Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 20-11-2025 Uruchomiony przez Marcin (administrator) DESKTOP-59CT2RP (MSI MS-7A69) (08-01-2026 12:38:03) Uruchomiony z C:\Users\Marcin\Downloads\FRST64.exe Załadowane profile: Marcin Platforma: Microsoft Windows 10 Pro Wersja 22H2 19045.6466 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9228776 2017-06-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [] => [X] HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\Run: [Marcin] => cmd.exe /c start www.url-advertisement.org (Brak pliku) <==== UWAGA HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\Policies\Explorer\DisallowRun: [1] Mshta.exe HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\Policies\Explorer\DisallowRun: [2] powershell.exe HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\MountPoints2: F - "F:\setup.exe" HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\MountPoints2: I - "I:\setup.exe" HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\MountPoints2: {343708cd-b6d7-11eb-b726-309c2343f0fa} - "I:\OnePlus_setup.exe" /s HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\MountPoints2: {34370f84-b6d7-11eb-b726-309c2343f0fa} - "I:\HiSuiteDownLoader.exe" HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\MountPoints2: {663b4635-463f-11ec-b73e-309c2343f0fa} - "J:\ready_for_assistant.exe" HKU\S-1-5-21-479834947-2641734155-682898169-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\DREAMA~1.SCR [141312 2014-06-17] () [Brak podpisu cyfrowego] HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [54944 2015-03-16] (Adobe Systems, Incorporated -> Adobe Systems Inc) HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files (x86)\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2025-11-06] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\143.0.7499.192\Installer\chrmstp.exe [2026-01-07] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{9459C573-B17A-45AE-9F64-1857B5D58CEE}] -> "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --msedge --channel=stable HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {9F82820C-5DCD-4A42-98B2-3259D23D8203} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1574856 2024-09-25] (Adobe Inc. -> Adobe Inc.) Task: {4919A4AF-ED11-4F9F-9C93-B5FBFE666BE0} - System32\Tasks\ASC_SkipUac_Marcin => D:\sc\P-1810ASCP\Advanced System Care Pro 18.1.0.201\App\AdvancedSystemCare\ASC.exe [11146080 2025-01-08] (IObit CO., LTD -> IObit) [Brak podpisu cyfrowego] -> D:\sc\P-1810ASCP\Advanced System Care Pro 18.1.0.201\App\AdvancedSystemCare\\/SkipUac Task: {EE94B518-C38F-4EB4-ACD8-E9DF92EF45B2} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [6089584 2025-10-14] (Microsoft Windows -> Microsoft Corporation) Task: {467EFAE0-01AB-441F-B480-6B0F02DC1269} - System32\Tasks\dts_apo_service_task => C:\Program Files (x86)\DTS, Inc\DTS Audio\dts_apo_task.exe [18872 2018-01-31] (DTS, Inc. -> ) Task: {33DB1BAE-EC4F-4627-B769-3D9F6D1DCB86} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{75109726-A4C3-4F41-9885-8E0B27F8DED0} => C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe [7056536 2025-11-26] (Google LLC -> Google LLC) Task: {047DA20D-00FC-4F81-B9F4-2DA62229B177} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\IntelPTTEKRecertification.exe [855664 2023-12-14] (Intel Corporation -> Intel(R) Corporation) Task: {02BBC8EA-CBDB-4C27-9994-F4F8DDC6E767} - System32\Tasks\Marcin => C:\Windows\system32\cmd.exe [289792 2024-05-15] (Microsoft Windows -> Microsoft Corporation) -> /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v Marcin /t REG_SZ /d "cmd.exe /c start www.url-advertisement.org" <==== UWAGA Task: {A102B798-5E6E-4C0F-82A9-BCB79CA9D77E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1FA1A41F-7633-45B2-94DC-49F5BFA9F87D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FF03F745-5CE2-4F02-BD3C-9CB52E9F8B46} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AF4C5F73-A44A-45F8-9299-76EB32D184A3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpCmdRun.exe [1803016 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {62A91A91-0608-45DA-8F4D-FBA0F6C8803B} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-479834947-2641734155-682898169-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [696960 2026-01-08] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). Task: {10FA98A9-4077-435A-96F9-FD3C5B4C46DC} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2026-01-08] (Mozilla Corporation -> Mozilla Foundation) Task: {2AF1AC6E-57A6-4504-8E71-00A70F0C4989} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3324528 2025-10-15] (NVIDIA Corporation -> NVIDIA Corporation) Task: {754DD374-B68D-4C71-B450-AA3B01458D8C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) Task: {4CE264CF-3C01-4253-96FA-D8ADB3E3AD86} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation) Task: {6A0F7A46-2301-4DA1-8F2A-C1FD1EEB3A13} - System32\Tasks\ScpUpdater => D:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe [460480 2016-04-12] (Open Source Developer, Benjamin Höglinger-Stelzer -> Nefarius Software Solutions) -> D:\Program Files\Nefarius Software Solutions\ScpToolkit\\/silent Task: {6F47360B-FB02-4231-8684-0C63C4B56B83} - System32\Tasks\Uninstaller_SkipUac_Marcin => "C:\\Users\\Marcin\\Downloads\\P-15202IOUP\\IObit Uninstaller Pro v15.2.0.2\\App\\uninstaller\\IObitUninstaler.exe" -> C:\\Users\\Marcin\\Downloads\\P-15202IOUP\\IObit Uninstaller Pro v15.2.0.2\\App\\uninstaller\\\/UninstallExplorer (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\WINDOWS\Tasks\ScpUpdater.job => D:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpUpdater.exe ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{a6a88e23-ec90-4911-808e-44261cdee097}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{e14b7d5d-1d20-4539-bf32-d8b19caa6292}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{e14b7d5d-1d20-4539-bf32-d8b19caa6292}: [DhcpDomain] home Edge: ======= Edge Profile: C:\Users\Marcin\AppData\Local\Microsoft\Edge\User Data\Default [2025-12-29] Edge Extension: (Closed tabs) - C:\Users\Marcin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\eonffnnfmbfnmjpaiigdclmfelolemah [2025-01-06] Edge Extension: (Dokumenty Google offline) - C:\Users\Marcin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-21] Edge Extension: (Edge relevant text changes) - C:\Users\Marcin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-02] Edge Extension: (IDM Integration Module) - C:\Users\Marcin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\llbjbkhnmlidjebalopleeepgdfgcpec [2025-10-15] Edge HKU\S-1-5-21-479834947-2641734155-682898169-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx [2024-11-17] FireFox: ======== FF DefaultProfile: kyw088oa.default-1709229249328 FF ProfilePath: C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\kyw088oa.default-1709229249328 [2026-01-08] FF Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\kyw088oa.default-1709229249328\Extensions\ascsurfingprotectionnew@iobit.com.xpi [2024-07-02] FF Extension: (New Tab) - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\kyw088oa.default-1709229249328\Extensions\newtab@mozilla.org.xpi [2026-01-08] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn => nie znaleziono FF HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2024-09-23] FF HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Marcin\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\Marcin\AppData\Roaming\IDM\idmmzcc5 [2018-09-09] [Przestarzałe] [Brak podpisu cyfrowego] FF HKU\S-1-5-21-479834947-2641734155-682898169-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-19] [Przestarzałe] FF Plugin: @videolan.org/vlc,version=3.0.17.3 -> D:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.21 -> D:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.6 -> D:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems) Chrome: ======= CHR Profile: C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default [2026-01-08] CHR Notifications: Default -> hxxps://2ntrfi.parthonylogles.com; hxxps://izjec2.scurdpic.com; hxxps://paymentsweb.org CHR Session Restore: Default -> [funkcja włączona] CHR Extension: (Prezentacje) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-08-26] CHR Extension: (Dokumenty) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-08-26] CHR Extension: (Dysk Google) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-22] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-12-21] CHR Extension: (Closed tabs) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eonffnnfmbfnmjpaiigdclmfelolemah [2021-07-11] CHR Extension: (Arkusze) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-08-26] CHR Extension: (Dokumenty Google offline) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-12-15] CHR Extension: (DualSafe Password Manager & Skarbiec Cyfrowy) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgbjhdkjmpgjgcbcdlhkokkckpjmedgc [2025-04-07] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Extension: (Gmail) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23] CHR HKLM\...\Chrome\Extension: [lgbjhdkjmpgjgcbcdlhkokkckpjmedgc] CHR HKU\S-1-5-21-479834947-2641734155-682898169-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKU\S-1-5-21-479834947-2641734155-682898169-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lgbjhdkjmpgjgcbcdlhkokkckpjmedgc] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [lgbjhdkjmpgjgcbcdlhkokkckpjmedgc] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-09-25] (Adobe Inc. -> Adobe Inc.) S3 AdvancedSystemCareService18; D:\sc\P-1810ASCP\Advanced System Care Pro 18.1.0.201\App\AdvancedSystemCare\ASCService.exe [1851760 2024-08-13] (IObit CO., LTD -> IObit) R2 AdvancedSystemCareService19; D:\P-1910176ASCP\Advanced SystemCare Pro 19.1.0.176\App\Advanced SystemCare\ASCService.exe [1858264 2025-11-28] (IObit CO., LTD -> IObit) S3 Ds3Service; D:\Program Files\Nefarius Software Solutions\ScpToolkit\ScpService.exe [394944 2016-04-12] (Open Source Developer, Benjamin Höglinger-Stelzer -> Scarlet.Crush Productions) S3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Audio\dts_apo_service.exe [26560 2018-01-31] (DTS, Inc. -> ) S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1673288 2020-07-15] (GOG Sp. z o.o. -> GOG.com) S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6821960 2020-06-14] (GOG Sp. z o.o. -> GOG.com) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MpDefenderCoreService.exe [2063376 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) S3 MSIREGISTER_MR; C:\MSI\MSIRegister\MSIRegisterService.exe [132048 2017-02-21] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmd.inf_amd64_aa54f7a758543a0a\Display.NvContainer\NVDisplay.Container.exe [1275024 2024-11-19] (NVIDIA Corporation -> NVIDIA Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 SmartConnect; C:\Program Files\Lenovo\Ready For Assistant\ReadyForService.exe [333824 2024-08-15] (Lenovo -> Motorola) S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182392 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe [4426832 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe [290704 2025-12-18] (Microsoft Windows Publisher -> Microsoft Corporation) S3 XperiaCompanionService; C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe [2575360 2020-09-02] (Sony) [Brak podpisu cyfrowego] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R3 AscFileFilter; D:\P-1910176ASCP\Advanced SystemCare Pro 19.1.0.176\App\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [47904 2025-07-23] (IObit CO., LTD -> IObit) R3 AscRegistryFilter; D:\P-1910176ASCP\Advanced SystemCare Pro 19.1.0.176\App\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [31944 2025-08-08] (Microsoft Windows Hardware Compatibility Publisher -> IObit) S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 cpuz145; Brak ImagePath S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 HtcVCom32; C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (Sqa.com(Test) -> QUALCOMM Incorporated) [Brak podpisu cyfrowego] R2 IDMWFP; C:\WINDOWS\system32\DRIVERS\idmwfp.sys [173736 2023-11-25] (Microsoft Windows Hardware Compatibility Publisher -> Tonec Inc.) S3 IMFEFSFileControl; Brak ImagePath R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2025-11-27] (Microsoft Windows -> Microsoft Corporation) R3 lenovoDriverBus; C:\WINDOWS\System32\drivers\lenovoDriverBus.sys [103152 2024-08-15] (Lenovo -> Lenovo Inc.) R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [261032 2020-03-15] (Malwarebytes Corporation -> Malwarebytes) R2 RFDriveFs2; C:\Program Files\Lenovo\Ready For Assistant\drivers\FileSystem\RFDriveFs2.sys [412984 2024-06-24] (Lenovo -> Motorola) R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions) S3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [47824 2019-08-02] (SteelSeries ApS -> SteelSeries ApS) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43640 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 UsbNcm; C:\WINDOWS\System32\drivers\UsbNcm.sys [114176 2019-12-07] (Microsoft Windows -> ) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2025-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [635272 2025-12-18] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2025-12-18] (Microsoft Windows -> Microsoft Corporation) R2 WtfEngineDrv; C:\WINDOWS\system32\DRIVERS\WtfEngineDrv.sys [27904 2016-02-01] (Initex -> AAA Internet Publishing, Inc.) S3 cpuz150; \??\C:\WINDOWS\temp\cpuz150\cpuz150_x64.sys [X] <==== UWAGA S3 cpuz154; \??\C:\WINDOWS\temp\cpuz154\cpuz154_x64.sys [X] <==== UWAGA ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (Wszystkie) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2026-01-08 12:38 - 2026-01-08 12:38 - 000021362 _____ C:\Users\Marcin\Downloads\FRST.txt 2026-01-08 12:38 - 2026-01-08 12:38 - 000000000 ____D C:\FRST 2026-01-08 12:01 - 2026-01-08 12:01 - 002444288 _____ (Farbar) C:\Users\Marcin\Downloads\FRST64.exe 2026-01-08 11:46 - 2026-01-08 11:58 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\IObit 2026-01-08 11:44 - 2026-01-08 11:44 - 085237760 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit 2026-01-08 11:44 - 2026-01-08 11:44 - 006737920 _____ C:\WINDOWS\system32\config\DRIVERS.iobit 2026-01-08 11:44 - 2026-01-08 11:44 - 000921600 _____ C:\WINDOWS\system32\config\DEFAULT.iobit 2026-01-08 11:44 - 2026-01-08 11:44 - 000036864 _____ C:\WINDOWS\system32\config\SAM.iobit 2026-01-08 11:44 - 2026-01-08 11:44 - 000028672 _____ C:\WINDOWS\system32\config\SECURITY.iobit 2026-01-08 11:35 - 2026-01-08 11:58 - 000000000 ____D C:\ProgramData\IObit 2026-01-08 09:37 - 2026-01-08 11:28 - 000000000 ____D C:\Program Files\Mozilla Firefox 2025-12-29 10:43 - 2025-12-29 10:43 - 000000000 ____D C:\Program Files (x86)\IObit 2025-12-29 10:02 - 2025-12-29 10:02 - 000003338 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_Marcin 2025-12-28 10:53 - 2025-12-28 10:55 - 335597712 _____ C:\Users\Marcin\Downloads\Pat-Mat_Win_EN-CS_Disc-Image.zip 2025-12-28 10:33 - 2025-12-28 17:15 - 000002086 _____ C:\Users\Marcin\Desktop\Sąsiedzi #1.lnk 2025-12-28 10:33 - 2025-12-28 10:33 - 000000000 ____D C:\WINDOWS\DD1865F0AD7340FBB23E1822E02396FF.TMP 2025-12-28 10:33 - 2025-12-28 10:33 - 000000000 ____D C:\Users\Marcin\Documents\patamat 2025-12-28 10:33 - 2025-12-28 10:33 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sąsiedzi 2025-12-28 10:33 - 2025-12-28 10:33 - 000000000 ____D C:\Program Files (x86)\Centauri 2025-12-28 10:33 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll 2025-12-28 10:32 - 2025-12-28 10:33 - 256221478 _____ C:\Users\Marcin\Downloads\Pat-Mat_Win_PL_Setup.zip 2025-12-24 14:16 - 2025-12-24 14:16 - 000000000 ____D C:\Users\Marcin\AppData\Local\SHf_BonusContent 2025-12-21 18:41 - 2025-12-21 18:41 - 000000000 ____D C:\Users\Marcin\Downloads\AiwnIn2226pVXWBDLAAx6SG ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2026-01-08 12:38 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2026-01-08 12:30 - 2024-02-29 19:17 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2026-01-08 12:25 - 2021-12-26 10:43 - 000000000 ____D C:\WINDOWS\SystemTemp 2026-01-08 12:24 - 2021-04-29 19:52 - 001921550 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2026-01-08 12:24 - 2019-12-07 16:09 - 000823314 _____ C:\WINDOWS\system32\perfh015.dat 2026-01-08 12:24 - 2019-12-07 16:09 - 000171332 _____ C:\WINDOWS\system32\perfc015.dat 2026-01-08 12:24 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2026-01-08 12:21 - 2024-12-22 19:44 - 000000000 ____D C:\ProgramData\ProductData3 2026-01-08 12:20 - 2021-04-29 19:48 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2026-01-08 12:20 - 2021-04-29 19:42 - 000008192 ___SH C:\DumpStack.log.tmp 2026-01-08 12:20 - 2018-08-18 18:28 - 000000000 ____D C:\ProgramData\NVIDIA 2026-01-08 12:19 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2026-01-08 11:50 - 2024-12-22 19:44 - 000001224 _____ C:\ProgramData\pdinst.ini 2026-01-08 11:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2026-01-08 11:28 - 2018-10-28 18:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2026-01-08 11:07 - 2024-02-29 19:17 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2026-01-08 11:07 - 2018-10-28 18:16 - 000001095 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2026-01-07 19:45 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2026-01-07 11:28 - 2018-08-26 14:49 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2026-01-07 11:28 - 2018-08-26 14:49 - 000002272 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2026-01-06 14:09 - 2018-08-18 18:24 - 000000000 ____D C:\Users\Marcin\AppData\Local\D3DSCache 2026-01-05 18:51 - 2021-04-29 19:43 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2026-01-04 13:28 - 2018-12-28 11:09 - 000000000 ____D C:\Users\Marcin\AppData\Roaming\vlc 2025-12-30 09:24 - 2018-09-09 17:33 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager 2025-12-29 10:47 - 2018-08-26 20:16 - 000000000 ____D C:\Users\Marcin\AppData\Local\CrashDumps 2025-12-29 10:13 - 2019-12-31 14:07 - 000000000 ____D C:\Program Files\AVAST Software 2025-12-29 10:08 - 2018-08-26 16:05 - 000003820 _____ C:\Users\Marcin\Desktop\Nowy dokument tekstowy.txt 2025-12-29 08:52 - 2018-08-18 17:57 - 000000000 ____D C:\Users\Marcin\AppData\Local\Packages 2025-12-22 17:51 - 2023-10-20 20:08 - 000003564 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2025-12-22 17:51 - 2023-10-20 20:08 - 000003438 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2025-12-18 19:17 - 2018-08-18 17:54 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2025-12-11 19:22 - 2018-08-20 19:30 - 000000000 ____D C:\WINDOWS\system32\MRT 2025-12-11 19:19 - 2018-08-20 19:30 - 218369424 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2025-12-11 13:18 - 2021-04-29 19:44 - 000000000 ____D C:\Users\Marcin ==================== Pliki w katalogu głównym wybranych folderów ======== 2020-03-09 11:14 - 2020-11-06 08:25 - 000000004 _____ () C:\ProgramData\lock.dat 2020-03-09 11:15 - 2020-11-06 08:25 - 000000004 _____ () C:\ProgramData\rc.dat 2020-03-09 11:14 - 2020-03-09 11:14 - 000000008 _____ () C:\ProgramData\ts.dat 2020-06-04 19:23 - 2020-08-30 13:41 - 000028672 _____ () C:\Users\Marcin\AppData\Roaming\crash.bin 2019-05-30 23:10 - 2019-05-30 23:10 - 000000043 _____ () C:\Users\Marcin\AppData\Roaming\WB.CFG 2024-09-04 13:32 - 2024-09-05 07:54 - 000000615 _____ () C:\Users\Marcin\AppData\Local\oobelibMkey.log 2020-07-02 11:07 - 2020-07-02 11:07 - 082395216 _____ (Sony) C:\Users\Marcin\AppData\Local\pcc.exe 2018-08-18 18:25 - 2018-08-18 18:25 - 000007625 _____ () C:\Users\Marcin\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) UWAGA: ==> Nie można uzyskać dostępu do BCD. -> ==================== Koniec FRST.txt ========================