services.exe ->) (Smart Sound Technology -> Intel) C:\Windows\System32\cAVS\Intel(R) Audio Service\IntelAudioService.exe (services.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe (services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe (sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.25061.25.0_x64__cw5n1h2txyewy\CrossDeviceService.exe (svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2524.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe (svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files\Intel\Intel(R) Virtual RAID on CPU\IAStorIcon.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.51.3.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_525.15301.20.0_x64__cw5n1h2txyewy\WidgetBoard.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11102808 2021-05-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618080 2021-05-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1236688 2020-12-04] (Waves Inc -> Waves Audio Ltd.) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [145344 2019-07-26] (Brother Industries, Ltd. -> Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3146752 2022-02-07] (Brother Industries, Ltd.) [Brak podpisu cyfrowego] HKU\S-1-5-21-1000332121-569252039-3906760741-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4113448 2025-06-26] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1000332121-569252039-3906760741-500\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKLM\...\Windows x64\Print Processors\HP1020PrintProc: C:\Windows\System32\spool\prtprocs\x64\pphp1020.dll [65024 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> ) HKLM\...\Print\Monitors\HPLJ1020LM: C:\WINDOWS\system32\zlhp1020.dll [192512 2012-09-18] (Microsoft Windows Hardware Compatibility Publisher -> ) Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2025-03-26] ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon Inc. -> Canon INC.) GroupPolicy: Ograniczenia ? <==== UWAGA Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {6BCD418D-4D48-4947-BE58-8DC483405539} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\FrameworkAgents\SupportAssistInstaller.exe [1256104 2025-04-04] (Dell Technologies Inc. -> Dell Inc.) -> C:\Program Files\Dell\SupportAssistAgent\bin\AutoUpdate Task: {BECD0168-79D6-42A7-B7A7-1C171699B428} - System32\Tasks\IAStorIcon => C:\Program Files\Intel\Intel(R) Virtual RAID on CPU\IAStorIcon.exe [292576 2021-10-04] (Intel Corporation -> Intel Corporation) Task: {36F2989F-250F-4B86-A366-955B39DADBCD} - System32\Tasks\Intel\Intel® Management and Security Status => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [220792 2024-01-31] (Intel Corporation -> Intel Corporation) -> "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60 Task: {175015D3-4017-4B73-AF55-7B708D236C40} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Brak pliku) Task: {380D7708-6675-4452-A499-D83094ED8025} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AD139798-66BB-4C7A-856B-EB9A9969F00F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {D88BD66B-861A-4438-9C80-178F4A6ECBEF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {78DFE313-561F-480D-A806-4432065B67A6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpCmdRun.exe [1757568 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{037de347-0c68-491d-bdab-6b37be903964}: [NameServer] 1.1.1.1,1.0.0.1 Tcpip\..\Interfaces\{037de347-0c68-491d-bdab-6b37be903964}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{037de347-0c68-491d-bdab-6b37be903964}: [DhcpDomain] home Tcpip\..\Interfaces\{aaf406b9-26ed-4652-9c0a-0776755f972c}: [NameServer] 1.1.1.1,1.0.0.1 Tcpip\..\Interfaces\{aaf406b9-26ed-4652-9c0a-0776755f972c}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{aaf406b9-26ed-4652-9c0a-0776755f972c}: [DhcpDomain] home Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default [2025-07-01] Edge DownloadDir: Default -> C:\Users\Administrator\Downloads\Piosenki słońce lato wakacje Edge HomePage: Default -> hxxps://www.google.pl/ Edge Session Restore: Default -> [funkcja włączona] Edge Extension: (Open in PDF Reader) - C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ciphgjdgpkhlngiadnpebblpcjcoabcp [2025-05-02] Edge Extension: (Dokumenty Google offline) - C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-06] Edge Extension: (Edge relevant text changes) - C:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-08] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [321536 2022-01-26] (Brother Industries, Ltd.) [Brak podpisu cyfrowego] R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [459456 2025-02-14] (Dell Technologies Inc. -> Dell Technologies Inc.) R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [153792 2025-02-14] (Dell Technologies Inc. -> Dell Technologies Inc.) R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [481984 2025-02-14] (Dell Technologies Inc. -> Dell Technologies Inc.) R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [51648 2024-11-14] (Dell Technologies Inc. -> ) R2 DellTechHub; C:\Program Files\Dell\TechHub\Dell.TechHub.exe [153288 2025-02-20] (Dell Technologies Inc. -> Dell) S3 LibreOfficeMaintenance; C:\Program Files\LibreOffice\program\update_service.exe [123304 2025-03-19] (The Document Foundation -> The Document Foundation) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MpDefenderCoreService.exe [2071592 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvdw.inf_amd64_a19248ee5419ef52\Display.NvContainer\NVDisplay.Container.exe [1275016 2025-01-07] (NVIDIA Corporation -> NVIDIA Corporation) R2 NVWMI; C:\WINDOWS\System32\DriverStore\FileRepository\nvdw.inf_amd64_a19248ee5419ef52\NVWMI\nvWmi64.exe [4544160 2025-01-07] (NVIDIA Corporation -> NVIDIA Corporation) R2 PhotopiaUpdate; C:\Program Files\Photopia Software Updater\updateService.exe [4234240 2025-04-26] () [Brak podpisu cyfrowego] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [917480 2025-06-10] (Microsoft Windows Publisher -> Microsoft Corporation) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [148648 2025-04-04] (Dell Technologies Inc. -> Dell Inc.) R2 TbtP2pShortcutService; C:\WINDOWS\TbtP2pShortcutService.exe [256608 2022-06-29] (Intel Corporation -> Intel Corporation) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\NisSrv.exe [4513624 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25050.5-0\MsMpEng.exe [278328 2025-06-17] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 bcmnfcusb; C:\WINDOWS\System32\drivers\bcmnfcusb.sys [72880 2024-10-03] (Broadcom Inc. -> Broadcom Corporation.) R3 DellInstrumentation; C:\WINDOWS\System32\drivers\DellInstrumentation.sys [35896 2025-02-13] (Microsoft Windows Hardware Compatibility Publisher -> Dell) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_f3c6513565231a23\e1d.sys [609456 2022-11-14] (Intel Corporation -> Intel Corporation) R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [330112 2025-06-17] (Microsoft Windows -> Microsoft Corporation) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [12435144 2024-10-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20032 2025-06-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [612768 2025-06-17] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [100744 2025-06-17] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2025-07-01 14:27 - 2025-07-01 14:32 - 000000000 ____D C:\FRST 2025-07-01 14:15 - 2025-07-01 14:18 - 000000000 ____D C:\Users\Administrator\Documents\2025-07-01 CrystalDiskInfo 2025-07-01 14:08 - 2025-07-01 14:08 - 000001835 _____ C:\Users\Administrator\Desktop\CrystalDiskInfo.lnk 2025-07-01 14:08 - 2025-07-01 14:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2025-07-01 14:08 - 2025-07-01 14:08 - 000000000 ____D C:\Program Files\CrystalDiskInfo 2025-07-01 13:37 - 2025-07-01 13:37 - 000798672 _____ C:\WINDOWS\system32\perfh015.dat 2025-07-01 13:37 - 2025-07-01 13:37 - 000158220 _____ C:\WINDOWS\system32\perfc015.dat 2025-06-30 12:47 - 2025-06-30 12:48 - 000000000 ____D C:\Users\Administrator\Downloads\do liner24 2025-06-30 2025-06-23 23:39 - 2025-06-24 01:07 - 000000000 ____D C:\Users\Administrator\Downloads\2025.06.23 obrazy telefon Siostra Beata Rokicka 2025-06-23 16:14 - 2025-06-23 16:14 - 000000000 ____D C:\Users\Administrator\Downloads\2025.06.23 zlecenia pawlatrans 2025-06-23 00:10 - 2025-07-01 14:32 - 000000000 ____D C:\Users\Administrator\Downloads\Piosenki słońce lato wakacje 2025-06-20 01:18 - 2025-06-20 02:22 - 000000000 ____D C:\Users\Administrator\Documents\Oficjum za zmarłych 2025-06-18 20:13 - 2025-06-18 20:13 - 000000000 ____D C:\Users\Administrator\Downloads\Boze Cialo 2025-06-15 19:25 - 2025-06-24 19:33 - 000000000 ____D C:\Users\Administrator\Documents\Log Files 2025-06-15 19:25 - 2025-06-23 23:14 - 000000000 ____D C:\Users\Administrator\Documents\AnyMP4 Studio 2025-06-15 19:25 - 2025-06-15 19:25 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyMP4 2025-06-15 19:25 - 2025-06-15 19:25 - 000000000 ____D C:\Users\Administrator\AppData\Local\AnyMP4 Studio 2025-06-13 02:46 - 2025-06-13 02:46 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\3D LUT Creator 2025-06-13 02:45 - 2025-06-13 03:03 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\retouch4me-arams 2025-06-13 02:45 - 2025-06-13 02:45 - 000001989 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Retouch4me Arams.lnk 2025-06-13 02:45 - 2025-06-13 02:45 - 000001977 _____ C:\Users\Public\Desktop\Retouch4me Arams.lnk 2025-06-13 02:45 - 2025-06-13 02:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\retouch4me-arams-updater 2025-06-13 02:44 - 2025-06-13 02:45 - 000000000 ____D C:\Program Files\Retouch4me Arams 2025-06-13 02:42 - 2025-06-13 02:43 - 366316808 _____ (Retouch4me) C:\Users\Administrator\Downloads\Retouch4me_Arams_1.3.2.exe 2025-06-13 02:26 - 2025-06-13 02:26 - 000001100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Retouch4me Color Match Free.lnk 2025-06-13 02:26 - 2025-06-13 02:26 - 000000000 ____D C:\Program Files\Retouch4me Color Match Free 2025-06-13 02:24 - 2025-06-13 02:25 - 144340365 _____ (Oleg Sharonov ) C:\Users\Administrator\Downloads\Retouch4me_Color_Match_Free_Mieszko_Kaczmarek_1.200.exe 2025-06-11 16:12 - 2025-06-11 16:12 - 000000000 ____D C:\Users\Administrator\AppData\Local\Apps\2.0 2025-06-05 21:45 - 2025-06-05 21:45 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet Wacom 2025-06-04 17:14 - 2025-06-04 17:15 - 000000000 ____D C:\Users\Administrator\Downloads\2025-06-04 Roman Kaczmarek ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2025-07-01 13:48 - 2025-01-08 16:58 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2025-07-01 13:43 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\SystemTemp 2025-07-01 13:37 - 2025-01-08 17:12 - 001798726 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2025-07-01 13:37 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\INF 2025-07-01 13:33 - 2025-01-08 21:27 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\WTablet 2025-07-01 13:33 - 2025-01-08 17:08 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2025-07-01 13:33 - 2025-01-08 17:05 - 000000000 ____D C:\ProgramData\NVIDIA 2025-07-01 10:16 - 2025-01-08 16:56 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2025-07-01 08:40 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\AppReadiness 2025-07-01 08:31 - 2025-01-08 16:58 - 000000000 ___HD C:\Program Files\WindowsApps 2025-07-01 08:12 - 2025-01-08 17:05 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2025-06-30 14:27 - 2025-01-08 17:11 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe 2025-06-30 09:10 - 2025-01-08 17:07 - 000000000 ____D C:\Users\Administrator 2025-06-28 12:00 - 2025-01-08 17:05 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2025-06-28 12:00 - 2025-01-08 17:05 - 000002293 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2025-06-25 03:59 - 2025-04-27 15:06 - 002918800 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll 2025-06-25 03:59 - 2025-04-27 15:06 - 000817528 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll 2025-06-25 03:59 - 2025-04-27 15:06 - 000403832 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_8.dll 2025-06-25 03:59 - 2025-04-27 15:06 - 000272784 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll 2025-06-25 03:59 - 2025-04-27 15:06 - 000244088 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll 2025-06-25 03:59 - 2025-04-27 15:06 - 000166264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll 2025-06-25 03:59 - 2025-04-27 15:06 - 000121232 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe 2025-06-25 03:59 - 2025-04-27 15:06 - 000076152 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe 2025-06-24 19:47 - 2025-04-26 19:26 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Photopia 2025-06-24 19:47 - 2025-04-26 19:26 - 000000000 ____D C:\ProgramData\Strata 2025-06-24 19:47 - 2025-04-26 19:25 - 000000000 ____D C:\ProgramData\Photopia 2025-06-24 09:17 - 2025-02-11 22:10 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\foobar2000-v2 2025-06-24 01:05 - 2025-04-26 19:26 - 000000000 ____D C:\Users\Administrator\Documents\Photopia Slide Shows 2025-06-23 07:19 - 2025-01-08 17:14 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache 2025-06-17 07:51 - 2025-01-08 17:08 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2025-06-15 18:48 - 2025-02-07 23:46 - 000007605 _____ C:\Users\Administrator\AppData\Local\resmon.resmoncfg 2025-06-11 16:47 - 2025-01-09 01:39 - 000000000 ____D C:\WINDOWS\system32\MRT 2025-06-11 16:45 - 2025-01-09 01:39 - 216824056 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2025-06-11 16:08 - 2025-01-10 16:52 - 000000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics 2025-06-10 22:38 - 2025-01-14 21:06 - 000446016 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ___SD C:\WINDOWS\system32\UNP 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ___RD C:\WINDOWS\PrintDialog 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\UUS 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\SystemResources 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\setup 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\oobe 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\migwiz 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\system32\Dism 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\ShellExperiences 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\ShellComponents 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\WINDOWS\bcastdvr 2025-06-10 22:35 - 2025-01-08 16:58 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2025-06-10 21:44 - 2025-01-08 16:56 - 000000000 ____D C:\WINDOWS\CbsTemp 2025-06-10 21:41 - 2025-01-08 17:10 - 003216384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2025-06-07 22:12 - 2025-04-29 17:03 - 000000000 ____D C:\Users\Administrator\Downloads\Piosenki imieninowe 2025-06-05 21:45 - 2025-01-13 01:49 - 000000000 ____D C:\Program Files\dotnet 2025-06-05 21:45 - 2025-01-08 21:24 - 000000000 ____D C:\ProgramData\Package Cache 2025-06-05 21:45 - 2025-01-08 21:23 - 000000000 ____D C:\Program Files\Tablet 2025-06-02 14:44 - 2025-01-08 21:23 - 002734032 _____ (Wacom Co. Ltd.) C:\WINDOWS\system32\Wacom_Tablet.dll 2025-06-02 14:44 - 2025-01-08 21:23 - 002726864 _____ (Wacom Co. Ltd.) C:\WINDOWS\system32\Wacom_Touch_Tablet.dll 2025-06-02 14:44 - 2025-01-08 21:23 - 002612688 _____ (Wacom Co. Ltd.) C:\WINDOWS\system32\WacomMT.dll 2025-06-02 14:44 - 2025-01-08 21:23 - 002569680 _____ (Wacom Co. Ltd.) C:\WINDOWS\system32\Wintab32.dll 2025-06-02 14:44 - 2025-01-08 21:23 - 000114744 _____ (Wacom Co. Ltd.) C:\WINDOWS\system32\Drivers\wachidrouter.sys 2025-06-02 14:44 - 2025-01-08 21:23 - 000032848 _____ (Wacom Co. Ltd.) C:\WINDOWS\system32\Drivers\wacomrouterfilter.sys 2025-06-02 14:43 - 2025-01-08 21:23 - 002286032 _____ (Wacom Co. Ltd.) C:\WINDOWS\SysWOW64\Wacom_Tablet.dll 2025-06-02 14:43 - 2025-01-08 21:23 - 002279376 _____ (Wacom Co. Ltd.) C:\WINDOWS\SysWOW64\Wacom_Touch_Tablet.dll 2025-06-02 14:43 - 2025-01-08 21:23 - 002143696 _____ (Wacom Co. Ltd.) C:\WINDOWS\SysWOW64\WacomMT.dll 2025-06-02 14:43 - 2025-01-08 21:23 - 002094544 _____ (Wacom Co. Ltd.) C:\WINDOWS\SysWOW64\Wintab32.dll ==================== Pliki w katalogu głównym wybranych folderów ======== 2025-02-07 23:46 - 2025-06-15 18:48 - 000007605 _____ () C:\Users\Administrator\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================