Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 23-02-2026 Uruchomiony przez seth9 (administrator) DESKTOP-1DPULQM (Dell Inc. Precision WorkStation T3500) (23-02-2026 18:46:13) Uruchomiony z E:\Downloads\FRST64.exe Załadowane profile: seth9 Platforma: Microsoft Windows 10 Pro Wersja 22H2 19045.6466 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (C:\Program Files\AMD\CNext\CNext\amddvr.exe ->) (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe (C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe (C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2602.50221.0_x64__8wekyb3d8bbwe\M365Copilot.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\145.0.3800.70\msedgewebview2.exe <12> (DriverStore\FileRepository\u0366524.inf_amd64_09ec4a1cc3957750\B369435\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0366524.inf_amd64_09ec4a1cc3957750\B369435\atieclxx.exe (E:\Programy\Glass wire\GlassWire\GWCtlSrv.exe ->) (domotz inc -> ) E:\Programy\Glass wire\GlassWire\GWCrashpadHandler.exe <3> (E:\Programy\Glass wire\GlassWire\GWCtlSrv.exe ->) (domotz inc -> GlassWire) E:\Programy\Glass wire\GlassWire\GWIdlMon.exe (explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2> (explorer.exe ->) (domotz inc -> GlassWire) E:\Programy\Glass wire\GlassWire\GlassWire.exe (explorer.exe ->) (Winstep Software Technologies) [Brak podpisu cyfrowego] C:\Program Files (x86)\Winstep\Nexus.exe (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2602.50221.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <16> (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0366524.inf_amd64_09ec4a1cc3957750\B369435\atiesrxx.exe (services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (services.exe ->) (domotz inc -> GlassWire) E:\Programy\Glass wire\GlassWire\GWCtlSrv.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) E:\Programy\TeamViewer_Service.exe (services.exe ->) (Winstep Software Technologies) [Brak podpisu cyfrowego] C:\Program Files (x86)\Winstep\WsxService.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\seth9\AppData\Local\Microsoft\OneDrive\26.017.0126.0002_1\FileCoAuth.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.6465_none_7e0fb53c7c8be091\TiWorker.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [330040 2014-02-11] (Hewlett-Packard Company -> Hewlett-Packard Company) HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\Run: [Nexus] => C:\Program Files (x86)\Winstep\Nexus.exe [18169472 2024-04-28] (Winstep Software Technologies) [Brak podpisu cyfrowego] HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [408976 2021-07-06] (AVB Disc Soft, SIA -> Disc Soft Ltd) HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\Run: [BlueMail] => C:\Windows\explorer.exe me.blueone.win:noopt:hidden (Brak pliku) <==== UWAGA HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\Run: [Microsoft Edge Update] => C:\Users\seth9\AppData\Local\Microsoft\EdgeUpdate\1.3.221.3\MicrosoftEdgeUpdateCore.exe [279136 2026-02-13] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [41732568 2026-02-17] (Adobe Inc. -> Adobe Systems Incorporated) HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\Run: [GlassWire] => E:\Programy\Glass wire\GlassWire\glasswire.exe [12403856 2025-08-13] (domotz inc -> GlassWire) HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\...\MountPoints2: {5b0fd444-ddda-11eb-9f7b-b8ac6f7f2209} - "L:\SETUP.EXE" HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\Windows\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [Brak podpisu cyfrowego] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\145.0.7632.76\Installer\chrmstp.exe [2026-02-18] (Google LLC -> Google LLC) ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {20F53C76-1047-4C47-82B1-F6CB5F77D69E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.) Task: {55860C73-76D6-4088-B0CE-4B6F41F40CEE} - System32\Tasks\e-pity2022_kwiecien => C:\Program Files (x86)\e-file\e-pity\Assets\signxml.exe [35328 2023-04-07] (e-file sp. z o.o. sp. k.) [Brak podpisu cyfrowego] Task: {68C5B5DA-7A2B-4CE6-93AF-AE36A6810808} - System32\Tasks\e-pity2022_styczen => C:\Program Files (x86)\e-file\e-pity\Assets\signxml.exe [35328 2023-04-07] (e-file sp. z o.o. sp. k.) [Brak podpisu cyfrowego] Task: {F2E99F8D-BC29-4A99-9147-E5384DA9AD6A} - System32\Tasks\Game_Booster_AutoUpdate => E:\Programy\Game Booster 3\AutoUpdate.exe /AUTORUN (Brak pliku) Task: {24956D3E-3EEA-40C2-87BF-684983705DDF} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem144.0.7547.0{EF8C45B4-1A1A-41B0-85CE-4F737826C1A7} => C:\Program Files (x86)\Google\GoogleUpdater\144.0.7547.0\updater.exe [7056536 2025-11-26] (Google LLC -> Google LLC) Task: {DF41AD2E-D13A-4E74-BE50-ED00E0EA77EA} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [89840 2014-10-19] (Hewlett-Packard Company -> Hewlett Packard) Task: {7E96810F-3292-4626-9DC3-B03B5869747F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2118144 2024-07-18] () [Brak podpisu cyfrowego] Task: {9E33B3EB-B091-4A8E-A6E4-6B1867D44FC9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1B7B7C99-A5B9-42AA-A1CF-8C20A28EF857} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F9D99D24-A62F-48FC-9A35-A3BA28622D6E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {3EF2BEBB-2DC2-4C8F-AA9D-AAD5A85D2C76} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpCmdRun.exe [1786528 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {183CB72D-7F21-4CCD-9EC7-93C6716F0EC1} - System32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-3041043692-3727988098-2832288276-1001Core{1E255B76-31AE-443A-BFA5-B1F2C16ACE88} => C:\Users\seth9\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [205920 2025-12-22] (Microsoft Corporation -> Microsoft Corporation) Task: {67C16DDE-14DD-42C1-8FD2-3D1D8F26E372} - System32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-3041043692-3727988098-2832288276-1001UA{18FB78A6-5DE8-4A75-9650-DE59CD184D37} => C:\Users\seth9\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [205920 2025-12-22] (Microsoft Corporation -> Microsoft Corporation) Task: {1E446FBB-08F8-44B4-845B-9B9C13F11320} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [680064 2026-02-16] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). Task: {FD216FB6-1B8E-4518-BB68-C21D74B1E2B5} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3041043692-3727988098-2832288276-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [680064 2026-02-16] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). Task: {3E9D97B1-41A2-4989-B752-3D4C71E54E8D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2026-02-16] (Mozilla Corporation -> Mozilla Foundation) Task: {CFD4FBE6-36E9-4704-BB84-4734F99E753E} - System32\Tasks\PlitchSkipUAC => E:\Games\PLITCH\PLITCH.exe (Brak pliku) Task: {5F801197-5FB7-4E4F-AD67-1A7ED165B8AE} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [49032 2018-11-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {5D7EF1DE-6156-4961-91E1-8A3EE16125B4} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [63880 2018-11-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{8c3ae280-8207-4d04-bad5-bb6de7933228}: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox FF DefaultProfile: k58i6j2d.default-release -> 308046B0AF4A39CB FF ProfilePath: C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\w8w4j7r3.default [2020-10-08] FF ProfilePath: C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release [2026-02-23] FF DownloadDir: E:\Downloads FF Session Restore: Mozilla\Firefox\Profiles\k58i6j2d.default-release -> [funkcja włączona] FF Extension: (AdBlocker Ultimate) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\adblockultimate@adblockultimate.net.xpi [2026-02-19] FF Extension: (Bloker reklam AdGuard) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\adguardadblocker@adguard.com.xpi [2026-01-28] FF Extension: (Cookie AutoDelete) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\CookieAutoDelete@kennydo.com.xpi [2024-06-26] FF Extension: (GIPHY for Firefox) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\gt@giphy.com.xpi [2024-10-19] FF Extension: (HTTPS Everywhere) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\https-everywhere@eff.org.xpi [2021-07-16] FF Extension: (Użyj Google Translate) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2025-10-09] FF Extension: (Privacy Badger) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2025-12-16] FF Extension: (New Tab) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\newtab@mozilla.org.xpi [2026-02-13] FF Extension: (Creates a sliding puzzle from any image. Just right-click on the image and select the “Puzzle Creator” option.) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\puzzle-creator@mozilla.org.xpi [2024-04-26] FF Extension: (S3.Translator) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\s3@translator.xpi [2025-02-28] FF Extension: (uBlock Origin) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-02-22] FF Extension: (Video Background Play Fix) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\video-bg-play@timdream.org.xpi [2024-12-03] FF Extension: (Viewhance) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{00000c4c-fcfd-49bc-9f0d-78db44456c9c}.xpi [2024-06-25] FF Extension: (YouTube Downloader (UDL Helper)) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{08aaa0e6-3ab6-4afd-9b94-319f19e096fa}.xpi [2025-03-07] FF Extension: (VPN) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{31ef552b-41be-460c-b61d-342bcabdc2e7}.xpi [2021-04-09] FF Extension: (YouTube™ use Flash Player) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{3cb66f33-d9c7-441e-9f24-82ce974ba6b2}.xpi [2024-06-25] FF Extension: (FlashPlayer - SWF to HTML) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{580d99ee-bcc9-47b2-a5d9-6a2c8aa855a7}.xpi [2025-08-17] FF Extension: (Pixiv Toolkit) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{6706d386-2d33-4e1e-bbf1-51b9e1ce47e1}.xpi [2024-07-09] FF Extension: (YouTube High Definition) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2024-09-02] FF Extension: (Ruffle - Flash Emulator) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{b5501fd1-7084-45c5-9aa6-567c2fcf5dc6}.xpi [2026-02-12] FF Extension: (Java-Redirector) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{b75af37b-574d-4746-ac34-629fa349cf81}.xpi [2024-01-01] FF Extension: (Video DownloadHelper) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-06-04] FF Extension: (Flash Video Player for Facebook™) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{d0bfdcce-52c7-4b32-bb45-948f62db8d3f}.xpi [2024-06-26] FF Extension: (javascript) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{d4bc778f-3a98-44f4-9b2e-45fab92a21db}.xpi [2024-06-26] FF Extension: (YouTube Flash Video Player) - C:\Users\seth9\AppData\Roaming\Mozilla\Firefox\Profiles\k58i6j2d.default-release\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2024-06-26] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> E:\Programy\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-02-17] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) Edge: ======= Edge Profile: C:\Users\seth9\AppData\Local\Microsoft\Edge\User Data\Default [2026-02-17] Edge Extension: (Adblock) - C:\Users\seth9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\dckihkcdmjmlkndgmmgplpcnkmdpangb [2020-12-11] Edge Extension: (Dokumenty Google offline) - C:\Users\seth9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-02-01] Edge Extension: (Online Security) - C:\Users\seth9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl [2026-02-11] Edge Extension: (Edge relevant text changes) - C:\Users\seth9\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-03] Edge HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl] Edge HKLM-x32\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl] Chrome: ======= CHR Profile: C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default [2025-09-11] CHR HomePage: Default -> hxxp://www.gazeta.pl/0,0.html?p=190 CHR StartupUrls: Default -> "hxxp://www.gazeta.pl/0,0.html?p=190" CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms} CHR DefaultSearchKeyword: Default -> duckduckgo.com CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list CHR Extension: (Dokumenty Google offline) - C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-09-11] CHR Extension: (AdBlock — najlepszy bloker reklam) - C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-09-11] CHR Extension: (Boczna lista zakładek) - C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdbnofccmhefkmjbkkdkfiicjkgofkdh [2024-10-07] CHR Extension: (Online Security) - C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default\Extensions\llbcnfanfmjhpedaedhbcnpgeepdnnok [2025-09-11] CHR Extension: (Morpheon Dark) - C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default\Extensions\mafbdhjdkjnoafhfelkjpchpaepjknad [2024-06-25] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\seth9\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-06-25] CHR HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKU\S-1-5-21-3041043692-3727988098-2832288276-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4816272 2021-07-06] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 DiscordSystemHelper; C:\Program Files\Common Files\Discord\Discord\DiscordSystemHelper.exe [2131840 2025-11-07] (discord-code-sign-windows-admin -> Discord Inc.) R2 GlassWire; E:\Programy\Glass wire\GlassWire\GWCtlSrv.exe [9267856 2025-08-13] (domotz inc -> GlassWire) S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [Brak podpisu cyfrowego] R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243720 2025-07-09] (HP Inc. -> HP Inc.) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe [2067464 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) S3 Microsoft SharePoint Workspace Audit Service; E:\Programy\Office14\GROOVE.EXE [51740536 2011-06-12] (Microsoft Corporation -> Microsoft Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-10-15] (Microsoft Windows Publisher -> Microsoft Corporation) R2 TeamViewer; E:\Programy\TeamViewer_Service.exe [13103632 2020-09-17] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe [4435096 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe [290744 2026-02-10] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService.exe [776704 2023-11-18] (Winstep Software Technologies) [Brak podpisu cyfrowego] R2 WirelessKB850NotificationService; C:\Windows\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation) ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [Brak podpisu cyfrowego] S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [42256 2021-07-06] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [59360 2021-07-06] (AVB Disc Soft, SIA -> Disc Soft Ltd) R1 gwdrv; C:\Windows\System32\drivers\gwdrv.sys [48808 2025-08-13] (Microsoft Windows Hardware Compatibility Publisher -> Domotz Inc) R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82352 2026-02-10] (Microsoft Windows -> Microsoft Corporation) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [24064 2020-10-09] (Microsoft Corporation) [Brak podpisu cyfrowego] S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21888 2026-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [635272 2026-02-10] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [102832 2026-02-10] (Microsoft Windows -> Microsoft Corporation) S3 WinRing0_1_2_0; E:\Programy\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (Noriyuki MIYAZAKI -> OpenLibSys.org) S3 cpuz145; \??\C:\Windows\temp\cpuz145\cpuz145_x64.sys [X] <==== UWAGA S3 hfFilter; system32\drivers\hfFilter.sys [X] ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2026-02-23 18:45 - 2026-02-23 18:46 - 000000000 ____D C:\FRST 2026-02-22 21:56 - 2026-02-22 21:56 - 000000000 ____D C:\Users\seth9\AppData\Local\glasswire 2026-02-22 21:56 - 2026-02-22 21:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GlassWire 2026-02-22 21:55 - 2026-02-22 21:56 - 000000000 ____D C:\ProgramData\glasswire 2026-02-16 19:52 - 2026-02-16 19:52 - 000000000 ____D C:\Program Files\Mozilla Firefox 2026-02-16 12:39 - 2026-02-16 12:39 - 000000000 ____D C:\Users\seth9\Documents\Doc 2026-01-24 01:11 - 2026-01-24 01:11 - 000000000 ____D C:\Program Files\Common Files\Discord ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2026-02-23 18:44 - 2022-02-10 10:19 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2026-02-23 18:31 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2026-02-23 17:22 - 2020-10-07 16:28 - 000000000 ____D C:\Windows\system32\SleepStudy 2026-02-23 16:50 - 2020-10-07 16:35 - 000000000 ____D C:\Users\seth9\AppData\Local\D3DSCache 2026-02-23 16:50 - 2019-12-07 10:14 - 000000000 ____D C:\Windows\AppReadiness 2026-02-23 15:11 - 2022-02-14 01:16 - 000000000 ____D C:\Windows\SystemTemp 2026-02-22 21:56 - 2019-12-07 10:13 - 000000000 ____D C:\Windows\INF 2026-02-22 21:55 - 2020-10-12 18:10 - 000000000 ____D C:\ProgramData\Package Cache 2026-02-22 20:52 - 2021-01-20 22:38 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task 2026-02-22 20:49 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2026-02-22 12:49 - 2020-11-10 18:14 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2026-02-19 20:03 - 2024-06-25 17:56 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2026-02-19 11:10 - 2025-04-16 17:20 - 000000000 ____D C:\Users\seth9\Desktop\liluAI 2026-02-19 11:08 - 2020-10-26 17:09 - 000000000 ____D C:\Users\seth9\AppData\Roaming\Microsoft\Word 2026-02-18 21:55 - 2024-06-25 18:17 - 000002213 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2026-02-18 14:52 - 2025-01-28 23:57 - 000003580 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3041043692-3727988098-2832288276-1001 2026-02-18 14:52 - 2021-12-11 00:21 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3041043692-3727988098-2832288276-1001 2026-02-18 14:52 - 2020-10-07 16:37 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3041043692-3727988098-2832288276-1001 2026-02-18 14:52 - 2020-10-07 16:34 - 000002383 _____ C:\Users\seth9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2026-02-17 14:06 - 2021-10-06 12:21 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla 2026-02-17 14:06 - 2020-10-08 09:36 - 000001089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2026-02-16 22:35 - 2020-10-26 17:09 - 000000000 ____D C:\Users\seth9\AppData\Roaming\Microsoft\Office 2026-02-16 21:34 - 2021-02-04 17:17 - 000000000 ____D C:\Users\seth9\AppData\Roaming\Microsoft\Excel 2026-02-16 12:38 - 2025-06-10 11:35 - 000000000 ____D C:\Users\seth9\Desktop\mama 2026-02-13 18:11 - 2023-01-05 10:03 - 000003904 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-3041043692-3727988098-2832288276-1001UA{18FB78A6-5DE8-4A75-9650-DE59CD184D37} 2026-02-13 18:11 - 2023-01-05 10:03 - 000003838 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskUserS-1-5-21-3041043692-3727988098-2832288276-1001Core{1E255B76-31AE-443A-BFA5-B1F2C16ACE88} 2026-02-13 18:09 - 2020-11-10 18:14 - 000003564 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2026-02-13 18:09 - 2020-11-10 18:14 - 000003438 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2026-02-11 19:14 - 2020-10-10 11:37 - 000000000 ____D C:\Windows\system32\MRT 2026-02-11 19:11 - 2020-10-10 11:37 - 221154392 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2026-02-10 10:22 - 2020-10-07 16:28 - 000000000 ____D C:\Windows\system32\Drivers\wd 2026-02-06 19:22 - 2020-10-08 09:36 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2026-02-03 00:34 - 2020-10-07 16:34 - 000000000 ____D C:\Users\seth9 2026-02-02 22:51 - 2020-10-07 16:35 - 001768984 _____ C:\Windows\system32\PerfStringBackup.INI 2026-02-02 22:51 - 2019-12-07 16:09 - 000784578 _____ C:\Windows\system32\perfh015.dat 2026-02-02 22:51 - 2019-12-07 16:09 - 000152474 _____ C:\Windows\system32\perfc015.dat 2026-02-02 22:44 - 2020-10-07 16:28 - 000008192 ___SH C:\DumpStack.log.tmp 2026-02-02 22:44 - 2020-10-07 16:28 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2026-01-26 15:33 - 2022-10-02 18:00 - 000000000 ____D C:\Users\seth9\AppData\Roaming\discord 2026-01-26 15:33 - 2022-10-02 18:00 - 000000000 ____D C:\Users\seth9\AppData\Local\Discord ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================