Obok frst.exe utworz plik fixlist.txt z zawartoscia:
Task: {119AEA82-BB7E-4979-934E-F3430D71BE13} - System32\Tasks\temp_f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-2 => C:\Users\Mejol\AppData\Local\Temp\nsk7A7E.tmp\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-2.exe <==== ATTENTION
Task: {20AA6390-33C0-4113-AE68-491179F5EA65} - System32\Tasks\DZOQTF => C:\Users\Mejol\AppData\Roaming\DZOQTF.exe [2014-09-11] (enter) <==== ATTENTION
Task: {3BB1D6A7-3B77-44F1-9634-79AC476D38B4} - System32\Tasks\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-5 => C:\Program Files (x86)\videos+ MediaPlayer+\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-5.exe <==== ATTENTION
Task: {77D858C1-E9CC-4BFF-9E07-47AC704B92A3} - System32\Tasks\temp_eb6e23c5-3bfd-45ea-b9da-9e1eb8ea3447 => C:\Program Files (x86)\videos+ MediaPlayer+\eb6e23c5-3bfd-45ea-b9da-9e1eb8ea3447.exe <==== ATTENTION
Task: {7944CF09-ACCC-42C3-9042-4A8D121EE284} - System32\Tasks\HDBRAR => C:\Users\Mejol\AppData\Roaming\HDBRAR.exe [2014-09-11] (enter) <==== ATTENTION
Task: {8D4BDF9F-2ED8-41EF-BEF1-0B82E38FB94C} - System32\Tasks\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-4 => C:\Program Files (x86)\videos+ MediaPlayer+\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-4.exe <==== ATTENTION
Task: {A4EFE918-1D87-4015-8FE5-BBFD6FDAE33F} - System32\Tasks\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-5_user => C:\Program Files (x86)\videos+ MediaPlayer+\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-5.exe <==== ATTENTION
Task: {B865C618-ABB9-4F18-9EDA-4890D7AC2FA3} - System32\Tasks\temp_62f9e9c2-55b8-476f-b5d2-35cc93d5b1ca => C:\Program Files (x86)\videos+ MediaPlayer+\62f9e9c2-55b8-476f-b5d2-35cc93d5b1ca.exe <==== ATTENTION
Task: {F87D8176-305F-4F8B-B98F-26F868F6B10C} - System32\Tasks\eb6e23c5-3bfd-45ea-b9da-9e1eb8ea3447 => C:\Program Files (x86)\videos+ MediaPlayer+\eb6e23c5-3bfd-45ea-b9da-9e1eb8ea3447.exe <==== ATTENTION
Task: C:\Windows\Tasks\DZOQTF.job => C:\Users\Mejol\AppData\Roaming\DZOQTF.exe
Task: C:\Windows\Tasks\HDBRAR.job => C:\Users\Mejol\AppData\Roaming\HDBRAR.exe
FF Extension: videos+ MediaPlayer+ - C:\Users\Mejol\AppData\Roaming\Mozilla\Firefox\Profiles\pxy5d86z.default\Extensions\BHOKP84458125@VTA31058834.com [2014-09-11]
2014-09-14 16:34 - 2014-09-14 16:36 - 00000000 ____D () C:\AdwCleaner
2014-09-11 21:51 - 2014-09-14 16:39 - 00001338 _____ () C:\Windows\Tasks\HDBRAR.job
2014-09-11 21:51 - 2014-09-12 08:45 - 00003466 _____ () C:\Windows\System32\Tasks\temp_f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-2
2014-09-11 21:51 - 2014-09-11 21:51 - 01935264 _____ (enter) C:\Users\Mejol\AppData\Roaming\HDBRAR.exe
2014-09-11 21:51 - 2014-09-11 21:51 - 01488800 _____ (enter) C:\Users\Mejol\AppData\Roaming\DZOQTF.exe
2014-09-11 21:51 - 2014-09-11 21:51 - 00005848 _____ () C:\Windows\System32\Tasks\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-4
2014-09-11 21:51 - 2014-09-11 21:51 - 00004824 _____ () C:\Windows\System32\Tasks\f2b68ce7-eaeb-4e75-ac89-b2b7145353fa-5
2014-09-11 21:51 - 2014-09-11 21:51 - 00004376 _____ () C:\Windows\System32\Tasks\HDBRAR
2014-09-11 21:51 - 2014-09-11 21:51 - 00003488 _____ () C:\Windows\System32\Tasks\temp_62f9e9c2-55b8-476f-b5d2-35cc93d5b1ca
2014-09-11 21:51 - 2014-09-11 21:51 - 00003382 _____ () C:\Windows\System32\Tasks\DZOQTF
2014-09-11 21:51 - 2014-09-11 21:51 - 00002688 _____ () C:\Windows\System32\Tasks\temp_eb6e23c5-3bfd-45ea-b9da-9e1eb8ea3447
2014-09-11 21:51 - 2014-09-11 21:51 - 00002688 _____ () C:\Windows\System32\Tasks\eb6e23c5-3bfd-45ea-b9da-9e1eb8ea3447
2014-09-11 21:51 - 2014-09-11 21:51 - 00001338 _____ () C:\Windows\Tasks\DZOQTF.job
2014-09-11 21:51 - 2014-09-11 21:51 - 00000000 ____D () C:\Users\Mejol\AppData\Local\com
2014-09-11 21:50 - 2014-09-11 21:50 - 01339544 _____ () C:\Users\Mejol\Downloads\Player_Setup.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Mejol\AppData\Roaming\DZOQTF
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Mejol\AppData\Roaming\HDBRAR
2014-09-11 23:01 - 2014-09-11 23:01 - 00632808 _____ (ClickMeIn Limited) C:\Users\Mejol\AppData\Local\nsn61A5.tmp
2014-09-11 22:36 - 2014-09-11 22:36 - 00617369 _____ (ClickMeIn Limited) C:\Users\Mejol\AppData\Local\nsdAA64.tmp
C:\Program Files (x86)\videos+ MediaPlayer+\
EmptyTemp:
W FRST wybierz Fix.
Zrob pelny skan przy pomocy Mbam:
http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
Po wykonaniu usun katalog C:\FRST i to wszystko.