Dodaję nowe logi. Czy jest możliwe że to ten trojan spowodował infekcję wheelsof'em?
Wklejam zawartość Blitzblank:
BlitzBlank 1.0.0.32
File/Registry Modification Engine native application
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\windows\installer\{f51c0d38-e0b8-2588-2017-024284637aeb}", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\windows\installer\{f51c0d38-e0b8-2588-2017-024284637aeb}\@", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\windows\installer\{f51c0d38-e0b8-2588-2017-024284637aeb}\L", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\windows\installer\{f51c0d38-e0b8-2588-2017-024284637aeb}\U", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\local\{f51c0d38-e0b8-2588-2017-024284637aeb}", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\local\{f51c0d38-e0b8-2588-2017-024284637aeb}\@", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\local\{f51c0d38-e0b8-2588-2017-024284637aeb}\L", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\local\{f51c0d38-e0b8-2588-2017-024284637aeb}\U", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\local\microsoft\windows\1175", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\local\microsoft\windows\1175\3a26dfbf", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\local\microsoft\windows\1175\sqlncli.exe", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\roaming\hellomoto", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\roaming\hellomoto\BukF.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\roaming\hellomoto\TujP.dat", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\roaming\zayka", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\roaming\yhca", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\roaming\yhca\owivg.exe", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\users\cezar\appdata\roaming\quhyag", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\users\cezar\appdata\roaming\quhyag\ivdik.agi", destinationFile = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\programdata\b7e8586b00015381005d8034b4eb2367", destinationDirectory = "(null)", replaceWithDummy = 0
MoveFileOnReboot: sourceFile = "\??\c:\programdata\b7e8586b00015381005d8034b4eb2367\B7E8586B00015381005D8034B4EB2367", destinationFile = "(null)", replaceWithDummy = 0
LaunchOnReboot: launchName = "\fix.bat", commandLine = "c:\fix.bat"
OpenDriver: ZwLoadDriver(\Registry\Machine\System\CurrentControlSet\Services\blzblk) failed: status = c0000428
LaunchOnReboot: OpenDriver failed: status = c0000428
FSS.txt
SystemLook.txt
OTL.Txt