Problem z PlusHStrong signal i innymi

Witam, proszę o pomoc w usunięciu złośliwego oprogramowania. Wykonałem czyszczenie ADW Cleanerem lecz niewiele pomogło.

Wklejam logi:

 

FRST

 

http://wklej.org/id/1657973/

 

Addition

 

http://wklej.org/id/1657976/

 

Z góry dziękuję za okazaną pomoc.

 

 

Odinstaluj PlusHD Cinema 2.1cV08.03.Otwórz notatnik systemowy i wklej:

Task: C:\WINDOWS\Tasks\HSTZBDT.job = C:\Users\Pawel\AppData\Roaming\HSTZBDT.exe ==== ATTENTION
Task: C:\WINDOWS\Tasks\VAAQ.job = C:\Users\Pawel\AppData\Roaming\VAAQ.exe ==== ATTENTION
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF Extension: PlusHD Cinema 2.1cV08.03 - C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\gudwnsfn.default\Extensions\9852e04d-7923-4f02-84e5-c1a1b9fe8c30@gmail.com [2015-03-08]
FF Extension: Strong Signal - C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\gudwnsfn.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-21]
R2 buwimefe; C:\Users\Pawel\AppData\Local\622AF870-1425841966-81E4-3DC0-D897BA0D85F5\insrE712.tmp [137216 2015-03-08] () [File not signed]
R2 diseqoxe; C:\Users\Pawel\AppData\Roaming\622AF870-1425841752-81E4-3DC0-D897BA0D85F5\jnsh1E5A.tmp [173568 2015-03-08] () [File not signed]
S2 BasementDuster; C:\Program Files (x86)\IGS\BasementDuster.exe [X]
R2 korepofy; C:\Users\Pawel\AppData\Roaming\622AF870-1425841752-81E4-3DC0-D897BA0D85F5\nswEA15.tmpfs [X]
S1 qrnfd_1_10_0_9; system32\drivers\qrnfd_1_10_0_9.sys [X]
2015-03-08 19:21 - 2015-03-08 19:21 - 00613255 _____ (CMI Limited) C:\Users\Pawel\AppData\Local\nsx6670.tmp
2015-03-08 19:18 - 2015-03-08 19:18 - 01854464 _____ (Plus HDV08.03) C:\Users\Pawel\AppData\Roaming\VAAQ.exe
2015-03-08 19:18 - 2015-03-08 19:18 - 01371136 _____ (Plus HDV08.03) C:\Users\Pawel\AppData\Roaming\HSTZBDT.exe
2015-03-08 19:18 - 2015-03-08 19:18 - 00001360 _____ () C:\WINDOWS\Tasks\HSTZBDT.job
2015-03-08 19:18 - 2015-03-08 19:18 - 00001354 _____ () C:\WINDOWS\Tasks\VAAQ.job
2015-03-08 16:45 - 2015-03-09 08:28 - 00000000 ____ D () C:\AdwCleaner
2015-03-08 12:41 - 2015-03-08 12:41 - 00000000 _____ () C:\autoexec.bat
2015-03-08 12:39 - 2015-03-08 12:39 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\Pawel\Downloads\SpyHunter-Installer.exe
2015-01-25 16:12 - 2015-01-25 16:12 - 0002086 _____ () C:\Users\Pawel\AppData\Roaming\HSTZBDT
2015-03-08 19:18 - 2015-03-08 19:18 - 1371136 _____ (Plus HDV08.03) C:\Users\Pawel\AppData\Roaming\HSTZBDT.exe
2015-01-25 16:12 - 2015-01-25 16:12 - 0001248 _____ () C:\Users\Pawel\AppData\Roaming\VAAQ
2015-03-08 19:18 - 2015-03-08 19:18 - 1854464 _____ (Plus HDV08.03) C:\Users\Pawel\AppData\Roaming\VAAQ.exe
2015-03-08 19:21 - 2015-03-08 19:21 - 0613255 _____ (CMI Limited) C:\Users\Pawel\AppData\Local\nsx6670.tmp
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.