Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 14.03.2018 Uruchomiony przez Wojtek (19-03-2018 18:26:35) Run:4 Uruchomiony z C:\Users\Wojtek\Downloads Załadowane profile: Wojtek (Dostępne profile: Wojtek) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: EmptyTemp: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA VirusTotal: C:\Program Files\wufuc\wufuc.dll Folder: C:\Program Files\wufuc CHR HomePage: Default -> hxxp://www.funnysearching.com/ 2018-03-04 11:25 - 2018-03-04 11:25 - 000000008 __RSH C:\ProgramData\ntuser.pol 2018-02-25 10:04 - 2018-03-04 11:25 - 000000008 __RSH C:\Users\Wojtek\ntuser.pol Task: {C48A5C41-5BDB-4B8D-87F9-91A4875E1A0A} - System32\Tasks\wufuc.{72EEE38B-9997-42BD-85D3-2DD96DA17307} => C:\Windows\system32\rundll32.exe "C:\Program Files\wufuc\wufuc.dll",Rundll32Entry C:\Users\Wojtek\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk AlternateDataStreams: C:\Users\Public\AppData:CSM [470] C:\Users\Wojtek\Favorites\Links\Интернет.url ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" => pomyślnie usunięto VirusTotal: C:\Program Files\wufuc\wufuc.dll => https://www.virustotal.com/file/d6055a2e79e7499f335320036497e4a2e1f8a5d2fae7741fda7463b9cd6af5a7/analysis/1519201360/ ========================= Folder: C:\Program Files\wufuc ======================== 2017-06-05 07:25 - 2017-06-05 07:25 - 000035815 ____A [9C25E1CDC3B5122842A6A70FAB49A522] () C:\Program Files\wufuc\COPYING.txt 2017-07-15 23:47 - 2017-07-15 23:47 - 000148480 ____A [9B6F24764A49A4CB7512F1C7BFD61229] (zeffy) C:\Program Files\wufuc\wufuc.dll 2018-02-26 20:30 - 2018-03-19 17:23 - 000016618 ____A [C748556B081B8A19AA4F46398203BE11] () C:\Program Files\wufuc\wufuc.rundll32.exe.log 2018-02-26 20:30 - 2018-03-19 18:02 - 000082568 ____A [6CBA720CF74AD081D44A4F0F3B2312EC] () C:\Program Files\wufuc\wufuc.svchost.exe.log 2018-02-26 20:30 - 2018-02-26 20:30 - 000000000 ____D [00000000000000000000000000000000] () C:\Program Files\wufuc\Helper Scripts 2017-07-03 17:50 - 2017-07-03 17:50 - 000001455 ____A [08CB38CEE8231BDEB6BC13AB76F70522] () C:\Program Files\wufuc\Helper Scripts\disable_wufuc.bat 2017-06-28 13:21 - 2017-06-28 13:21 - 000001361 ____A [104B14FCA3E0FB2B79D77C4189357F72] () C:\Program Files\wufuc\Helper Scripts\enable_wufuc.bat ====== Koniec Folder: ====== "Chrome HomePage" => pomyślnie usunięto C:\ProgramData\ntuser.pol => pomyślnie przeniesiono C:\Users\Wojtek\ntuser.pol => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C48A5C41-5BDB-4B8D-87F9-91A4875E1A0A}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C48A5C41-5BDB-4B8D-87F9-91A4875E1A0A}" => pomyślnie usunięto C:\Windows\System32\Tasks\wufuc.{72EEE38B-9997-42BD-85D3-2DD96DA17307} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wufuc.{72EEE38B-9997-42BD-85D3-2DD96DA17307}" => pomyślnie usunięto C:\Users\Wojtek\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk => pomyślnie przeniesiono C:\Users\Public\AppData => ":CSM" ADS pomyślnie usunięto C:\Users\Wojtek\Favorites\Links\Интернет.url => pomyślnie przeniesiono =========== EmptyTemp: ========== BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15075675 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 0 B Edge => 0 B Chrome => 424790271 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 0 B Wojtek => 2354482921 B RecycleBin => 0 B EmptyTemp: => 2.6 GB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 18:26:56 ====