Uruchom frst z poziomu WinRe:
http://www.fixitpc.pl/topic/4414-diagnostyka-infekcji-na-niestartujących-windows/
Wykonaj tam taki Fixlist.txt:
HKU\S-1-5-21-3146931800-3533405739-1405901393-1001\...\Run: [wotlabxuqj] => explorer "hxxp://asevok.ru/?utm_source=uoua03&utm_content=11add12143a40cfea45caa1b50981941&utm_term=C486831BEBE37A06D023A84303D10416&utm_d=20160905" <===== UWAGA
HKU\S-1-5-21-3146931800-3533405739-1405901393-1001\...\MountPoints2: {abb93556-91d0-11e5-825d-94de80b5865f} - "J:\SETUP.EXE"
HKU\S-1-5-21-3146931800-3533405739-1405901393-1001\...\MountPoints2: {e8fb7731-8df6-11e5-824e-806e6f6e6963} - "I:\Setup_Testy_B.exe"
R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [355808 2016-09-05] (DotC United Inc) <==== UWAGA
R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-09-05] (DotC United Inc) <==== UWAGA
2016-09-09 21:19 - 2016-09-09 21:26 - 00001796 _____ C:\Users\Public\Desktop\MPC Desktop.lnk
2016-09-09 21:19 - 2016-09-09 21:26 - 00001741 _____ C:\Users\Public\Desktop\MPC Cleaner.lnk
2016-09-09 21:19 - 2016-09-09 21:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC Desktop
2016-09-09 06:28 - 2016-09-09 06:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlaysTV
2016-09-05 22:23 - 2016-09-05 22:23 - 00000000 ____D C:\Users\Ferbi\AppData\Local\Вoйти в Интeрнет
2016-09-05 22:21 - 2016-09-05 22:27 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
2016-09-05 22:21 - 2016-09-05 22:21 - 00060136 _____ (DotC United Inc) C:\Windows\system32\Drivers\MPCKpt.sys
2016-09-05 22:21 - 2016-09-05 22:21 - 00000000 ____D C:\Users\Ferbi\AppData\Local\Chromium
2016-09-05 22:18 - 2016-09-05 22:18 - 00000000 ____D C:\Users\Ferbi\AppData\Local\Поиcк в Интeрнете
2016-09-09 21:17 - 2015-11-23 12:49 - 00000000 ____D C:\AdwCleaner
Usun recznie katalogi:
C:\Users\Ferbi\AppData\Local\Поиcк в Интeрнете
C:\Users\Ferbi\AppData\Local\Вoйти в Интeрнет
Wykonaj ponownie ten sam Fixlist w trybie normalnym.
Po wykonaniu zamiesc nowe logi z FRST, ze skanowania (z trybu normalnego).