Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 10-11-2025 Uruchomiony przez Gieni (administrator) GIENIO (HP HP 255 G8 Notebook PC) (10-11-2025 18:51:39) Uruchomiony z C:\Users\Gieni\Downloads\FRST64.exe Załadowane profile: Gieni Platforma: Microsoft Windows 11 Home Wersja 24H2 26100.6899 (X64) Język: Polski (Polska) Domyślna przeglądarka: Chrome Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe (0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe (C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentservice.exe ->) (ZOHO Corporation Private Limited -> ) C:\Program Files (x86)\DesktopCentral_Agent\bin\dcondemand.exe (C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentservice.exe ->) (ZOHO Corporation Private Limited -> ) C:\Program Files (x86)\DesktopCentral_Agent\bin\DCProcessMonitor.exe (C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe (C:\Program Files (x86)\Internet Explorer\ScreenConnect.ClientService.exe ->) (Connectwise, LLC -> ScreenConnect Software) C:\Program Files (x86)\Internet Explorer\ScreenConnect.WindowsClient.exe (C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.ClientService.exe ->) (Connectwise, LLC -> ScreenConnect Software) C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.WindowsClient.exe (C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe ->) (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe (C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe (C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe (C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.10.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe ->) (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.10.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityHost.exe (C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe ->) (0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSSrcExt.exe (C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe ->) (0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.22.20073.0_x64__0a9344xs7nr4m\radeonsoftware\cncmd.exe (DriverStore\FileRepository\u0390931.inf_amd64_12d851e1980a239f\B386329\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390931.inf_amd64_12d851e1980a239f\B386329\atieclxx.exe (ED346674-0FA1-4272-85CE-3187C9C86E26 -> HP Inc.) C:\Program Files\WindowsApps\AD2F1837.HPSystemEventUtility_3.2.10.0_x64__v10z8vjag6ke6\SystemEventUtility\HPSystemEventUtilityBackground.exe (ETDService.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <33> (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Media Network\HPMediaNetwork.exe (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2025.11100.9001.0_x64__8wekyb3d8bbwe\Photos.exe <2> (Microsoft Corporation -> Microsoft Corporation) C:\Users\Gieni\AppData\Local\Microsoft\OneDrive\25.194.1005.0003\FileCoAuth.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\Gieni\AppData\Local\Microsoft\OneDrive\25.194.1005.0003\OneDrive.Sync.Service.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoNotificationUx.exe (SECOMN64.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe (services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe (services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0390931.inf_amd64_12d851e1980a239f\B386329\atiesrxx.exe (services.exe ->) (Connectwise, LLC -> ) C:\Program Files (x86)\Internet Explorer\ScreenConnect.ClientService.exe (services.exe ->) (Connectwise, LLC -> ) C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.ClientService.exe (services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe (services.exe ->) (EXPRSVPN LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\AppHelperCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\DiagsCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\NetworkCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\SysInfoCap.exe (services.exe ->) (Immense Networks) [Brak podpisu cyfrowego] C:\Program Files\Remotely\Remotely_Agent.exe (services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_d315e0ae42c5f5e6\RtkAudUService64.exe <3> (services.exe ->) (Reason Software Company Inc. -> Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe (services.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe (services.exe ->) (ZOHO Corporation Private Limited -> ) C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentservice.exe (sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_22509.1401.17.0_x64__8wekyb3d8bbwe\WinStore.DesktopExtension\StoreDesktopExtension.exe (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.151.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_22509.1401.17.0_x64__8wekyb3d8bbwe\WinStore.App.exe (svchost.exe ->) (Microsoft Windows -> ) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe <2> ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_d315e0ae42c5f5e6\RtkAudUService64.exe [1922856 2023-10-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [370088 2021-10-08] (EXPRSVPN LLC -> ExpressVPN) HKU\S-1-5-21-2154322142-1083756757-1331411065-1001\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [545288 2025-03-28] (HP Inc. -> HP Inc.) HKU\S-1-5-21-2154322142-1083756757-1331411065-1009\...\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HPSEU\HpseuHostLauncher.exe [545288 2025-03-28] (HP Inc. -> HP Inc.) HKU\S-1-5-18\...\Policies\Explorer: [SettingsPageVisibility] hide:appsfeatures HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2025-11-06] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\142.0.7444.61\Installer\chrmstp.exe [2025-11-06] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-A658-80934ECCD7CB}] -> C:\Program Files (x86)\Internet Explorer\ScreenConnect.WindowsCredentialProvider.dll [2024-07-23] (Connectwise, LLC -> ) <==== UWAGA HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-D8A7-1F27744C1734}] -> C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.WindowsCredentialProvider.dll [2025-04-08] (Connectwise, LLC -> ) <==== UWAGA Lsa: [Authentication Packages] msv1_0 C:\Program Files (x86)\Internet Explorer\ScreenConnect.WindowsAuthenticationPackage.dll C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.WindowsAuthenticationPackage.dll ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {CCF86EC2-0ACB-4FC9-BBDB-EC112F611148} - System32\Tasks\DCAgentUpdater => C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentupgrader.exe Task (Brak pliku) Task: {97CB9106-850C-4C24-B27F-52D072973FFE} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem143.0.7482.0{4FB0E6BF-7169-4D43-AA2D-60310D2DB108} => C:\Program Files (x86)\Google\GoogleUpdater\143.0.7482.0\updater.exe [6933656 2025-10-19] (Google LLC -> Google LLC) Task: {FBCB1711-ADE9-4090-8B5D-26686728AEE9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1004040 2025-10-21] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show Task: {D4877E22-9A76-4443-8285-A5B0AA508277} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2025-10-21] (HP Inc. -> HP Inc.) Task: {CABF285C-0352-43C6-BE26-2805AF88713F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1176136 2025-10-21] (HP Inc. -> HP Inc.) Task: {D1B542FE-12D9-4866-9AAB-0A062A55A155} - System32\Tasks\HP\Consent Manager Launcher => C:\WINDOWS\system32\sc.exe [102400 2025-07-08] (Microsoft Windows -> Microsoft Corporation) -> start hptouchpointanalyticsservice Task: {100E5924-FDC5-4E9A-A8EC-DA4CA1750A94} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1651032 2020-11-05] (HP Inc. -> HP Inc.) Task: {15A63A06-7032-4577-8B74-4A845BB4635B} - System32\Tasks\Meta\Messenger-SL-Helper-S-1-5-21-2154322142-1083756757-1331411065-1001 => C:\Users\Gieni\AppData\Local\Programs\Messenger\MessengerHelper.exe --lassie (Brak pliku) Task: {31BC89D7-904F-43E2-834C-740F8C87D119} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16961872 2025-11-09] (Microsoft Corporation -> Microsoft Corporation) Task: {3D6167A1-7666-4F2F-BC2A-123B2A6B65DF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29173088 2025-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {CAB7E2C4-D3AB-48B1-93BF-5A1FCC60C4B3} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [70488 2025-11-09] (Microsoft Corporation -> Microsoft Corporation) Task: {CAEF1F6F-CC9B-4424-9A70-844C0888483F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29173088 2025-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {D793B170-87D9-46B1-88B9-A72A2340C97F} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [316736 2025-11-09] (Microsoft Corporation -> Microsoft Corporation) Task: {688A277B-7DAC-4A3C-B1F8-5CD16062B902} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [316736 2025-11-09] (Microsoft Corporation -> Microsoft Corporation) Task: {667E44DA-90CC-4FEB-B9E2-E94FACB75D23} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1365280 2025-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (Brak pliku) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Brak pliku) Task: {10541549-741B-465A-A666-177B97BD0FD1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpCmdRun.exe [1790640 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {E5D82AD6-F09A-44B1-B50C-BD1031F8CC54} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpCmdRun.exe [1790640 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A8AB9196-92C1-4002-BC7C-2EE2A54F0408} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpCmdRun.exe [1790640 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {611E2D5C-1D96-4A80-AFD9-7937F51410EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpCmdRun.exe [1790640 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FB99BA6C-39CE-4A3A-87F1-0E3A652DCE3F} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2154322142-1083756757-1331411065-1001 => C:\Users\Gieni\AppData\Local\Microsoft\OneDrive\25.194.1005.0003\OneDriveLauncher.exe [725864 2025-11-01] (Microsoft Corporation -> Microsoft Corporation) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\DCAgentUpdater.job => C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentupgrader.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 195.46.37.3 195.46.37.2 Tcpip\..\Interfaces\{92b322ad-0b6f-4c92-9451-43c57dc82408}: [DhcpNameServer] 195.46.37.3 195.46.37.2 Tcpip\..\Interfaces\{c4b93dd1-e92b-424b-905e-baf6043d52ce}: [DhcpNameServer] 195.46.37.3 195.46.37.2 Tcpip\..\Interfaces\{c4b93dd1-e92b-424b-905e-baf6043d52ce}\2416E6B6020556B616F6023514: [DhcpNameServer] 192.168.7.231 HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\Gieni\AppData\Local\Microsoft\Edge\User Data\Default [2025-11-07] Edge Extension: (Dokumenty Google offline) - C:\Users\Gieni\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-07-03] Edge Extension: (Edge relevant text changes) - C:\Users\Gieni\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-16] FireFox: ======== FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-11-03] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-11-03] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Gieni\AppData\Local\Google\Chrome\User Data\Default [2025-11-10] CHR Notifications: Default -> hxxps://www.facebook.com CHR HomePage: Default -> hxxp://www.google.pl/ CHR StartupUrls: Default -> "hxxp://www.wirtualnapolska.pl/" CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Gieni\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-05-09] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13366704 2025-11-03] (Microsoft Corporation -> Microsoft Corporation) R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [437160 2021-10-08] (EXPRSVPN LLC -> ExpressVPN) R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [891256 2020-07-30] (HP Inc. -> HP Inc.) R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\AppHelperCap.exe [909496 2025-09-30] (HP Inc. -> HP Inc.) R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\DiagsCap.exe [907960 2025-09-30] (HP Inc. -> HP Inc.) R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\NetworkCap.exe [903856 2025-09-30] (HP Inc. -> HP Inc.) R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_383a15da209a6794\x64\SysInfoCap.exe [909464 2025-09-30] (HP Inc. -> HP Inc.) R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_ef460d1f2a35fc16\x64\TouchpointAnalyticsClientService.exe [639784 2025-10-01] (HP Inc. -> HP Inc.) R2 ManageEngine Desktop Central - Agent; C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagentservice.exe [1169416 2022-04-27] (ZOHO Corporation Private Limited -> ) S3 ManageEngine Desktop Central - Remote Control; C:\Program Files (x86)\DesktopCentral_Agent\bin\dcrdservice.exe [2563080 2022-04-27] (ZOHO Corporation Private Limited -> ) R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [951024 2025-10-30] (McAfee, LLC -> McAfee, LLC) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MpDefenderCoreService.exe [2026144 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Remotely_Service; C:\Program Files\Remotely\Remotely_Agent.exe [249344 2024-08-08] (Immense Networks) [Brak podpisu cyfrowego] R2 ScreenConnect Client (f54e48458ed500f5); C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5)\ScreenConnect.ClientService.exe [95512 2025-04-08] (Connectwise, LLC -> ) <==== UWAGA R2 unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2023-10-17] (Reason Software Company Inc. -> Reason Software Company Inc.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\NisSrv.exe [4418608 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25090.3009-0\MsMpEng.exe [282440 2025-10-22] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ManRas; "C:\Program Files (x86)\Internet Explorer\ScreenConnect.ClientService.exe" "?e=Access&y=Guest&h=aszen.org&p=8041&s=381043c7-dc49-4e9a-8f98-4b37219f7460&k=BgIAAACkAABSU0ExAAgAAAEAAQA1CqNC3EdLM8HKZI6wSby1N31VyJTLn%2b4fSspm7dELQ1CuRC4uJVTMlYHxFkgGT%2bbBCsbgBUEYcrFTiE4%2bdqQivCSMibxFeLcxptl0fFdRv7CLyGlx8FDziuc5M8FriAqqv310GJr7l7Em%2fCKiH5oaTnbuKGIcYNjpsnuKd2sjN3x6MyjNvG9TMVn463SlI6b%2fjCgG4AagcQzczrxr13CF%2f%2bvWlv6d1SBmQQI5uFLYNyZKWow2kJnNNVC1uvpHfg0m%2bBXDW7Yf7pnTg07et6yCOjCiKkpRsTuUSWg4qHj74UsYzNw5%2fgt0xf8a8j3L4nmM4h%2bclaTKxOGUPhjEH3HD&v=AQAAANCMnd8BFdERjHoAwE%2fCl%2bsBAAAADSS9qw3JQkS2CWSdx%2fAbxAAAAAACAAAAAAAQZgAAAAEAACAAAACdlRJ6GA8iSnqbzgM9w%2bz6cF5OmuGXC8swaYuEkUHYLwAAAAAOgAAAAAIAACAAAAB5Xr5HqL2V%2fn9N40J2Str8L3QIBN38KCU%2bT1Z10H3wkqAEAAApccqlqYrej8X6pP5vTxwgBpGgleGNlw2MfeEQvi6zrwkmk4n8YnnjzMbe9YhddCO08fnpH6QMCoWnBvA9%2bplyocykoHzN0zKm8dO7AQI87hlyJwnW%2bLTw5CKCXJY%2fU1iKSkCyrc5lhLnMFQj1SuwxmQ5rr2mNcgPSvFwVpIDKCnqoxaqPhJyJTsO8EmBjKLkyNXGI3l%2bztv7pHJm8EYBRTTszAEDSv84i%2f5V7ezSUP5SpzE5jqDz6slSNaCy%2bszdGaC9bxYM%2f%2bl%2bunjfxzowKezLvRpGbXl9DmgQVy47YX4M71chOuqhQFT99KxuyvvswZAQ7Rof8TqMXajMbuaT6HWdtMGE1ONtJKBymKnw8WoBOPK%2b1BFLKUpmGat7yGoh0JlX6b9lIYoO%2bu7e6WfgdrKrori9VCSfB36EBHdQEYw50DNSaGF6w0g6ha%2bVkxxn19e3RSDhfmpRQP1EXNB8JML%2ftR45tdUt8sfn%2bkal2m69rdS2JYsHFExSi8J948pL6dEqfzDVCUL%2bheX2ZHVzRNRm9%2fkDvW%2fM81jMsEHIibzA8X3mGPLYOg22LV2EQR2Mo7yQjUifKuv1CeT9JrxwIn44p2n1wokbGW1lcxhz%2fZXPLvUS3l%2bFFhXP9zjN7IIKgXaJVkycWG7Ex3RNwJriQU9%2bxAdrN4z0BvEGzJWIpvVp7%2blwKbmcWOIxbRlw2F5sh1x28r58aF%2bxe%2bZusT%2fjHRfdJvjN0O%2btjc32Bb9BKmrJRP72yphIIJ%2bBI2iWbOLoY89M3n0OxshLijE3%2bmmhV3aNxDAAWokqpcwJHnGJYxr%2bpSXReBMtegsB9iZmp9U%2bfZEkmV7y32BUFJU%2bj7zCfVEMJtXRjlkfh2kbArlJPMb%2fsQmjamvrF6GqBQkn%2bmio5p2KCmxw61O1us6wtxjxAqDLlrUOwjJOfYdZAzkapY0tKEvxigk41whGxaspQfpWp9qklswOYGbKrvgZTI2ymNRT4rtaapYi2mCQNZReGopb6T7vzcai45Wp%2bI1b3mcf8Jkuqh2ZkRrFNyncyA9RUiSiHU6zWhYEkVOXCOfaFcF8ewYFvFvgdkF9I5VLhtTdOs%2bRV2SLniuPA1iWaH9UG5pE6v4DSrb%2b3MKPGP4BFRdYcxW%2bZhAyXe24m1n%2bfPZ4dx0iJfFjzgZZ%2bhWbPAJiBXMn10u2wgZnDXVGSVVaIPhQYpwaMP67a6tO0HrWykK1t%2fWtRMsxksf7MM3vrSbGrXo6smdsffiMa9sFZs0bp4pDW4HiAcqh4BnihKdMwUzOub6km85Fz5JBESdQ19S1Wlwnbib1AD6tTkfIzRbwya%2bE3htUvKiQdFElQ4pqfIM5tKD%2bCxRwxAcqzVBsgz7r0RIuIzxmjNqv1t%2fG0b%2fKFUL%2bptqZ0gVyt7PayQ3x%2bfa2IO3i5AoY%2bOhJbRv0lpogIQbevFCjzOeSEhYs5crmYoeQAdsHWmcwoL74UpgPRRxfCzrDz43qSu0%2fDbc5zZkven8viooxblqByEoGCGC5wNUdskNZ7TxS5rACNdjusekTwv0GKyjZaeMbXC%2bYLkpolTAdtewDLn7f%2fjrztmlCYMEAAAACRP3lBTW4%2ffOG%2bf5Zz82vtZ0i37Cfi7RO9SWnScl%2fsv0Qc3vRhnf3uInQW3MU5VrwEj4z4TZ%2bmpPlMXxorAxs%2b" [X] <==== UWAGA ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [35360 2022-06-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R3 amdwddmg; C:\WINDOWS\System32\DriverStore\FileRepository\u0390931.inf_amd64_12d851e1980a239f\B386329\amdkmdag.sys [94633328 2023-04-21] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) S3 AmUStor; C:\WINDOWS\system32\drivers\AmUStorU.sys [150840 2022-03-01] (Alcorlink Corp. -> ) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [602112 2025-07-08] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [204800 2025-07-08] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [110592 2025-02-15] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\expressvpnsplittunnel.sys [45640 2021-10-08] (ExprsVPN LLC -> ExpressVPN) R3 expressvpntun; C:\WINDOWS\System32\drivers\expressvpn-tun.sys [46896 2021-10-08] (Express VPN International Ltd. -> ExpressVPN) R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.) R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333216 2025-09-19] (Microsoft Windows -> Microsoft Corporation) R3 tapexpressvpn; C:\WINDOWS\System32\drivers\tapexpressvpn.sys [61496 2021-10-08] (ExprsVPN LLC -> The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20888 2025-10-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [629128 2025-10-22] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102832 2025-10-22] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [40200 2023-11-17] (HP Inc. -> HP) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2025-11-10 18:51 - 2025-11-10 18:52 - 000027930 _____ C:\Users\Gieni\Downloads\FRST.txt 2025-11-10 18:51 - 2025-11-10 18:52 - 000000000 ____D C:\FRST 2025-11-10 18:50 - 2025-11-10 18:50 - 002443776 _____ (Farbar) C:\Users\Gieni\Downloads\FRST64.exe 2025-11-10 18:46 - 2025-11-10 18:46 - 009616736 _____ (Malwarebytes) C:\Users\Gieni\Downloads\adwcleaner.exe 2025-11-07 08:22 - 2025-11-07 08:22 - 000000000 ____D C:\ProgramData\Whesvc 2025-11-07 08:10 - 2025-11-07 08:10 - 000785630 _____ C:\WINDOWS\system32\perfh015.dat 2025-11-07 08:10 - 2025-11-07 08:10 - 000171416 _____ C:\WINDOWS\system32\perfc015.dat 2025-11-07 00:43 - 2025-11-10 12:45 - 000000000 ____D C:\WINDOWS\CbsTemp 2025-11-06 08:30 - 2025-11-06 08:30 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2025-11-04 20:41 - 2025-11-04 20:41 - 000077233 _____ C:\WINDOWS\SysWOW64\ctac.json 2025-11-04 20:41 - 2025-11-04 20:41 - 000077233 _____ C:\WINDOWS\system32\ctac.json 2025-11-04 20:41 - 2025-11-04 20:41 - 000035125 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json 2025-11-04 20:41 - 2025-11-04 20:41 - 000035125 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json 2025-11-04 20:41 - 2025-11-04 20:41 - 000001681 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json 2025-11-03 15:45 - 2025-11-03 15:45 - 000000000 ____D C:\Program Files (x86)\ScreenConnect Client (f54e48458ed500f5) 2025-11-03 15:39 - 2025-11-03 15:39 - 013920712 _____ (Nanosystems S.r.l.) C:\Users\Gieni\Downloads\Supremo (5).exe 2025-11-03 15:02 - 2025-11-03 15:02 - 000000000 ____D C:\Program Files\Common Files\DESIGNER 2025-10-29 09:13 - 2025-10-29 09:16 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2025-11-10 18:41 - 2023-05-09 14:32 - 000000000 ____D C:\Users\Gieni\AppData\Local\D3DSCache 2025-11-10 18:39 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2025-11-10 18:15 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp 2025-11-10 14:05 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness 2025-11-10 08:39 - 2025-02-16 01:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2025-11-09 08:46 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps 2025-11-09 08:37 - 2023-05-09 14:26 - 000000000 ____D C:\Users\Gieni\AppData\Local\Packages 2025-11-09 08:37 - 2021-06-25 19:11 - 000000000 ____D C:\ProgramData\Packages 2025-11-09 08:36 - 2022-05-18 09:32 - 000000000 ____D C:\Program Files\Microsoft Office 2025-11-08 08:45 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF 2025-11-07 08:10 - 2025-02-16 01:07 - 001789212 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2025-11-07 08:06 - 2025-02-16 01:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard 2025-11-07 01:21 - 2025-02-16 08:32 - 000001898 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 2025-11-07 01:21 - 2025-02-16 01:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2025-11-07 01:21 - 2021-06-25 19:10 - 000012288 ___SH C:\DumpStack.log.tmp 2025-11-07 01:17 - 2025-02-16 01:00 - 000594184 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2025-11-07 01:17 - 2024-04-01 08:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2025-11-07 01:16 - 2024-04-01 17:27 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2025-11-07 01:16 - 2024-04-01 17:26 - 000000000 ____D C:\WINDOWS\system32\OpenSSH 2025-11-07 01:16 - 2024-04-01 17:26 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\system32\F12 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ___RD C:\Program Files\Windows Defender 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\UUS 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\setup 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\oobe 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\migwiz 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Dism 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\appraiser 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellExperiences 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellComponents 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\Provisioning 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\BrowserCore 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\USOPrivate 2025-11-07 01:16 - 2024-04-01 08:26 - 000000000 ____D C:\Program Files\Common Files\System 2025-11-07 01:16 - 2024-04-01 08:21 - 000000000 ____D C:\WINDOWS\servicing 2025-11-07 00:51 - 2024-04-01 08:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2025-11-07 00:51 - 2024-04-01 08:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2025-11-07 00:30 - 2025-02-16 01:01 - 000000000 ____D C:\Users\Gieni 2025-11-07 00:30 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth 2025-11-06 17:49 - 2023-05-09 14:38 - 000002260 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2025-11-04 20:40 - 2025-02-16 01:05 - 003276800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2025-11-04 20:23 - 2023-05-11 02:50 - 000000000 ____D C:\WINDOWS\system32\MRT 2025-11-04 20:21 - 2023-05-11 02:49 - 214534944 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2025-11-03 15:49 - 2025-05-09 14:44 - 000000000 ____D C:\ProgramData\SupremoRemoteDesktop 2025-11-02 18:46 - 2025-02-16 01:06 - 000003564 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2025-11-02 18:46 - 2025-02-16 01:06 - 000003438 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2025-11-02 08:45 - 2021-06-25 19:10 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2025-11-01 08:33 - 2025-02-16 01:06 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2154322142-1083756757-1331411065-1001 2025-11-01 08:33 - 2025-02-16 01:06 - 000003576 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2154322142-1083756757-1331411065-1001 2025-11-01 08:33 - 2025-02-16 01:06 - 000003362 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2154322142-1083756757-1331411065-1001 2025-11-01 08:33 - 2023-05-09 14:34 - 000002390 _____ C:\Users\Gieni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2025-10-22 21:50 - 2021-06-25 19:10 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2025-10-22 14:20 - 2023-05-09 14:56 - 000000000 ____D C:\Users\Gieni\AppData\Local\Messenger ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================