Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Safefinder - jak się go pozbyć?

alicjaa 26 Paź 2016 23:38 465 3
  • #1 26 Paź 2016 23:38
    alicjaa
    Poziom 6  

    Witam. Moim utrapieniem związanym z Safefinderem jest otwieranie nowej karty, ostatnio problem się nasilił i co kilkanaście minut muszę zmieniać domyślną przeglądarkę na google, a mimo to gdy otwieram nową kartę wciąż wyszukuje mi przez safefindera... załączam to co wyszło z FRST

    0 3
  • #2 27 Paź 2016 00:13
    krzychupar
    Poziom 40  

    Odinstaluj:
    McAfee
    Amazon 1Button App (HKLM-x32\...\{3E69CC95-C0F6-4C74-8F43-74F9046F20B2}) (Version: 1.0.10 - Amazon) <==== UWAGA

    Otwórz notatnik systemowy i wklej:
    Task: {03853929-B56F-4424-9054-ED440B017695} - System32\Tasks\psv_Via-Tip => /c regedit.exe /s "C:\ProgramData\Quotenamron\Hotsing.reg" &amp; del "C:\ProgramData\Quotenamron\Hotsing.reg" &amp; SCHTASKS /Delete /TN "psv_Via-Tip" /F <==== UWAGA
    Task: {29135477-FCD8-4A0D-AC3F-3C69CB993EB1} - System32\Tasks\psv_Inchzap => /c regedit.exe /s "C:\ProgramData\Quotenamron\Duohold.reg" &amp; del "C:\ProgramData\Quotenamron\Duohold.reg" &amp; SCHTASKS /Delete /TN "psv_Inchzap" /F <==== UWAGA
    Task: {213590EA-AE32-402E-9E27-308F6A1D04A9} - System32\Tasks\McAfee\McAfee Idle Detection Task
    Task: {8D8EDAE3-DACB-4B5A-A77B-A10816A43A9B} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
    Task: {95FAED40-991B-4BAB-A5B6-FB6313180ABC} - System32\Tasks\{0D65B9A9-68AB-4DDA-81E8-0A99DF3EEFDA} => pcalua.exe -a "C:\Program Files (x86)\Operacja Pustynny Grom\OAA.exe" -d C:\PROGRA~2\OPERAC~1
    Task: {C47FCAB4-1B57-499C-A02F-9F670182BB8E} - System32\Tasks\psv_Daltfresh => /c regedit.exe /s "C:\ProgramData\Quotenamron\Med-Fresh.reg" &amp; del "C:\ProgramData\Quotenamron\Med-Fresh.reg" &amp; SCHTASKS /Delete /TN "psv_Daltfresh" /F <==== UWAGA
    Task: {F5BEEC70-39E1-4123-85DC-5EA93066858C} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\platform\McUICnt.exe [2016-04-23] (McAfee, Inc.)
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfemms.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.9.741.0\McCSPServiceHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
    HKU\S-1-5-21-784178985-2830456283-3502390081-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...fRWvda0ebPtcuIyKAjvXDdHLbeo8QW9UR7qG15&q={searchTerms}
    HKU\S-1-5-21-784178985-2830456283-3502390081-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://mystart.lenovo.com




    HKU\S-1-5-21-784178985-2830456283-3502390081-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...fRWvda0ebPtcuIyKAjvXDdHLbeo8QW9UR7qG15&q={searchTerms}
    HKU\S-1-5-21-784178985-2830456283-3502390081-1002\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...fRWvda0ebPtcuIyKAjvXDdHLbeo8QW9UR7qG15&q={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-784178985-2830456283-3502390081-1002 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKU\S-1-5-21-784178985-2830456283-3502390081-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2016-04-28] (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2016-04-28] (McAfee, Inc.)
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2016-06-02] [Brak podpisu cyfrowego]
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-04-28] ()
    CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%...lESTA4_iZ-jlN23qBuMrjb_JLmty8Gc7SzKDfBugKeEcV
    CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...3tCzXygDoU4HxW9WNNlkguSE2YTwYnRqBtgT47&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
    CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
    CHR Extension: (SafeFinder Search) - C:\Users\Alicja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jidkebcigjgheaahopdnlfaohgnocfai [2016-07-29]
    CHR Extension: (SafeFinder New Tab) - C:\Users\Alicja\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\knnaihaddpogmkclkahpcnhppgapinpe [2016-07-29]
    CHR HKLM-x32\...\Chrome\Extension: [jidkebcigjgheaahopdnlfaohgnocfai] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [knnaihaddpogmkclkahpcnhppgapinpe] - hxxps://clients2.google.com/service/update2/crx
    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [989192 2016-04-28] (McAfee, Inc.)
    S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [332528 2014-03-12] (McAfee, Inc.)
    R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.9.741.0\\McCSPServiceHost.exe [1903320 2016-04-18] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [795528 2016-04-20] (McAfee, Inc.)
    S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232688 2016-03-07] (McAfee, Inc.)
    R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [382456 2016-04-01] (McAfee, Inc.)
    R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [277744 2016-03-07] (McAfee, Inc.)
    R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1424352 2016-04-21] (McAfee, Inc.)
    R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [599864 2016-04-23] (McAfee, Inc.)
    S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [207968 2016-02-24] (McAfee, Inc.)
    R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [419624 2016-03-11] (McAfee, Inc.)
    R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [349480 2016-03-11] (McAfee, Inc.)
    S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [83608 2016-03-11] (McAfee, Inc.)
    R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [493352 2016-03-11] (McAfee, Inc.)
    R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [842536 2016-03-11] (McAfee, Inc.)
    R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [543488 2016-02-10] (McAfee, Inc.)
    S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [109480 2016-02-10] (McAfee, Inc.)
    R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [243496 2016-03-11] (McAfee, Inc.)
    2016-10-26 21:48 - 2016-06-27 12:08 - 00000000 ____D C:\AdwCleaner
    2016-10-26 18:29 - 2015-03-28 12:41 - 00000000 ____D C:\Program Files (x86)\Amazon
    2016-03-28 23:41 - 2016-03-28 23:41 - 6493696 _____ () C:\Users\Alicja\AppData\Roaming\agent.dat
    2016-03-28 23:41 - 2016-03-28 23:41 - 0065856 _____ () C:\Users\Alicja\AppData\Roaming\Config.xml
    2016-03-28 23:41 - 2016-03-28 23:41 - 0061177 _____ () C:\Users\Alicja\AppData\Roaming\inst.lat
    2016-03-28 23:41 - 2016-03-28 23:41 - 0014448 _____ () C:\Users\Alicja\AppData\Roaming\InstallationConfiguration.xml
    2016-03-28 23:41 - 2016-03-28 23:41 - 0127488 _____ () C:\Users\Alicja\AppData\Roaming\Installer.dat
    2016-03-28 23:41 - 2016-03-28 23:41 - 0018432 _____ () C:\Users\Alicja\AppData\Roaming\Main.dat
    2016-03-28 23:41 - 2016-03-28 23:41 - 0005568 _____ () C:\Users\Alicja\AppData\Roaming\md.xml
    2016-03-28 23:41 - 2016-03-28 23:41 - 0126464 _____ () C:\Users\Alicja\AppData\Roaming\noah.dat
    2016-03-28 23:41 - 2016-03-28 23:40 - 0960512 _____ () C:\Users\Alicja\AppData\Roaming\Solstattam.exe
    2016-03-28 23:41 - 2016-03-28 23:41 - 1622179 _____ () C:\Users\Alicja\AppData\Roaming\Solstattam.tst
    2016-03-28 23:41 - 2016-03-28 23:41 - 0032038 _____ () C:\Users\Alicja\AppData\Roaming\uninstall_temp.ico
    2016-05-13 16:41 - 2016-07-31 22:41 - 0000138 _____ () C:\Users\Alicja\AppData\Roaming\WB.CFG
    2016-03-28 23:41 - 2016-03-28 23:41 - 0402905 _____ () C:\Users\Alicja\AppData\Roaming\Zunis.bin
    2015-09-18 10:04 - 2015-09-18 10:04 - 0000000 _____ () C:\Users\Alicja\AppData\Local\{89D55EBF-0666-4AFB-A540-52D5B4BCE52A}
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom FRST i kliknij w Fix/Napraw.

    0
  • #4 27 Paź 2016 00:54
    krzychupar
    Poziom 40  

    W takim razie usuń folder C:\FRST i zamknij temat.

    0