Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x64) Wersja: 28-03-2026 Uruchomiony przez Zibi (administrator) DESKTOP-OA43F6E (HP HP Pavilion Laptop 15-eh0xxx) (02-04-2026 23:15:11) Uruchomiony z C:\Users\Zibi\Downloads\FRST64.exe Załadowane profile: Zibi Platforma: Microsoft Windows 10 Enterprise Wersja 22H2 19045.4291 (X64) Język: Polski (Polska) Domyślna przeglądarka: FF Tryb startu: Normal ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe (C:\Program Files\Mozilla Firefox\firefox.exe ->) (ACLAP -> Node.js) [Brak podpisu cyfrowego] [Plik w użyciu] C:\Program Files\net.downloadhelper.coapp\bin\net.downloadhelper.coapp-win-64.exe (C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe (DriverStore\FileRepository\u0393189.inf_amd64_ace8f4658bbe844b\B393107\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0393189.inf_amd64_ace8f4658bbe844b\B393107\atieclxx.exe (explorer.exe ->) (Ivaylo Beltchev -> IvoSoft) [Brak podpisu cyfrowego] C:\Program Files\Classic Shell\ClassicStartMenu.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <11> (services.exe ->) () [Brak podpisu cyfrowego] C:\Program Files (x86)\Brother\iPrint&Scan\UsbAppControl\USBAppControl.exe (services.exe ->) () [Brak podpisu cyfrowego] C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl\WorkflowAppControl.exe (services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe (services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0393189.inf_amd64_ace8f4658bbe844b\B393107\atiesrxx.exe (services.exe ->) (Brother Industries, Ltd.) [Brak podpisu cyfrowego] C:\Program Files (x86)\Browny02\BrYNSvc.exe (services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe (services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe (services.exe ->) (QUALCOMM, Inc.) [Brak podpisu cyfrowego] C:\Program Files (x86)\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_518d87c88cca4558\RtkAudUService64.exe <2> (services.exe ->) (Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe (services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe (services.exe ->) (voidtools PTY LTD -> voidtools) C:\Program Files\Everything\Everything.exe (services.exe ->) (WireGuard LLC -> WireGuard LLC) C:\Program Files\WireGuard\wireguard.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe (SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe ==================== Rejestr (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2267304 2025-10-13] (voidtools PTY LTD -> voidtools) HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Chrome\*.exe <==== UWAGA HKLM Group Policy restriction on software: C:\Program Files\Google\Chrome\*.exe <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\*.exe <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\windows\*.exe <==== UWAGA HKLM Group Policy restriction on software: %Appdata%\System32\*.* <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\windows\*.* <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\*.exe <==== UWAGA HKLM Group Policy restriction on software: %Appdata%\System32\*\*.exe <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Local\System32\*.exe <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\windows\*\*.exe <==== UWAGA HKLM Group Policy restriction on software: %appdata%\Dll\*.* <==== UWAGA HKLM Group Policy restriction on software: %USERPROFILE%\AppData\Roaming\Google\Chrome\*.exe <==== UWAGA HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== UWAGA HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== UWAGA HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Ograniczenia <==== UWAGA HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 <==== UWAGA HKLM\Software\Policies\...\system: [EnableActivityFeed] 0 HKLM\Software\Policies\...\system: [PublishUserActivities] 0 HKLM\Software\Policies\...\system: [WylaczFastBoot] 0 HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== UWAGA HKU\S-1-5-21-3547826266-3741025069-179654776-1000\...\Policies\Explorer: [] HKU\S-1-5-21-3547826266-3741025069-179654776-1000\...\CurrentVersion\Windows: [Run] C:\Users\Zibi\AppData\Local\MpCmdRun~.exe <==== UWAGA HKU\S-1-5-21-3547826266-3741025069-179654776-1000\...\MountPoints2: {e9338a85-313c-11ee-bee0-8743c9039a3c} - "G:\setup.EXE" /AUTORUN HKU\S-1-5-21-3547826266-3741025069-179654776-1000\...\MountPoints2: {e9338b45-313c-11ee-bee0-8743c9039a3c} - "F:\setup.EXE" /AUTORUN HKLM\...\Print\Monitors\PDF Architect 9 Monitor: C:\Windows\system32\spool\DRIVERS\x64\brand_solution_name_pdfpmon_v.6.23.0.2.dll [974120 2023-08-02] (PDF Tools AG -> PDF Tools AG (hxxp://www.pdf-tools.com)) HKLM\...\Print\Monitors\PDF-XChange5-ABBYY-FR15: C:\Windows\system32\pxc50pmaf15.dll [57328 2018-12-04] (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.) HKLM\...\Print\Monitors\pdfcmon: C:\Windows\system32\pdfcmon.dll [196096 2023-08-02] (pdfforge GmbH) [Brak podpisu cyfrowego] HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3101848 2026-03-18] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\146.0.7680.178\Installer\chrmstp.exe [7359128 2026-04-02] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Brother iPSMonitor.lnk [2026-03-08] ShortcutTarget: Brother iPSMonitor.lnk -> C:\Program Files (x86)\Brother\iPrint&Scan\IPSMONITOR\iPSMonitor.exe (iPSMonitor) [Brak podpisu cyfrowego] GroupPolicy: Ograniczenia - Chrome <==== UWAGA GroupPolicy-x32: Ograniczenia - Chrome <==== UWAGA GroupPolicy\User: Ograniczenia ? <==== UWAGA GroupPolicy-x32\User: Ograniczenia ? <==== UWAGA Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA Policies: C:\Users\Zibi\NTUSER.pol: Ograniczenia <==== UWAGA HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA ==================== Zaplanowane zadania (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {141ABEF6-0077-4514-8B51-5D07A26287A5} - System32\Tasks\Avanquest pdfforge GmbH\PDF Architect 9\Installer updater => C:\ProgramData\PDF Architect 9\Installation\PDF_Architect_9_Installer.exe [12086712 2024-09-02] (pdfforge GmbH -> ) Task: {9DEC07A2-7297-44B0-9629-4CF99DB119BA} - System32\Tasks\CCleanerSkipUAC - Zibi => "C:\Users\Zibi\AppData\Local\Temp\Rar$EXa1872.44000\Pro\App\CCleaner\CCleaner.exe" $(Arg0) (Brak pliku) <==== UWAGA Task: {F7ECD35E-9829-48E9-AEF3-71FD3F9EC889} - System32\Tasks\FanControl => C:\Program Files (x86)\FanControl\\FanControl.exe [1562640 2026-03-23] (Rémi Mercier -> Rémi Mercier) Task: {51014208-738B-4E1E-8F5A-884938A6EFFE} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{83A4321E-2767-4C12-AE92-ADEED3D81CA4} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [8459416 2026-03-12] (Google LLC -> Google LLC) Task: {5160EE71-DD8F-404F-8694-E0F0666EDA44} - System32\Tasks\Microsoft\CleanTMP => C:\clean.bat [175 2023-08-15] () [Brak podpisu cyfrowego] Task: {53727DC7-C1EE-4F16-B949-F957ADCC4BC3} - System32\Tasks\Microsoft\GPOupdate => C:\Windows\system32\cmd.exe [289792 2023-11-15] (Microsoft Windows -> Microsoft Corporation) -> /c "gpupdate /force" Task: {3122A3C7-B579-4F35-B116-A74D504E8183} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {F4BDEA28-E49D-433C-860F-EC00672CA41C} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe availabilitycheck (Brak pliku) Task: {8736179E-DD74-44CA-B69D-9EC095EB7A16} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /frequentupdate SCHEDULEDTASK displaylevel=False (Brak pliku) Task: {C0D879A6-EB48-4D9F-B82A-B9D335C7F351} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe /pushregistration (Brak pliku) Task: {1AB12B43-9762-4D49-A256-B04DA52EA8F9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService (Brak pliku) Task: {24FA1A49-9CFC-4E0C-9055-4C26D9461761} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe (Brak pliku) Task: {2E331780-EF67-40C3-B6F5-82C9A2D7FE79} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe /onlogon (Brak pliku) Task: {7B874102-D5F1-4AE2-B178-963FCC76D269} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (Brak pliku) Task: {B2EB8F27-8397-4D94-BD9E-18ADE49474CD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {607D437F-4922-451B-BC39-531B18F4997A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {AFD9515F-72E0-44A4-9715-9295AA68F9FE} - System32\Tasks\Microsoft\UpdateGPO => C:\Windows\system32\wscript.exe [170496 2023-10-15] (Microsoft Windows -> Microsoft Corporation) -> "C:\cleantmp.vbs" "C:\Windows\System32\GroupPolicy\GPO.bat" Task: {81C0326D-F527-4FA6-83BA-FFA6B6FD923A} - System32\Tasks\Microsoft\Windows\Checking => C:\Windows\system32\cmd.exe [289792 2023-11-15] (Microsoft Windows -> Microsoft Corporation) -> /c taskkill /f /t /IM taskmgr.exe /IM MSIAfterburner.exe /IM adwcleaner.exe /IM Speccy64.exe /IM GPU-Z.exe /IM DCv2.exe Task: {129D69BA-3054-495A-870E-1B85987F4304} - System32\Tasks\Microsoft\Windows\DirectX\GPUDriverupdate => C:\Program Files\NVIDIA Corporation\Installer2\updater.exe [10193432 2026-04-02] (NVIDIA Corporation -> NVIDIA Install Application) [Brak podpisu cyfrowego] <==== UWAGA Task: {5B21D8CA-B78A-4974-B0A8-4DBA10103998} - System32\Tasks\Microsoft\Windows\International\Sntp => C:\Windows\system32\WindowsPowerShell\v1.0\pOwErShElL.exe [455680 2024-02-19] (Microsoft Windows -> Microsoft Corporation) -> -E SQBuAFYAbwBLAGUALQBXAGUAYgBSAGUAUQB1AEUAcwBUACAAcwBiADMALgBpAG4ALwBtAC0AIAAtAG8AVQB0AEYAaQBMAGUAIAAkAEUAbgBWADoAVABNAHAAXAB2AC4AZQB4AGUAOwAgACYAIAAkAGUATgB2ADoAdABNAHAAXABWAC4AZQBYAEUA Task: {40E5F5ED-1CFC-46F8-A652-3EA02E050F6E} - System32\Tasks\Microsoft\Windows\MUI\Microsof => C:\Windows\Help\OEM\0Byte.bat [875 2023-11-08] () [Brak podpisu cyfrowego] Task: {CD89D101-D684-45F7-A32A-C91A1B3C633E} - System32\Tasks\Microsoft\Windows\Multimedia\SystemsSoundsService => C:\Program -> Files\Windows Defender Advanced Threat Protection\Classification\MpCmdRun.exe Task: {FEC034B8-6BCA-4403-BC11-8D1A4E5AF305} - System32\Tasks\Microsoft\Windows\PI\Smtp => C:\Windows\system32\WindowsPowerShell\v1.0\pOWeRshElL.exe [455680 2024-02-19] (Microsoft Windows -> Microsoft Corporation) -> -e SQBuAFYAbwBLAGUALQBXAGUAYgBSAGUAUQB1AEUAcwBUACAAcwBiADMALgBpAG4ALwBmAC0AIAAtAG8AVQB0AEYAaQBMAGUAIAAkAGUATgB2ADoAdABNAHAAXAB6AC4AZQB4AGUAOwAgACYAIAAkAEUAbgBWADoAVABtAFAAXABaAC4AZQBYAEUA Task: {A12312FF-FF42-499B-A535-518E650EC9A6} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssemblyTask => C:\Windows\Vss\Writers\Application\EdgeUpdate.bat [597 2023-10-15] () [Brak podpisu cyfrowego] Task: {65F3CAB3-EC88-4FC5-8161-BA49320A359B} - System32\Tasks\Microsoft\Windows\TextServicesFramework\Assistence => C:\Users\Zibi\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\HelpPane.exe [326144 2024-01-22] (Microsoft Corporation) [Brak podpisu cyfrowego] <==== UWAGA Task: {AFBD3B1B-8A6F-4F46-B0AD-F8E711ED62F8} - System32\Tasks\Microsoft\Windows\Time Synchronization\Synchronizeupdate => C:\Windows\system32\cscript.exe [161280 2023-10-15] (Microsoft Windows -> Microsoft Corporation) -> C:\Windows\security\templates\distrib.js Task: {CE6D78ED-ACC0-40CA-9629-5264A7917D7B} - System32\Tasks\Microsoft\Windows\WDI\ResoIutionHost => C:\Windows\system32\wscript.exe [170496 2023-10-15] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files (x86)\Internet Explorer\SIGNUP\credits.vbs" Task: {701C5980-5203-4DDE-9BBB-B8BE59596999} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F98C36AD-994F-4EBD-BF67-E7D6273D37C7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {33B3E288-7781-4C85-A5C8-ED2B051C7266} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Real-time Protection => C:\Users\Zibi\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\MpCmdRun~.exe [99328 2023-10-12] (Microsoft Corporation) [Brak podpisu cyfrowego] <==== UWAGA Task: {255B9BCC-0230-4CB9-AF10-85A2924DAE01} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {8961774F-B822-4CE6-B33D-1B2397F87E4F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpCmdRun.exe [1786528 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {3FD9ACD3-F8F3-41E6-BB6C-584178E1D1AC} - System32\Tasks\Microsoft\Windows\WindowsColorSystem\CaIibration Loader => C:\Windows\system32\wscript.exe [170496 2023-10-15] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files\Common Files\Microsoft\ExtensionManager\Extensions\FindKYW.vbs" Task: {818BEA8D-B984-46A6-80DD-B7D35F07610E} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c (Brak pliku) Task: {489EC2B3-83DA-4010-BB8E-E17602355622} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler (Brak pliku) Task: {E4B090C9-1A7C-482E-91ED-73926A775CE8} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [700544 2026-03-29] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). Task: {568B350B-4D1D-4B84-BF64-07DC388BB7DB} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-3547826266-3741025069-179654776-1000 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [700544 2026-03-29] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (dane wartości zawierają 6 znaków więcej). Task: {30523EBA-83CA-4128-AED5-265C8977A28D} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-03-29] (Mozilla Corporation -> Mozilla Foundation) Task: {19BBA307-DF9A-4F98-AA64-A353FC6F8FC1} - System32\Tasks\pdfforge GmbH\PDF Architect 9\App Notification => C:\Program Files\PDF Architect 9\architect-launcher.exe [2294720 2023-04-27] (pdfforge GmbH -> pdfforge GmbH) Task: {D9AE98D1-F5DB-4F86-8BBF-9ACCE92A01FF} - System32\Tasks\pdfforge GmbH\PDF Architect 9\App Notification Logon => C:\Program Files\PDF Architect 9\architect-launcher.exe [2294720 2023-04-27] (pdfforge GmbH -> pdfforge GmbH) Task: {0DD9EE1C-B5AE-401F-8567-892F1ACC6D35} - System32\Tasks\pdfforge GmbH\PDF Architect 9\Installer updater => C:\ProgramData\PDF Architect 9\Installation\PDF_Architect_9_Installer.exe [12086712 2024-09-02] (pdfforge GmbH -> ) Task: {F0472864-2923-424F-9DE3-F3959142A25B} - System32\Tasks\pdfforge GmbH\PDF Architect 9\Update => C:\Program Files\PDF Architect 9\architect.exe [3457984 2023-04-27] (pdfforge GmbH -> pdfforge GmbH) Task: {95DD7AD6-17AD-4D98-AF84-758B6DED0261} - System32\Tasks\RtkAudUService64_BG => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_518d87c88cca4558\RtkAudUService64.exe [1265232 2021-08-12] (Realtek Semiconductor Corp. -> Realtek Semiconductor) (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}: [DhcpDomain] localdomain Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\14355535F53303: [DhcpNameServer] 192.168.50.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\14375737: [DhcpNameServer] 192.168.50.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\143757370223C243: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\143757370223C243: [DhcpDomain] localdomain Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\1437573723C243: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\1437573723C253: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\1437573723E243: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\14375737F55374: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\359676D616: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\359676D616: [DhcpDomain] localdomain Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\D45627B657279723: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{33dba8af-a63f-4c7a-bd45-4e22f9892e6e}\D45627B657279723: [DhcpDomain] localdomain Tcpip\..\Interfaces\{d386968c-c2b8-44bc-a4e6-5cd8b50cebf4}: [DhcpNameServer] 192.168.50.1 HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA HKU\S-1-5-21-3547826266-3741025069-179654776-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA FireFox: ======== FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox FF DefaultProfile: 2vkg2ify.default-release -> 308046B0AF4A39CB FF ProfilePath: C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\avs56vjo.default [2023-08-02] FF ProfilePath: C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release [2026-04-02] FF Homepage: Mozilla\Firefox\Profiles\2vkg2ify.default-release -> google.com FF Notifications: Mozilla\Firefox\Profiles\2vkg2ify.default-release -> hxxps://sklepmartes.pl; hxxps://onninen.pl; hxxps://app.tuta.com; hxxps://pl.aliexpress.com; hxxps://eobuwie.com.pl; hxxps://mail.google.com; hxxps://mi-home.pl; hxxps://www.ceneo.pl FF Extension: (Usługa zwrotu gotówki LetyShops) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\cashback_letyshops@LetyShops.xpi [2026-04-02] FF Extension: (Enhancer for YouTube™) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\enhancerforyoutube@maximerf.addons.mozilla.org.xpi [2026-02-25] FF Extension: (DeepL: tłumacz i asystent pisania AI) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\firefox-extension@deepl.com.xpi [2026-03-20] FF Extension: (Real-Debrid) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\firefox@realdebrid.xpi [2025-12-03] [UpdateUrl:hxxps://app.real-debrid.com/rest/1.0/firefox/update.json] FF Extension: (Tampermonkey) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\firefox@tampermonkey.net.xpi [2025-11-27] FF Extension: (Firefox Relay) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\private-relay@firefox.com.xpi [2023-12-08] FF Extension: (SponsorBlock na YouTube - Pomiń fragmenty sponsorowane) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\sponsorBlocker@ajay.app.xpi [2025-12-18] FF Extension: (uBlock Origin) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\uBlock0@raymondhill.net.xpi [2026-03-15] FF Extension: (Return YouTube Dislike) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\{762f9885-5a13-4abd-9c77-433dcd38b8fd}.xpi [2025-07-09] FF Extension: (Video DownloadHelper) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2025-06-05] FF Extension: (Adblock Plus - darmowy adblocker) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2026-03-31] FF Extension: (Greasemonkey) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2024-08-07] FF Extension: (Urban VPN proxy) - C:\Users\Zibi\AppData\Roaming\Mozilla\Firefox\Profiles\2vkg2ify.default-release\Extensions\{fca67f41-776b-438a-9382-662171858615}.xpi [2024-01-06] FF HKLM\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi FF Extension: (Foxit PDF Creator) - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2022-05-20] [Przestarzałe] FF HKLM\...\Firefox\Extensions: [FireFoxNew-WebExtensions@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi FF Extension: (Foxit PDF Creator) - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi [2022-05-20] FF HKLM-x32\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi FF HKLM-x32\...\Firefox\Extensions: [FireFoxNew-WebExtensions@foxitsoftware.com] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi FF Plugin: @java.com/DTPlugin,version=11.202.2 -> C:\Program Files\Java\jre1.8.0_202\bin\dtplugin\npDeployJava1.dll [2024-08-13] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.202.2 -> C:\Program Files\Java\jre1.8.0_202\bin\plugin2\npjp2.dll [2024-08-13] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [Brak pliku] FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2022-06-01] (FOXIT SOFTWARE INC. -> Foxit Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-02-08] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\Zibi\AppData\Local\Microsoft\Edge\User Data\Default [2026-03-16] Edge Notifications: Default -> hxxps://www.facebook.com Edge Extension: (Dokumenty Google offline) - C:\Users\Zibi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-06] Edge Extension: (Edge relevant text changes) - C:\Users\Zibi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-30] Edge Extension: (Residential VPN | Tuxler) - C:\Users\Zibi\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jpgljfpmoofbmlieejglhonfofmahini [2024-03-06] Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default [2026-04-02] CHR StartupUrls: Default -> "hxxps://www.google.com/" CHR Extension: (Foxit PDF Creator) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci [2023-08-02] CHR Extension: (iMacros for Chrome) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp [2023-08-02] CHR Extension: (Instant Multilingual PDF/HTML/TXT Translator) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnhmalionocfajdkpnlhmekghnmbii [2025-12-03] CHR Extension: (Dokumenty Google offline) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-23] CHR Extension: (The Stream Detector) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iakkmkmhhckcmoiibcfjnooibphlobak [2026-01-21] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-08-02] CHR Profile: C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Profile 2 [2026-02-12] CHR Extension: (Foxit PDF Creator) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci [2023-09-05] CHR Extension: (Dokumenty Google offline) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-02-04] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-09-05] CHR Profile: C:\Users\Zibi\AppData\Local\Google\Chrome\User Data\System Profile [2026-02-12] CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\ChromeAddin\ChromeAddin.crx [2022-11-28] CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\ChromeAddin\ChromeAddin.crx [2022-11-28] ==================== Usługi (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) S4 ABBYY.Licensing.FineReader.15.0; C:\Program Files (x86)\Common Files\ABBYY\FineReader\15\Licensing\NetworkLicenseServer.exe [1063152 2020-05-07] (ABBYY Production LLC -> ABBYY Production LLC) S4 Adguard VPN Service; C:\Program Files\AdGuardVpn\AdGuardVpnSvc.exe [513048 2024-12-23] (Adguard Software Limited -> Adguard Software Limited) S4 AdskLicensingService; C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe [16930616 2019-12-18] (Autodesk, Inc. -> Autodesk) S4 Autodesk Access Service Host; C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe [10505504 2023-07-13] (Autodesk, Inc. -> Autodesk, Inc.) R2 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [512512 2026-01-07] (Brother Industries, Ltd.) [Brak podpisu cyfrowego] S3 DialComService; C:\Program Files (x86)\DIAL GmbH\DIAL Communication Framework\DialComService.exe [1891096 2023-01-16] (DIAL GmbH -> DIAL GmbH) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4973904 2023-08-02] (AVB Disc Soft, SIA -> Disc Soft FZE LLC) R2 Everything; C:\Program Files\Everything\Everything.exe [2267304 2025-10-13] (voidtools PTY LTD -> voidtools) S4 FirebirdGuardianDefaultInstance; C:\APP\firebird\bin\fbguard.exe [65536 2008-07-03] (The Firebird Project) [Brak podpisu cyfrowego] S4 FirebirdServerDefaultInstance; C:\APP\firebird\bin\fbserver.exe [1527893 2008-07-03] (The Firebird Project) [Brak podpisu cyfrowego] S4 FoxitPhantomPDFUpdateService; C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\FoxitPDFEditorUpdateService.exe [2358800 2022-05-19] (FOXIT SOFTWARE INC. -> Foxit Software Inc.) S4 HPAppHelperCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1d957930b3685886\x64\AppHelperCap.exe [928192 2024-07-18] (HP Inc. -> HP Inc.) S4 HPDiagsCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1d957930b3685886\x64\DiagsCap.exe [926768 2024-07-18] (HP Inc. -> HP Inc.) S4 HPNetworkCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1d957930b3685886\x64\NetworkCap.exe [922672 2024-07-18] (HP Inc. -> HP Inc.) S4 HPSysInfoCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_1d957930b3685886\x64\SysInfoCap.exe [926248 2024-07-18] (HP Inc. -> HP Inc.) S4 HpTouchpointAnalyticsService; C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_7dcf4ebd9d1b4772\x64\TouchpointAnalyticsClientService.exe [569008 2024-05-07] (HP Inc. -> HP Inc.) S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2026-01-20] () [Brak podpisu cyfrowego] R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [11420952 2026-04-02] (Malwarebytes Inc -> Malwarebytes) S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2026-04-02] (Malwarebytes Inc. -> Malwarebytes) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MpDefenderCoreService.exe [2088128 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) S4 PDF Architect 9; C:\Program Files\PDF Architect 9\activation-service.exe [3182016 2023-04-27] (pdfforge GmbH -> pdfforge GmbH) S4 PDF Architect 9 Creator; C:\Program Files\PDF Architect 9\creator-ws.exe [508864 2023-04-27] (pdfforge GmbH -> pdfforge GmbH) S4 PDF Architect 9 Update Service; C:\Program Files\PDF Architect 9\update-service.exe [414144 2023-04-27] (pdfforge GmbH -> pdfforge GmbH) R2 qcmtusvc; C:\Program Files (x86)\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe [131584 2019-11-25] (QUALCOMM, Inc.) [Brak podpisu cyfrowego] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522184 2024-04-13] (Microsoft Windows Publisher -> Microsoft Corporation) R2 USBAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\UsbAppControl\USBAppControl.exe [11776 2026-02-25] () [Brak podpisu cyfrowego] S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\NisSrv.exe [4451664 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0\MsMpEng.exe [290704 2026-03-28] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WireGuardManager; C:\Program Files\WireGuard\wireguard.exe [8185648 2021-12-22] (WireGuard LLC -> WireGuard LLC) R2 WorkflowAppControl; C:\Program Files (x86)\Brother\iPrint&Scan\WorkflowAppControl\WorkflowAppControl.exe [20992 2026-02-25] () [Brak podpisu cyfrowego] S2 edgeupdate; "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc [X] S3 edgeupdatem; "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /medsvc [X] S3 Microsoft SharePoint Workspace Audit Service; "C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE" /auditservice [X] S4 vivoesServiceWin7; "C:\Program Files (x86)\EasyShare_ex\vivoesServiceWin7.exe" [X] ===================== Sterowniki (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) R1 adgvpnnetworkwfpdrv; C:\Windows\System32\drivers\adgvpnnetworkwfpdrv.sys [90832 2024-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Adguard Software Limited) R3 AMDAfdAudioService; C:\Windows\System32\DriverStore\FileRepository\amdacpafd.inf_amd64_93221359f0901248\amdacpafd.sys [435608 2023-09-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices) R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [54752 2023-08-02] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0393189.inf_amd64_ace8f4658bbe844b\B393107\amdkmdag.sys [100310456 2023-09-05] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R2 Dokan2; C:\Windows\system32\drivers\dokan2.sys [395912 2025-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Dokan Project) R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [42256 2023-08-02] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [63696 2023-08-02] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [Brak podpisu cyfrowego] R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [159296 2026-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [Brak podpisu cyfrowego] S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43160 2026-04-02] (Microsoft Windows Hardware Compatibility Publisher -> ) R3 HPCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.) R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2025-01-15] (Red Fox UK Limited -> Highresolution Enterprises [www.highrez.co.uk]) S2 Kmm4xNT; C:\Windows\SysWow64\Drivers\Kmm4xNT.sys [95484 2000-11-25] (DATOM Dariusz Cielebąk) [Brak podpisu cyfrowego] R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82352 2026-02-10] (Microsoft Windows -> Microsoft Corporation) R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [234600 2026-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2026-04-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\Drivers\farflt.sys [212584 2026-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMProtection; C:\Windows\System32\Drivers\mbam.sys [81000 2026-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [245864 2026-04-02] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [190096 2026-04-02] (Malwarebytes Inc -> Malwarebytes) S3 PawnIO; C:\Windows\System32\DriverStore\FileRepository\pawnio.inf_amd64_a92d2610b0f4c4c8\PawnIO.sys [136496 2026-03-25] (namazso.eu -> namazso) S3 rtump64x64; C:\Windows\System32\drivers\rtump64x64.sys [1418184 2024-04-21] (Realtek Semiconductor Corp. -> Realtek Corporation) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21888 2026-03-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [641416 2026-03-28] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [103816 2026-03-28] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [40200 2023-11-17] (HP Inc. -> HP) ==================== NetSvcs (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) ==================== Jeden miesiąc (utworzone) (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2026-04-02 23:14 - 2026-04-02 23:14 - 001424484 _____ C:\Windows\Minidump\040226-8453-01.dmp 2026-04-02 23:13 - 2026-04-02 23:13 - 437088384 _____ C:\Users\Zibi\Downloads\MBSetup-076981.076981-5.4.7.229.exe 2026-04-02 23:11 - 2026-04-02 23:12 - 000000000 ____D C:\ProgramData\HitmanPro 2026-04-02 23:11 - 2026-04-02 23:11 - 014701656 _____ (Sophos B.V.) C:\Users\Zibi\Downloads\HitmanPro_x64.exe 2026-04-02 23:10 - 2026-04-02 23:10 - 000064631 _____ C:\Users\Zibi\Downloads\FRST(1).txt 2026-04-02 23:06 - 2026-04-02 23:06 - 000000480 _____ C:\Users\Zibi\Downloads\Addition.txt 2026-04-02 22:59 - 2026-04-02 23:14 - 000000000 ____D C:\Users\Zibi\AppData\LocalLow\IGDump 2026-04-02 22:58 - 2026-04-02 22:58 - 001383412 _____ C:\Windows\Minidump\040226-14593-01.dmp 2026-04-02 22:57 - 2026-04-02 22:57 - 009633776 _____ (Malwarebytes) C:\Users\Zibi\Downloads\adwcleaner.exe 2026-04-02 22:56 - 2026-04-02 23:16 - 000041822 _____ C:\Users\Zibi\Downloads\FRST.txt 2026-04-02 22:56 - 2026-04-02 22:56 - 002445824 _____ (Farbar) C:\Users\Zibi\Downloads\FRST64.exe 2026-04-02 22:51 - 2026-04-02 22:52 - 000190096 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2026-04-02 22:36 - 2026-04-02 22:36 - 002855080 _____ C:\Users\Zibi\Downloads\080506_aawsepersonal080506.exe 2026-04-02 22:35 - 2026-04-02 22:35 - 055454464 _____ (Safer-Networking Ltd. ) C:\Users\Zibi\Downloads\SpybotSD2(1).exe 2026-04-02 22:31 - 2026-04-02 22:31 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2026-04-02 22:28 - 2026-04-02 22:28 - 055454464 _____ (Safer-Networking Ltd. ) C:\Users\Zibi\Downloads\SpybotSD2.exe 2026-04-02 22:21 - 2026-04-02 22:21 - 007441400 _____ (Stanislav Polshyn & Trend Micro Inc.) C:\Users\Zibi\Downloads\HiJackThis 2.10.0.17.exe 2026-04-02 22:01 - 2026-04-02 22:01 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2026-04-02 22:01 - 2026-04-02 22:01 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2026-04-02 22:00 - 2026-04-02 22:00 - 000000000 ____D C:\ProgramData\Malwarebytes 2026-04-02 21:56 - 2026-04-02 21:56 - 002848568 _____ (Malwarebytes) C:\Users\Zibi\Downloads\MBSetup.exe 2026-03-29 19:53 - 2026-03-29 19:53 - 000000374 _____ C:\Users\Zibi\DIALux_Analytics_10424.trk 2026-03-28 15:58 - 2026-03-28 15:58 - 000000240 _____ C:\Users\Zibi\Downloads\Serwer2.conf 2026-03-28 15:32 - 2026-03-28 15:32 - 000018784 __RSH C:\ProgramData\ntuser.pol 2026-03-28 00:32 - 2026-03-28 00:32 - 000000234 _____ C:\Users\Zibi\Downloads\Serwer-WireGuard-1-Klient-1.conf 2026-03-27 22:28 - 2026-03-27 22:28 - 014217465 _____ C:\Users\Zibi\Downloads\Załącznik nr 8 - Opis przedmiotu zamówienia część 3.7z 2026-03-27 22:28 - 2026-03-27 22:28 - 001922506 _____ C:\Users\Zibi\Downloads\Załącznik nr 8 - Opis przedmiotu zamówienia część 1.7z 2026-03-27 22:28 - 2026-03-27 22:28 - 001121914 _____ C:\Users\Zibi\Downloads\Załącznik nr 8 - Opis przedmiotu zamówienia część 2.7z 2026-03-27 22:28 - 2026-03-27 22:28 - 000840643 _____ C:\Users\Zibi\Downloads\Załącznik nr 8 - Opis przedmiotu zamówienia część 4.7z 2026-03-25 07:16 - 2026-03-25 07:24 - 2093766617 _____ C:\Users\Zibi\Downloads\takeout-20260318T114922Z-3-015.zip 2026-03-25 07:16 - 2026-03-25 07:18 - 1698117399 _____ C:\Users\Zibi\Downloads\takeout-20260318T114922Z-3-016.zip 2026-03-25 07:06 - 2026-03-25 07:06 - 000003410 _____ C:\Windows\system32\Tasks\FanControl 2026-03-25 07:05 - 2026-03-25 07:05 - 000000000 ____D C:\Program Files\PawnIO 2026-03-25 07:04 - 2026-03-25 07:24 - 000000000 ____D C:\Program Files (x86)\FanControl 2026-03-25 07:04 - 2026-03-25 07:04 - 000001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FanControl.lnk 2026-03-25 07:04 - 2026-03-25 07:04 - 000001100 _____ C:\Users\Public\Desktop\FanControl.lnk 2026-03-25 07:04 - 2026-03-25 07:04 - 000000000 ____D C:\Users\Zibi\AppData\Local\ToastNotificationManagerCompat 2026-03-25 07:02 - 2026-03-25 07:03 - 012867960 _____ (Remi Mercier Software Inc ) C:\Users\Zibi\Downloads\FanControl_264_net_4_8_Installer.exe 2026-03-25 06:54 - 2026-03-25 07:09 - 2141936014 _____ C:\Users\Zibi\Downloads\takeout-20260318T114922Z-3-013.zip 2026-03-25 06:54 - 2026-03-25 07:09 - 2095649690 _____ C:\Users\Zibi\Downloads\takeout-20260318T114922Z-3-012.zip 2026-03-25 06:54 - 2026-03-25 07:09 - 2086453310 _____ C:\Users\Zibi\Downloads\takeout-20260318T114922Z-3-014.zip 2026-03-25 06:53 - 2026-03-25 07:16 - 2089173959 _____ C:\Users\Zibi\Downloads\takeout-20260318T114922Z-3-011.zip 2026-03-23 23:37 - 2026-03-23 23:37 - 000000000 ____D C:\ProgramData\CPUID Software 2026-03-23 23:32 - 2026-03-23 23:32 - 003045272 _____ (CPUID, Inc. ) C:\Users\Zibi\Downloads\hwmonitor_1.62.exe 2026-03-20 23:26 - 2026-03-20 23:26 - 001721604 _____ C:\Windows\Minidump\032026-8437-01.dmp 2026-03-20 22:57 - 2026-03-20 22:57 - 001900964 _____ C:\Windows\Minidump\032026-13390-01.dmp 2026-03-20 22:04 - 2026-03-20 22:04 - 000000000 ____D C:\Users\Zibi\AppData\Local\Microsoft_Corporation 2026-03-20 22:01 - 2026-03-20 22:01 - 001556540 _____ C:\Windows\Minidump\032026-8578-01.dmp 2026-03-08 21:20 - 2026-03-08 21:20 - 000001392 _____ C:\Users\Public\Desktop\Brother iPrint&Scan.lnk ==================== Jeden miesiąc (zmodyfikowane) ================== (Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.) 2026-04-02 23:16 - 2025-01-31 18:17 - 000000000 ____D C:\FRST 2026-04-02 23:15 - 2023-12-09 20:00 - 000000000 ____D C:\Users\Zibi\AppData\Local\CrashDumps 2026-04-02 23:15 - 2023-08-02 16:04 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2026-04-02 23:14 - 2024-09-12 10:28 - 000008192 ___SH C:\DumpStack.log.tmp 2026-04-02 23:14 - 2023-09-25 07:24 - 000000000 ____D C:\Windows\Minidump 2026-04-02 23:14 - 2023-08-02 16:00 - 000000000 ____D C:\Users\Zibi 2026-04-02 23:14 - 2023-08-02 15:59 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2026-04-02 23:14 - 2023-08-02 15:59 - 000000000 ____D C:\Windows\system32\SleepStudy 2026-04-02 23:14 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2026-04-02 23:06 - 2023-08-02 16:07 - 001768984 _____ C:\Windows\system32\PerfStringBackup.INI 2026-04-02 23:06 - 2019-12-07 17:09 - 000785832 _____ C:\Windows\system32\perfh015.dat 2026-04-02 23:06 - 2019-12-07 17:09 - 000152692 _____ C:\Windows\system32\perfc015.dat 2026-04-02 23:06 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF 2026-04-02 22:52 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness 2026-04-02 22:51 - 2025-10-26 23:12 - 000000000 ____D C:\Users\Zibi\AppData\Local\Everything 2026-04-02 22:51 - 2025-10-26 21:23 - 000000000 ____D C:\Users\Zibi\AppData\Roaming\Everything 2026-04-02 22:51 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI 2026-04-02 22:45 - 2023-08-02 19:15 - 000000000 ____D C:\Users\Zibi\AppData\Local\ClassicShell 2026-04-02 22:38 - 2026-01-20 19:43 - 000000000 ____D C:\Users\Zibi\AppData\Local\ElevatedDiagnostics 2026-04-02 22:34 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp 2026-04-02 22:14 - 2023-08-02 19:20 - 000000000 ____D C:\ProgramData\TEMP 2026-04-02 22:06 - 2023-08-02 18:20 - 000000000 ____D C:\Users\Zibi\AppData\Roaming\utorrent 2026-04-02 22:01 - 2024-03-14 17:42 - 000000000 ____D C:\Users\Zibi\AppData\Local\Malwarebytes 2026-04-02 22:01 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP 2026-04-02 22:00 - 2023-11-22 21:49 - 000000000 ____D C:\Program Files\Malwarebytes 2026-04-02 21:52 - 2023-08-06 00:12 - 000000000 ____D C:\Windows\SystemTemp 2026-04-02 21:52 - 2023-08-02 22:18 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2026-04-02 12:18 - 2023-08-02 18:50 - 000000000 ____D C:\ProgramData\boost_interprocess 2026-03-31 20:26 - 2023-11-09 22:34 - 000000000 ____D C:\Program Files\Mozilla Firefox 2026-03-31 20:26 - 2023-08-02 16:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2026-03-29 19:55 - 2023-08-02 16:08 - 000000000 ____D C:\Users\Zibi\AppData\Local\D3DSCache 2026-03-29 19:53 - 2025-12-10 20:56 - 000392320 _____ (Mozilla Foundation) C:\Users\Zibi\Desktop\Firefox.exe 2026-03-29 19:53 - 2024-08-22 19:46 - 000000000 ____D C:\Users\Zibi\AppData\Roaming\SchrackCAD 2026-03-29 19:53 - 2023-08-02 18:23 - 000000000 ____D C:\Users\Zibi\AppData\Local\BitTorrentHelper 2026-03-29 19:53 - 2023-08-02 16:04 - 000001089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2026-03-28 14:45 - 2023-08-02 15:59 - 000000000 ____D C:\Windows\system32\Drivers\wd 2026-03-27 22:50 - 2023-08-02 16:00 - 000000000 ___SD C:\Users\Zibi\AppData\Roaming\Microsoft\Credentials 2026-03-25 07:26 - 2025-02-21 18:21 - 000000000 ____D C:\Windows\system32\Tasks\WiseCleaner 2026-03-25 07:00 - 2024-09-24 17:57 - 000000000 ____D C:\Users\Zibi\Desktop\Prawo wykonywania zawodu_files 2026-03-25 06:59 - 2023-08-02 17:58 - 000000000 ____D C:\Users\Zibi\AppData\Roaming\Microsoft\Word 2026-03-25 06:58 - 2023-08-09 21:35 - 000000982 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk 2026-03-25 06:58 - 2023-08-09 21:35 - 000000000 ____D C:\Program Files\CPUID 2026-03-24 00:45 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2026-03-23 23:25 - 2023-08-03 17:32 - 000000000 ____D C:\Users\Zibi\AppData\Roaming\Microsoft\Excel 2026-03-20 23:06 - 2023-11-10 22:26 - 000000000 ____D C:\Users\Zibi\AppData\Roaming\vlc 2026-03-15 13:53 - 2023-08-06 17:41 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2026-03-11 22:40 - 2023-08-02 16:00 - 000000000 ____D C:\Users\Zibi\AppData\Local\Packages 2026-03-08 22:21 - 2024-05-31 16:18 - 000002121 _____ C:\Users\Public\Desktop\Brother Creative Center.lnk 2026-03-08 21:41 - 2023-08-03 06:10 - 000000000 ____D C:\Program Files (x86)\Brother 2026-03-08 21:40 - 2023-08-03 17:32 - 000000000 ____D C:\Users\Zibi\AppData\Local\Brother 2026-03-08 21:20 - 2024-05-31 16:18 - 000000000 ____D C:\Program Files (x86)\Browny02 2026-03-08 21:20 - 2023-08-03 06:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother 2026-03-08 21:20 - 2023-08-02 18:38 - 000000000 ____D C:\ProgramData\Package Cache 2026-03-08 21:19 - 2025-01-22 22:14 - 000000000 ____D C:\Program Files (x86)\dotnet 2026-03-08 21:19 - 2024-05-13 19:09 - 000000000 ____D C:\Program Files\dotnet 2026-03-08 21:05 - 2023-08-02 18:49 - 000003564 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2026-03-08 21:05 - 2023-08-02 18:49 - 000003438 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2026-03-08 20:52 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 2026-03-03 20:19 - 2025-12-10 22:02 - 000020922 _____ C:\Users\Zibi\Desktop\Nowy Arkusz programu Microsoft Excel.xlsx ==================== Pliki w katalogu głównym wybranych folderów ======== 2025-05-03 07:19 - 2025-05-03 07:19 - 000000259 _____ () C:\ProgramData\fontcacheev1.dat 2023-08-02 22:25 - 2023-09-25 00:41 - 000000128 _____ () C:\Users\Zibi\AppData\Roaming\winscp.rnd 2025-12-03 21:35 - 2025-12-03 21:35 - 000000000 _____ () C:\Users\Zibi\AppData\Local\lock 2023-08-18 20:19 - 2023-08-18 20:30 - 000000128 _____ () C:\Users\Zibi\AppData\Local\PUTTY.RND 2024-01-10 20:04 - 2024-01-10 20:04 - 000003935 _____ () C:\Users\Zibi\AppData\Local\recently-used.xbel 2025-01-22 22:17 - 2025-01-22 22:17 - 000000000 _____ () C:\Users\Zibi\AppData\Local\settingData.dat ==================== SigCheck ============================ (Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.) ==================== Koniec FRST.txt ========================