Problem z PSW.Papras.ED

Witam

Prosze o pomoc w usunięciu infekcji

Z góry dziękuje.

http://wklej.org/id/1716516/

http://wklej.org/id/1716518/

http://wklej.org/id/1716521/

Odinstaluj Adobe Reader 9.1 - Polish.Otwórz notatnik systemowy i wklej:

HKLM-x32\...\Run: [Adobe Reader Speed Launcher] = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)
HKU\S-1-5-21-3376702620-2707505653-2522717313-1000\...\Winlogon: [Shell] C:\ProgramData\HP\HP Deskjet 5520 series\Installer\Help\1028\truncated_mean\capacitor.exe,explorer.exe ==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MMS FlowMaster.lnk [2014-03-05]
ShortcutTarget: MMS FlowMaster.lnk - C:\mmsFlowMaster\mmsFlowMaster.exe (No File)
SearchScopes: HKU\S-1-5-21-3376702620-2707505653-2522717313-1000 - {481BD4F8-1E33-4DB7-8CCD-43B961951371} URL = http://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-3376702620-2707505653-2522717313-1000 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-3376702620-2707505653-2522717313-1000 - {729654A2-0172-4F6D-BE1C-5FB05907248D} URL = http://www.amazon.co.uk/gp/search?ie=UTF8keywords={searchTerms}tag=tochibauk-win7-ie-search-21index=blendedlinkCode=ur2
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2015-05-15]
CHR DefaultSuggestURL: Default - http://ssmsp.ask.com/query?sstype=prefixli=ffq={searchTerms}
CHR Extension: (Bookmark Manager) - C:\Users\DYR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-27]
CHR HKLM\...\Chrome\Extension: [aaaaahlfahldnilidgnlikdckbfehhca] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [aaaaahlfahldnilidgnlikdckbfehhca] - https://clients2.google.com/service/update2/crx
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
2015-05-15 11:34 - 2015-05-15 11:34 - 00000000 ____ D () C:\ProgramData\AVG Security Toolbar
2014-11-19 11:29 - 2014-11-19 11:29 - 0000000 _____ () C:\Users\DYR\AppData\Roaming\wklnhst.dat
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.