Jak usunąć safe finder?

Pytanie jak w temacie jak się tego pozbyć??? Jak wchodzę do odinstaluj lub zmień program i klikam na safe finder odinstaluj to nic się nie dzieje.

system win 7pro

 

https://forum.dobreprogramy.pl/t/471355/1?source_topic_id=508107

Oto raporty co dalej?

http://www.wklej.org/id/2034189/

http://www.wklej.org/id/2034191/

http://www.wklej.org/id/2034194/

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia ======= UWAGA
HKU\S-1-5-21-3356050665-2197870431-129362846-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEYzwmkwM3HPmqx6qH3UpKemB0P_AuQY9Pn3XXzxrVdm_oWyeFnoLGKgEvhjID0yD6ihJVmsevo1opDKZcgRKOQIdiABUoY6vp5qb68gM8f-l9_YFzD3lMsKBA3YxitOLrBsT9bfLkcLk30_GCaZlIJCoM21mHrB3rmgOTx2P4,q={searchTerms}
HKU\S-1-5-21-3356050665-2197870431-129362846-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEYzwmkwM3HPmqx6qH3UpKemB0P_AuQY9Pn3XXzxrVdm_oWyeFnoLGKgEvhjID0yD6ihJVmsevo1opDJT7e8xfUDXGQODI8Dj0FpzfouNVSSO5M4UoE0K2A69xX2PZxtrwRWYH3SZhaa5SqZQ9K_LxHdiQuBKv10kiJ_KftXzE,
HKU\S-1-5-21-3356050665-2197870431-129362846-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEYzwmkwM3HPmqx6qH3UpKemB0P_AuQY9Pn3XXzxrVdm_oWyeFnoLGKgEvhjID0yD6ihJVmsevo1opDKZcgRKOQIdiABUoY6vp5qb68gM8f-l9_YFzD3lMsKBA3YxitOLrBsT9bfLkcLk30_GCaZlIJCoM21mHrB3rmgOTx2P4,q={searchTerms}
HKU\S-1-5-21-3356050665-2197870431-129362846-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnkdYvIvvwfEYzwmkwM3HPmqx6qH3UpKemB0P_AuQY9Pn3XXzxrVdm_oWyeFnoLGKgEvhjID0yD6ihJVmsevo1opDKZcgRKOQIdiABUoY6vp5qb68gM8f-l9_YFzD3lMsKBA3YxitOLrBsT9bfLkcLk30_GCaZlIJCoM21mHrB3rmgOTx2P4,q={searchTerms}
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iryhsimp=yhs-fullyhosted_003type=wny_kmpswt_15_52_newdopparam1=1param2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutCzztDtAyBtA0A0FtAtC0C0E0EyDtB0DtN0D0Tzu0StCyEyDtCtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StAtByDyEtA0FtAyBtGyD0FtC0BtG0C0C0A0AtGyCtCtCyDtGzytBtCtAtAyDyD0EtB0AyCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0E0C0EtCtDyC0CzztGyByDzyyEtGyEyE0EyBtGzytD0EtCtG0B0E0BtDyB0DtAyByEzzyC0C2QtN0A0LzuyE%26cr%3D834214145%26a%3Dwny_kmpswt_15_52_newdop%26os%3DWindows%2B7%2BProfessionalp={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iryhsimp=yhs-fullyhosted_003type=wny_kmpswt_15_52_newdopparam1=1param2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutCzztDtAyBtA0A0FtAtC0C0E0EyDtB0DtN0D0Tzu0StCyEyDtCtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StAtByDyEtA0FtAyBtGyD0FtC0BtG0C0C0A0AtGyCtCtCyDtGzytBtCtAtAyDyD0EtB0AyCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0E0C0EtCtDyC0CzztGyByDzyyEtGyEyE0EyBtGzytD0EtCtG0B0E0BtDyB0DtAyByEzzyC0C2QtN0A0LzuyE%26cr%3D834214145%26a%3Dwny_kmpswt_15_52_newdop%26os%3DWindows%2B7%2BProfessionalp={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {ielnksrch} URL =
SearchScopes: HKU\S-1-5-21-3356050665-2197870431-129362846-1000 - DefaultScope {ielnksrch} URL =
SearchScopes: HKU\S-1-5-21-3356050665-2197870431-129362846-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iryhsimp=yhs-fullyhosted_003type=wny_kmpswt_15_52_newdopparam1=1param2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutCzztDtAyBtA0A0FtAtC0C0E0EyDtB0DtN0D0Tzu0StCyEyDtCtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StAtByDyEtA0FtAyBtGyD0FtC0BtG0C0C0A0AtGyCtCtCyDtGzytBtCtAtAyDyD0EtB0AyCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0E0C0EtCtDyC0CzztGyByDzyyEtGyEyE0EyBtGzytD0EtCtG0B0E0BtDyB0DtAyByEzzyC0C2QtN0A0LzuyE%26cr%3D834214145%26a%3Dwny_kmpswt_15_52_newdop%26os%3DWindows%2B7%2BProfessionalp={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF NewTab: C:\\ProgramData\\Graveairs\\ff.NT
FF SelectedSearchEngine: Search Provided by Yahoo
R2 CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe [764416 2016-03-02] () [Brak podpisu cyfrowego]
S3 GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [X]
2016-03-02 20:32 - 2016-03-02 20:35 - 00000000 ____ D C:\AdwCleaner
2016-03-02 20:21 - 2016-03-02 20:21 - 00000000 ____ D C:\Program Files\Enigma Software Group
2016-03-02 20:12 - 2016-03-02 20:19 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\DELL\Downloads\SpyHunter-Installer.exe
2016-03-02 19:52 - 2016-03-02 19:52 - 00000000 ____ D C:\Users\DELL\AppData\Roaming\dlg
2016-03-02 13:55 - 2016-03-02 13:56 - 00000000 ____ D C:\ProgramData\Graveairs
2016-03-02 13:54 - 2016-03-02 15:20 - 00000000 ____ D C:\ProgramData\Graveair
2016-03-02 13:54 - 2016-03-02 13:54 - 08003072 _____ C:\Users\DELL\AppData\Roaming\agent.dat
2016-03-02 13:54 - 2016-03-02 13:54 - 01894566 _____ C:\Users\DELL\AppData\Roaming\DanCof.tst
2016-03-02 13:54 - 2016-03-02 13:54 - 00126464 _____ C:\Users\DELL\AppData\Roaming\noah.dat
2016-03-02 13:54 - 2016-03-02 13:54 - 00064752 _____ C:\Users\DELL\AppData\Roaming\Config.xml
2016-03-02 13:54 - 2016-03-02 13:54 - 00018432 _____ C:\Users\DELL\AppData\Roaming\Main.dat
2016-03-02 13:52 - 2016-03-02 13:54 - 00005568 _____ C:\Users\DELL\AppData\Roaming\md.xml
2016-03-02 13:52 - 2016-03-02 13:52 - 00126464 _____ C:\Users\DELL\AppData\Roaming\lobby.dat
2016-03-02 13:52 - 2016-03-02 13:52 - 00072795 _____ C:\Users\DELL\AppData\Roaming\Donbam.tst
2016-03-02 13:52 - 2016-03-02 13:52 - 00054272 _____ C:\Users\DELL\AppData\Roaming\ApplicationHosting.dat
2016-03-02 13:52 - 2016-03-02 13:52 - 00000000 ____ D C:\ProgramData\CloudPrinter
2016-03-02 13:52 - 2016-03-02 13:50 - 00764416 _____ C:\Users\DELL\AppData\Roaming\Donbam.exe
2016-03-02 13:52 - 2016-03-02 13:50 - 00764416 _____ C:\Users\DELL\AppData\Roaming\DanCof.exe
2016-03-02 13:51 - 2016-03-02 13:51 - 00848437 _____ C:\Users\DELL\AppData\Roaming\Bluezap.bin
2016-03-02 13:50 - 2016-03-02 13:50 - 00127488 _____ C:\Users\DELL\AppData\Roaming\Installer.dat
2016-03-02 13:50 - 2016-03-02 13:50 - 00015888 _____ C:\Users\DELL\AppData\Roaming\InstallationConfiguration.xml
2016-03-02 13:54 - 2016-03-02 13:54 - 0032038 _____ () C:\Users\DELL\AppData\Roaming\uninstall_temp.ico
Task: {0CBDF407-C053-41A7-8220-1D4B267FD800} - System32\Tasks\{53969F48-18D3-43A7-B8B7-03383D39A162} = pcalua.exe -a "C:\Program Files (x86)\Common Files\Dalttough\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Dalttough\uninstall.dat" -a uninstallme 0E00B9FD-C2B4-4AB2-9560-E3678850D080 DeviceId=9da6130d-d2a4-e065-4861-1f77327ceaa2 BarcodeId=50036003 ChannelId=3 DistributerName=APSFCovus
Task: {90715B58-9787-4592-80BF-8E31F2C19451} - System32\Tasks\{40FEE205-8031-46F5-8620-47DBEF0BB47F} = pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{F0A421DB-030E-40DE-A3E6-EC340B1074BC}\setup.exe" -c -runfromtemp -l0x0015 -removeonly
Task: {F23F626B-1E8D-4260-AA5C-B3704C3CE983} - System32\Tasks\{0D4F9B99-888A-4C2D-B7EC-54D653081559} = pcalua.exe -a D:\Autorun.exe -d D:\
ShortcutWithArgument: C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) - %SNP%
ShortcutWithArgument: C:\Users\DELL\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) - %SNP%
ShortcutWithArgument: C:\Users\DELL\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) - %SNF%
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) - %SNF%
EmptyTemp:

Uruchom FRST i kliknij Napraw (Fix). Pokaż raport z usuwania Fixlog.

 

Do systemowego notatnika znaczy gdzie? Sory za głupie pytanie ale nwm.

Wszystkie programy -> Akcesoria -> Notatnik

http://windows.microsoft.com/pl-pl/windows/open-notepad#1TC=windows-7

Dobra sory nie zrozumiałem :wink: zaraz pokażę raport

Robię ten plik fixlist.txt wklejam co podałeś i wyskakuje, że “nie odnaleziono pliku fixlist.txt plik należy utworzyć w folderze z programem” no i tam właśnie robię i ciągle to samo. Co zle robię?

 

Mam co trzeba

 http://www.wklej.org/id/2034653/

http://www.wklej.org/id/2034675/

http://www.wklej.org/id/2034688/

Skasuj folder C:\FRST

Dobra safe findera nie ma. Dzięki za pomoc.