Wielkie dzięki za poświęcony czas.
Wygląda na to ze proces bitcoin-miner już się nie uruchamia. Odnośnie dziwnej paczki to patch do PES.
Oto logi:
BlitzBlank 1.0.0.32
File/Registry Modification Engine native application
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\programdata\razoru0", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\programdata\razoru0\iflmnkfrd.exe", destinationFile = "(null)", replaceWithDummy = 0
RemoveFile: ZwDeleteFile failed: status = c0000121
MoveDirectoryOnReboot: ProcessElement failed: status = c0000121
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\dawid\appdata\local\temp", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\dawid\appdata\local\temp\FXSAPIDebugLogFile.txt", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\dawid\appdata\local\temp\iflmnkfrdvb.exe", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\dawid\appdata\local\temp\Low", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\dawid\appdata\local\temp\nkadlsgfden.exe", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\dawid\appdata\local\temp\wargaming.net", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\dawid\appdata\local\temp\wargaming.net\wot", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\dawid\appdata\local\temp\WPDNSE", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\dawid\appdata\local\temp\~DFDB59AA5B1533FA8A.TMP", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\programdata\adobeupdate.exe", destinationFile = "(null)", replaceWithDummy = 0
LaunchOnReboot: launchName = "\fix.bat", commandLine = "c:\fix.bat"
OpenDriver: ZwLoadDriver(\Registry\Machine\System\CurrentControlSet\Services\blzblk) failed: status = c0000428
LaunchOnReboot: OpenDriver failed: status = c0000428
AdwCleanerS1.txt
OTL.Txt