Stránka 1 z 1

Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirováním?

Napsal: 01 pro 2018 17:51
od prqyl
Ahoj lidi, nějakým způsobem se mi dostala do počítače tato havěť. Když zapnu například nějakou hru, tak se po chvíli objeví proces ve správci úloh ,, Systemcall " a využívá to 100% procesoru. Ten soubor se nachází na disku C ve Windows. Když jsem to projel malwarebytes tak to našlo 3 infikovane soubory a odstranilo to. Ale po restartu a znovu spuštění nějaké hry se to tam znova objeví. Taky to občas vypíná windows defender. Na internetu jsem našel návod jak to odstranit - odkaz zde : https://medium.com/@xymyike/how-to-remo ... 0c1bba46b2 Akorát si na to netroufám sám, byl by někdo ochotný mi s tím pomoci? Pomocí nějakého videohovoru například. Nebo pokud existuje i nějaký jiný způsob jak se toho zbavit? Prosím o radu, jsem už z toho zoufalý...
Ještě zde příkládám fotky z windows defenderu : https://ctrlv.cz/4tfv https://ctrlv.cz/k2mP Moc vás prosím o pomoc, jsem v tomto uplny amater a fakt nevim co mam delat, je mi z toho na nic.... Šlo by mi to prosím vysvětlit nějak jako úplnému neznalci?

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 18:01
od Rudy
Zdravím!
Dejte logy FRST+Addition: https://forum.viry.cz/viewtopic.php?f=13&t=154679 .

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 18:10
od prqyl
Už jsem přiložil logy

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 18:54
od Rudy
OK. Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 19:17
od prqyl
přikládám zde log, zde už žádný soubor asi nebude nalezen, protože jsem toto dělal ještě předtím, než jsem sem vůbec napsal a předtím mi to našlo nějaké 2 soubory
# -------------------------------
# Malwarebytes AdwCleaner 7.2.5.0
# -------------------------------
# Build: 11-26-2018
# Database: 2018-11-30.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-01-2018
# Duration: 00:00:02
# OS: Windows 10 Pro
# Cleaned: 0
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1378 octets] - [01/12/2018 15:43:45]
AdwCleaner[C00].txt - [1524 octets] - [01/12/2018 15:46:50]
AdwCleaner[S01].txt - [1371 octets] - [01/12/2018 19:06:54]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########




a toto je ten starý log:
# -------------------------------
# Malwarebytes AdwCleaner 7.2.5.0
# -------------------------------
# Build: 11-26-2018
# Database: 2018-11-30.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-01-2018
# Duration: 00:00:06
# OS: Windows 10 Pro
# Cleaned: 2
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Windows\SysWOW64\C2MP

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|Codec Settings UAC Manager

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1378 octets] - [01/12/2018 15:43:45]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 19:56
od Rudy
Dejte nové logy FRST+Addition.

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 20:05
od prqyl
přikládám zde

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 21:17
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
C:\Users\Karlovec\AppData\LocalLow\Temp
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\System32\Tasks\{E716ABBA-9E5E-42AB-9186-A183C6221B29}
C:\WINDOWS\System32\Tasks\{838EF32A-09BE-45E0-831F-50F6CF0719A4}
C:\WINDOWS\System32\Tasks\{EF28D22A-3249-417B-A205-DDCBD0E3C7F9}
C:\WINDOWS\System32\Tasks\{52F02491-C528-4441-BA01-1E76C4548880}
C:\WINDOWS\System32\Tasks\{E535B888-DB9D-457F-AECD-91122BC55493}
C:\WINDOWS\System32\Tasks\{F18581D8-8108-4436-9B6E-7D418E8E567A}
C:\WINDOWS\System32\Tasks\{93708A26-A351-4236-B0AA-2CDF2DBC34A7}
C:\WINDOWS\System32\Tasks\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37}
C:\WINDOWS\System32\Tasks\{6A315494-1DB4-4462-8F89-ABCC792C7C72}
C:\WINDOWS\System32\Tasks\{74A13E07-4F0C-4E9F-9B43-5F107FDA9CAF}
C:\WINDOWS\System32\Tasks\{E29454BB-FD10-4809-8B90-6FF2E8ED80B8}
C:\Program Files\rempl
C:\Users\Karlovec\AppData\Local\Temp
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {07B87440-B229-4B1E-AD31-AFEA4C4AA6EF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {287D770D-C620-449D-9D88-F4BB2EB694A9} - System32\Tasks\{E716ABBA-9E5E-42AB-9186-A183C6221B29} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Cenega Czech\Mafia\Game.exe" -d "C:\Program Files (x86)\Cenega Czech\Mafia"
Task: {28CFECA8-411F-49A5-8411-131AB78F2009} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {2CCF163C-0DD3-4370-8B0C-DE4228279DF0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {2CF45287-7DE7-4057-9F20-FFC633531BF7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {33461A78-3BD2-4054-9607-BAC9651EBF5D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {3A474997-8CD5-40D6-B5D9-DE110C7A0C95} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {3AEDDDEB-D2BA-42DA-BA13-4854705F9185} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-09] (Google Inc.)
Task: {58CF4D2C-B626-4DAA-BDC0-EFBA42F9B85A} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {716F42C3-363A-4043-A3DB-2AD724F6DFC2} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {8EE7FC2C-5BC8-41C1-96D5-CBE58DA1167C} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {A388A92B-C02D-4F67-A6E4-ECA652C23391} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {AED4FD54-D39E-4C1D-8465-5297ED209E7F} - System32\Tasks\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37} => C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_19_0_0_226_pepper.exe -c -maintain pepperplugin
Task: {C71AC7F0-5227-4293-81E3-2372801F3B0C} - System32\Tasks\{52F02491-C528-4441-BA01-1E76C4548880} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=0
Task: {D2D81EEC-1752-4FA8-9D72-DD7EC0237D53} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D7F220CB-2643-47B7-9601-891EF1FB0BC2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-09] (Google Inc.)
Task: {E06EB401-C5C9-417D-8E7C-6DE06E4CEFC6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {EB4BD79C-1AE1-4199-B4A2-39BB979AB84F} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {EF92DCEC-C7AE-4D37-AC88-DD9C62080FD1} - \WPD\SqmUpload_S-1-5-21-1109753939-290815030-3363476814-1001 -> No File <==== ATTENTION
Task: {F9E8D906-3CF2-4A1A-B26F-6E904CCC743B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
AlternateDataStreams: C:\Users\Karlovec\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Karlovec\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Public\AppData:CSM [478]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
C:\WINDOWS\Systemcall.exe

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 21:28
od prqyl
posílám zde:
Fix result of Farbar Recovery Scan Tool (x64) Version: 01.12.2018 01
Ran by Karlovec (01-12-2018 21:21:53) Run:1
Running from C:\Users\Karlovec\Desktop
Loaded Profiles: Karlovec (Available Profiles: Karlovec)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
C:\Users\Karlovec\AppData\LocalLow\Temp
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\System32\Tasks\{E716ABBA-9E5E-42AB-9186-A183C6221B29}
C:\WINDOWS\System32\Tasks\{838EF32A-09BE-45E0-831F-50F6CF0719A4}
C:\WINDOWS\System32\Tasks\{EF28D22A-3249-417B-A205-DDCBD0E3C7F9}
C:\WINDOWS\System32\Tasks\{52F02491-C528-4441-BA01-1E76C4548880}
C:\WINDOWS\System32\Tasks\{E535B888-DB9D-457F-AECD-91122BC55493}
C:\WINDOWS\System32\Tasks\{F18581D8-8108-4436-9B6E-7D418E8E567A}
C:\WINDOWS\System32\Tasks\{93708A26-A351-4236-B0AA-2CDF2DBC34A7}
C:\WINDOWS\System32\Tasks\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37}
C:\WINDOWS\System32\Tasks\{6A315494-1DB4-4462-8F89-ABCC792C7C72}
C:\WINDOWS\System32\Tasks\{74A13E07-4F0C-4E9F-9B43-5F107FDA9CAF}
C:\WINDOWS\System32\Tasks\{E29454BB-FD10-4809-8B90-6FF2E8ED80B8}
C:\Program Files\rempl
C:\Users\Karlovec\AppData\Local\Temp
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {07B87440-B229-4B1E-AD31-AFEA4C4AA6EF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {287D770D-C620-449D-9D88-F4BB2EB694A9} - System32\Tasks\{E716ABBA-9E5E-42AB-9186-A183C6221B29} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Cenega Czech\Mafia\Game.exe" -d "C:\Program Files (x86)\Cenega Czech\Mafia"
Task: {28CFECA8-411F-49A5-8411-131AB78F2009} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {2CCF163C-0DD3-4370-8B0C-DE4228279DF0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {2CF45287-7DE7-4057-9F20-FFC633531BF7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {33461A78-3BD2-4054-9607-BAC9651EBF5D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {3A474997-8CD5-40D6-B5D9-DE110C7A0C95} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {3AEDDDEB-D2BA-42DA-BA13-4854705F9185} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-09] (Google Inc.)
Task: {58CF4D2C-B626-4DAA-BDC0-EFBA42F9B85A} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {716F42C3-363A-4043-A3DB-2AD724F6DFC2} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {8EE7FC2C-5BC8-41C1-96D5-CBE58DA1167C} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {A388A92B-C02D-4F67-A6E4-ECA652C23391} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {AED4FD54-D39E-4C1D-8465-5297ED209E7F} - System32\Tasks\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37} => C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_19_0_0_226_pepper.exe -c -maintain pepperplugin
Task: {C71AC7F0-5227-4293-81E3-2372801F3B0C} - System32\Tasks\{52F02491-C528-4441-BA01-1E76C4548880} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=0
Task: {D2D81EEC-1752-4FA8-9D72-DD7EC0237D53} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D7F220CB-2643-47B7-9601-891EF1FB0BC2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-09] (Google Inc.)
Task: {E06EB401-C5C9-417D-8E7C-6DE06E4CEFC6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {EB4BD79C-1AE1-4199-B4A2-39BB979AB84F} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {EF92DCEC-C7AE-4D37-AC88-DD9C62080FD1} - \WPD\SqmUpload_S-1-5-21-1109753939-290815030-3363476814-1001 -> No File <==== ATTENTION
Task: {F9E8D906-3CF2-4A1A-B26F-6E904CCC743B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
AlternateDataStreams: C:\Users\Karlovec\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Karlovec\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Public\AppData:CSM [478]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
C:\WINDOWS\Systemcall.exe

EmptyTemp:
End
*****************

Processes closed successfully.
C:\Users\Karlovec\AppData\LocalLow\Temp => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\WINDOWS\System32\Tasks\{E716ABBA-9E5E-42AB-9186-A183C6221B29} => moved successfully
C:\WINDOWS\System32\Tasks\{838EF32A-09BE-45E0-831F-50F6CF0719A4} => moved successfully
C:\WINDOWS\System32\Tasks\{EF28D22A-3249-417B-A205-DDCBD0E3C7F9} => moved successfully
C:\WINDOWS\System32\Tasks\{52F02491-C528-4441-BA01-1E76C4548880} => moved successfully
C:\WINDOWS\System32\Tasks\{E535B888-DB9D-457F-AECD-91122BC55493} => moved successfully
C:\WINDOWS\System32\Tasks\{F18581D8-8108-4436-9B6E-7D418E8E567A} => moved successfully
C:\WINDOWS\System32\Tasks\{93708A26-A351-4236-B0AA-2CDF2DBC34A7} => moved successfully
C:\WINDOWS\System32\Tasks\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37} => moved successfully
C:\WINDOWS\System32\Tasks\{6A315494-1DB4-4462-8F89-ABCC792C7C72} => moved successfully
C:\WINDOWS\System32\Tasks\{74A13E07-4F0C-4E9F-9B43-5F107FDA9CAF} => moved successfully
C:\WINDOWS\System32\Tasks\{E29454BB-FD10-4809-8B90-6FF2E8ED80B8} => moved successfully

"C:\Program Files\rempl" folder move:

Could not move "C:\Program Files\rempl" => Scheduled to move on reboot.

C:\Users\Karlovec\AppData\Local\Temp => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{07B87440-B229-4B1E-AD31-AFEA4C4AA6EF}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{07B87440-B229-4B1E-AD31-AFEA4C4AA6EF}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{287D770D-C620-449D-9D88-F4BB2EB694A9}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{287D770D-C620-449D-9D88-F4BB2EB694A9}" => removed successfully
"C:\WINDOWS\System32\Tasks\{E716ABBA-9E5E-42AB-9186-A183C6221B29}" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E716ABBA-9E5E-42AB-9186-A183C6221B29}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{28CFECA8-411F-49A5-8411-131AB78F2009}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28CFECA8-411F-49A5-8411-131AB78F2009}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2CCF163C-0DD3-4370-8B0C-DE4228279DF0}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2CCF163C-0DD3-4370-8B0C-DE4228279DF0}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2CF45287-7DE7-4057-9F20-FFC633531BF7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2CF45287-7DE7-4057-9F20-FFC633531BF7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{33461A78-3BD2-4054-9607-BAC9651EBF5D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{33461A78-3BD2-4054-9607-BAC9651EBF5D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3A474997-8CD5-40D6-B5D9-DE110C7A0C95}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A474997-8CD5-40D6-B5D9-DE110C7A0C95}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3AEDDDEB-D2BA-42DA-BA13-4854705F9185}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AEDDDEB-D2BA-42DA-BA13-4854705F9185}" => removed successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58CF4D2C-B626-4DAA-BDC0-EFBA42F9B85A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58CF4D2C-B626-4DAA-BDC0-EFBA42F9B85A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{716F42C3-363A-4043-A3DB-2AD724F6DFC2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{716F42C3-363A-4043-A3DB-2AD724F6DFC2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8EE7FC2C-5BC8-41C1-96D5-CBE58DA1167C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EE7FC2C-5BC8-41C1-96D5-CBE58DA1167C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A388A92B-C02D-4F67-A6E4-ECA652C23391}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A388A92B-C02D-4F67-A6E4-ECA652C23391}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AED4FD54-D39E-4C1D-8465-5297ED209E7F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AED4FD54-D39E-4C1D-8465-5297ED209E7F}" => removed successfully
"C:\WINDOWS\System32\Tasks\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37}" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A155EC7-CBF5-43D3-9F93-4F6639FA1E37}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C71AC7F0-5227-4293-81E3-2372801F3B0C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C71AC7F0-5227-4293-81E3-2372801F3B0C}" => removed successfully
"C:\WINDOWS\System32\Tasks\{52F02491-C528-4441-BA01-1E76C4548880}" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{52F02491-C528-4441-BA01-1E76C4548880}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D2D81EEC-1752-4FA8-9D72-DD7EC0237D53}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2D81EEC-1752-4FA8-9D72-DD7EC0237D53}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D7F220CB-2643-47B7-9601-891EF1FB0BC2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7F220CB-2643-47B7-9601-891EF1FB0BC2}" => removed successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E06EB401-C5C9-417D-8E7C-6DE06E4CEFC6}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E06EB401-C5C9-417D-8E7C-6DE06E4CEFC6}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB4BD79C-1AE1-4199-B4A2-39BB979AB84F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB4BD79C-1AE1-4199-B4A2-39BB979AB84F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF92DCEC-C7AE-4D37-AC88-DD9C62080FD1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF92DCEC-C7AE-4D37-AC88-DD9C62080FD1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-1109753939-290815030-3363476814-1001" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F9E8D906-3CF2-4A1A-B26F-6E904CCC743B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9E8D906-3CF2-4A1A-B26F-6E904CCC743B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
C:\Users\Karlovec\Application Data => ":00e481b5e22dbe1f649fcddd505d3eb7" ADS removed successfully
"C:\Users\Karlovec\AppData\Roaming" => ":00e481b5e22dbe1f649fcddd505d3eb7" ADS not found.
C:\Users\Public\AppData => ":CSM" ADS removed successfully
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
"C:\WINDOWS\Systemcall.exe" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 243753180 B
Java, Flash, Steam htmlcache => 878460436 B
Windows/system/drivers => 876744 B
Edge => 12362 B
Chrome => 506868462 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 7072 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 10674 B
LocalService => 0 B
NetworkService => 16646 B
NetworkService => 0 B
Karlovec => 795820 B

RecycleBin => 430 B
EmptyTemp: => 1.5 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 01-12-2018 21:25:57)

C:\Program Files\rempl => Is moved successfully

==== End of Fixlog 21:25:58 ====

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 01 pro 2018 21:56
od Rudy
Smazáno. Nastala nějaká změna?

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 02 pro 2018 15:03
od prqyl
Zatím vše vypadá OK. Kdyby něco ozvu se znovu. Děkuji za pomoc!

Re: Win32/Fuery.B!cl Virus - může mi někdo pomoct s odvirová

Napsal: 02 pro 2018 16:09
od Rudy
OK, rádo se stalo! :)