Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Samsung R580 - Safe finder, jak usunąć? + FRST

aannkkaa 25 Gru 2015 18:04 813 5
  • #1 25 Gru 2015 18:04
    aannkkaa
    Poziom 8  

    Dobry wieczór!
    Przy instalowaniu flasha zainstalował mi się również safe finder. Nie mam pojęcia jak to usunąć, mogłabym prosić o pomoc?

    0 5
  • #2 25 Gru 2015 18:15
    Kolobos
    Spec od komputerów

    Jeszcze addition.txt.

    0
  • #4 25 Gru 2015 18:31
    Acorus 20
    Spec od komputerów

    Otwórz notatnik systemowy i wklej:

    Cytat:
    ShortcutWithArgument: C:\Users\Anjia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://mmotraffic.com/catalog/goplay/1000932/...B0A0Czyzz2RtBtDtCyDtCtBtByEtCyCyDyCyDtDtBzzyB
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\...\Policies\Explorer: []
    AppInit_DLLs: C:\ProgramData\Lightzap\Con-Ex.dll => C:\ProgramData\Lightzap\Con-Ex.dll [805376 2015-12-24] ()
    AppInit_DLLs-x32: C:\ProgramData\Lightzap\Dentotech.dll => C:\ProgramData\Lightzap\Dentotech.dll [257536 2015-12-24] ()
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D10C00E4-C6A2-4FE7-8D72-CB04BCBA5F3B}&mid=df4f0105bf4b47cc869965cbb8dc4550-58d208f25f1fd10748fac9e6924e9033a57fdba8&lang=pl&ds=AVG&coid=avgtbavg&cmpid=1215tb&pr=fr&d=2015-11-12 12:36:18&v=4.2.1.951&pid=wtu&sg=&sap=dsp&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}




    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1448047...or&uid=TOSHIBAXMK5055GSX_30C5P0YMTXX30C5P0YMT
    CHR HKU\S-1-5-21-454360895-629628766-2028212663-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
    R2 vToolbarUpdater40.2.4; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.4\ToolbarUpdater.exe [1923984 2015-12-17] (AVG Secure Search)
    S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
    2015-12-24 16:57 - 2015-12-25 17:08 - 00000000 ____D C:\ProgramData\Lightzap
    2015-12-24 16:57 - 2015-12-24 16:57 - 00002377 _____ C:\windows\SysWOW64\findit.xml
    2015-12-24 16:57 - 2015-12-24 16:57 - 00000000 ____D C:\ProgramData\Lightzaps
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0
  • Pomocny post
    #5 25 Gru 2015 18:32
    Kolobos
    Spec od komputerów

    Nie pobieraj programow z dobrychprogramow za pomoc ich menadzera pobierania, ktory instaluje szkodliwe dodatki.

    Odinstaluj:
    Google Toolbar for Internet Explorer
    WinZip 20.0
    WinRar tez zbedny.

    Zainstaluj 7-zip: http://7-zip.org.pl/

    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    ShortcutWithArgument: C:\Users\Anjia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://mmotraffic.com/catalog/goplay/1000932/...B0A0Czyzz2RtBtDtCyDtCtBtByEtCyCyDyCyDtDtBzzyB
    (Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
    (Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe
    (WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\...\Policies\Explorer: []
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\...\MountPoints2: {0476519b-8ba4-11e5-9acc-b482fe38aca3} - F:\_AUTORUN\AUTORUN.EXE
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\...\MountPoints2: {047651a7-8ba4-11e5-9acc-b482fe38aca3} - G:\_AUTORUN\AUTORUN.EXE
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\...\MountPoints2: {37a029bd-8d55-11e5-ac76-806e6f6e6963} - F:\SISetup.exe
    AppInit_DLLs: C:\ProgramData\Lightzap\Con-Ex.dll => C:\ProgramData\Lightzap\Con-Ex.dll [805376 2015-12-24] ()
    AppInit_DLLs-x32: C:\ProgramData\Lightzap\Dentotech.dll => C:\ProgramData\Lightzap\Dentotech.dll [257536 2015-12-24] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2015-12-24]
    ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2015-12-24]
    ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-12-24]
    ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
    HKU\S-1-5-21-454360895-629628766-2028212663-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_plPL666
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D10C00E4-C6A2-4FE7-8D72-CB04BCBA5F3B}&mid=df4f0105bf4b47cc869965cbb8dc4550-58d208f25f1fd10748fac9e6924e9033a57fdba8&lang=pl&ds=AVG&coid=avgtbavg&cmpid=1215tb&pr=fr&d=2015-11-12 12:36:18&v=4.2.1.951&pid=wtu&sg=&sap=dsp&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-454360895-629628766-2028212663-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...KAyBdQvHMKrcUaskGrm6EEU8x-a9ADRUcimiiYaQ,,&q={searchTerms}
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - Brak pliku
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - Brak pliku
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1448047...or&uid=TOSHIBAXMK5055GSX_30C5P0YMTXX30C5P0YMT
    FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Anjia\AppData\Roaming\Mozilla\Firefox\Profiles\4xc9anc1.default\extensions\defsearchp@gmail.com => nie znaleziono
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Anjia\AppData\Roaming\Mozilla\Firefox\Profiles\4xc9anc1.default\extensions\deskCutv2@gmail.com => nie znaleziono
    CHR HKU\S-1-5-21-454360895-629628766-2028212663-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
    S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
    2015-12-24 17:02 - 2015-12-24 17:03 - 00000000 ____D C:\Users\Anjia\AppData\Local\WinZip
    2015-12-24 16:58 - 2015-12-24 17:02 - 00000000 ____D C:\ProgramData\WinZip
    2015-12-24 16:58 - 2015-12-24 16:58 - 00002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
    2015-12-24 16:58 - 2015-12-24 16:58 - 00002205 _____ C:\Users\Public\Desktop\WinZip.lnk
    2015-12-24 16:58 - 2015-12-24 16:58 - 00000000 ____D C:\Users\Anjia\AppData\Local\Nico Mak Computing
    2015-12-24 16:58 - 2015-12-24 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
    2015-12-24 16:58 - 2015-12-24 16:58 - 00000000 ____D C:\Program Files\WinZip
    2015-12-24 16:57 - 2015-12-25 17:08 - 00000000 ____D C:\ProgramData\Lightzap
    2015-12-24 16:57 - 2015-12-24 16:57 - 72753664 _____ C:\Users\Anjia\Downloads\winzip200-64.msi
    2015-12-24 16:57 - 2015-12-24 16:57 - 00002377 _____ C:\windows\SysWOW64\findit.xml
    2015-12-24 16:57 - 2015-12-24 16:57 - 00000000 ____D C:\ProgramData\Lightzaps
    2015-12-24 16:55 - 2015-12-24 16:55 - 00961984 _____ (Installer ) C:\Users\Anjia\Downloads\WinZip-12854-dp.exe
    2015-12-21 20:50 - 2015-12-24 17:09 - 00000000 ____D C:\Users\Anjia\AppData\Roaming\WarThunder
    2015-12-21 20:49 - 2015-12-21 20:49 - 00962128 _____ (Installer Soft Program ) C:\Users\Anjia\Downloads\Photoscape-12505-dp.exe
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST i to wszystko.

    0
  • #6 25 Gru 2015 18:52
    aannkkaa
    Poziom 8  

    I wszystko wyczytał Pan z tych dwóch plików? Dla mnie to jedynie ciąg niezrozumiałych znaków. Jestem pełna podziwu :)
    Zadziałało błyskawicznie, dziękuję bardzo za pomoc. Od dobrychprogramów będę już trzymać się z daleka.

    Jeszcze raz dziękuję i życzę wesołych, pogodnych i szczęśliwych świąt!

    PS. Korzystałam z pomocy Kolobosa.

    0