Jak usunac key-find


(Mati36772) #1

Czytalem na dorum ze potrzeba skanowanie programem Frst:

http://www.wklej.org/id/1656434/

prosze o wyrozumialosc i pomoc


(Acorus) #2

Otwórz notatnik systemowy i wklej:

GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
HKU\S-1-5-21-114616064-4221931339-3264711685-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsppts=1424021108from=coruid=395049983_266035_A092A533q={searchTerms}
HKU\S-1-5-21-114616064-4221931339-3264711685-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
HKU\S-1-5-21-114616064-4221931339-3264711685-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
HKU\S-1-5-21-114616064-4221931339-3264711685-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsppts=1424021108from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsts=1424021100from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKU\S-1-5-21-114616064-4221931339-3264711685-1000 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424021108from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKU\S-1-5-21-114616064-4221931339-3264711685-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=395049983_266035_A092A533ts=1424021123type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-114616064-4221931339-3264711685-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=395049983_266035_A092A533ts=1424021123type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-114616064-4221931339-3264711685-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1424021108from=coruid=395049983_266035_A092A533q={searchTerms}
SearchScopes: HKU\S-1-5-21-114616064-4221931339-3264711685-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=395049983_266035_A092A533ts=1424021123type=defaultq={searchTerms}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll (Thinknice Co. Limited)
Toolbar: HKU\S-1-5-21-114616064-4221931339-3264711685-1000 - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF DefaultSearchEngine: key-find
FF SelectedSearchEngine: key-find
FF Homepage: hxxp://www.key-find.com/?type=hpppts=1424021108from=coruid=395049983_266035_A092A533
FF Extension: FF Toolbar - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\gvcjahxe.default\Extensions\fftoolbar2014@etech.com [2015-03-07]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\gvcjahxe.default\extensions\fftoolbar2014@etech.com
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [487056 2015-02-15] (SysTool PasSame LIMITED)
S2 Update Follow Rules; "C:\Program Files (x86)\Follow Rules\updateFollowRules.exe" [X]
R1 {2fc9157e-7b3c-4ebf-95d1-57a9fdf20894}Gw64; C:\Windows\System32\drivers\{2fc9157e-7b3c-4ebf-95d1-57a9fdf20894}Gw64.sys [48784 2015-02-16] (StdLib)
R1 {4a917b82-b02e-49db-87b9-93c2fbec60d7}Gw64; C:\Windows\System32\drivers\{4a917b82-b02e-49db-87b9-93c2fbec60d7}Gw64.sys [48784 2015-02-15] (StdLib)
R1 {9ca97048-43b1-43e4-b2ce-0f8419984bcc}Gw64; C:\Windows\System32\drivers\{9ca97048-43b1-43e4-b2ce-0f8419984bcc}Gw64.sys [48784 2015-02-19] (StdLib)
R1 {f40cc14b-0f67-44b4-a17e-03e43df8e712}Gw64; C:\Windows\System32\drivers\{f40cc14b-0f67-44b4-a17e-03e43df8e712}Gw64.sys [48784 2015-02-22] (StdLib)
2015-03-07 09:56 - 2015-03-07 09:56 - 00003154 _____ () C:\Windows\System32\Tasks\{6FD66748-8B13-468B-A866-EBEFF5F17C4B}
2015-02-15 18:25 - 2015-02-15 18:25 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-02-15 18:25 - 2015-02-15 18:25 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-15 18:25 - 2015-02-15 18:25 - 00000000 ____ D () C:\Program Files (x86)\XTab
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.