Jak usunąć SafeFinder?

Temat pewnie stary bo i ta zaraza jakiś czas już jest w komputerze. Czy znalazł by się jakiś dobry człowiek i pomógł by mi to usunąć? Użyłem FRST który zostawił po sobie dwa pliki.FRST.txt (19,6 KB)
Addition.txt (36,9 KB)

Odinstaluj Java 7 Update 40.Otwórz notatnik systemowy i wklej:

Task: {03436C5C-C234-43A3-9FE1-89E86E8EF3DD} - System32\Tasks\psv_HayTosoft => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Graveflex.reg” & del “C:\ProgramData\AppnormanetouQ\Graveflex.reg” & SCHTASKS /Delete /TN “psv_HayTosoft” /F <==== UWAGA
Task: {1525F78B-F343-428A-B22E-0A25B138FFA7} - System32\Tasks\psv_Ventohotfresh => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Quadsoljob.reg” & del “C:\ProgramData\AppnormanetouQ\Quadsoljob.reg” & SCHTASKS /Delete /TN “psv_Ventohotfresh” /F <==== UWAGA
Task: {1FEF7E32-B9CC-4779-A77C-29BB19CA7CB7} - System32\Tasks\psv_Techtom => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Isla.reg” & del “C:\ProgramData\AppnormanetouQ\Isla.reg” & SCHTASKS /Delete /TN “psv_Techtom” /F <==== UWAGA
Task: {2742EF5E-B95E-4E86-AC8C-88A0293095E5} - System32\Tasks\psv_Stock-Tip => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Triozap.reg” & del “C:\ProgramData\AppnormanetouQ\Triozap.reg” & SCHTASKS /Delete /TN “psv_Stock-Tip” /F <==== UWAGA
Task: {279181E3-D775-4740-A3D9-FACC1B60DC1A} - System32\Tasks\psv_Zummatouch => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Good-Tip.reg” & del “C:\ProgramData\AppnormanetouQ\Good-Tip.reg” & SCHTASKS /Delete /TN “psv_Zummatouch” /F <==== UWAGA
Task: {29A601C1-6989-4898-945B-46F2D7DC99F8} - System32\Tasks\psv_Greentone => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Zootop.reg” & del “C:\ProgramData\AppnormanetouQ\Zootop.reg” & SCHTASKS /Delete /TN “psv_Greentone” /F <==== UWAGA
Task: {2BE8C6DD-36CD-4451-89F0-D652660CF4C9} - System32\Tasks\psv_Vilala => /c regedit.exe /s “C:\ProgramData\Quotenamron\Trusttom.reg” & del “C:\ProgramData\Quotenamron\Trusttom.reg” & SCHTASKS /Delete /TN “psv_Vilala” /F <==== UWAGA
Task: {3BAA3BFD-0A5D-40E8-88CC-6CC8A8A19571} - System32\Tasks\psv_Joytop => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Toughtough.reg” & del “C:\ProgramData\AppnormanetouQ\Toughtough.reg” & SCHTASKS /Delete /TN “psv_Joytop” /F <==== UWAGA
Task: {3D0585F1-7710-4AA6-8127-B1957C481CE4} - System32\Tasks\psv_Ron-Trax => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Runlab.reg” & del “C:\ProgramData\AppnormanetouQ\Runlab.reg” & SCHTASKS /Delete /TN “psv_Ron-Trax” /F <==== UWAGA
Task: {49E1CB55-F275-4449-A1C8-9EB05062FFC3} - System32\Tasks\Home PremiumSpectatesNonautomatedV2 => Rundll32.exe AbnegateGain.dll,main 7 1 <==== UWAGA
Task: {4BBBFFE4-5C32-4790-9E3D-0BBCAC06AF8E} - System32\Tasks\psv_Joyfix => /c regedit.exe /s “C:\ProgramData\Quotenamron\Dentoin.reg” & del “C:\ProgramData\Quotenamron\Dentoin.reg” & SCHTASKS /Delete /TN “psv_Joyfix” /F <==== UWAGA
Task: {5273B9BA-4E0A-4578-91B3-3F4225666012} - System32\Tasks\psv_Tempit => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Zoomtone.reg” & del “C:\ProgramData\AppnormanetouQ\Zoomtone.reg” & SCHTASKS /Delete /TN “psv_Tempit” /F <==== UWAGA
Task: {5C504494-08C1-4BCC-9C7A-E88E9DF39EA5} - System32\Tasks\psv_Rantech => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Sonbam.reg” & del “C:\ProgramData\AppnormanetouQ\Sonbam.reg” & SCHTASKS /Delete /TN “psv_Rantech” /F <==== UWAGA
Task: {645B180F-7269-4B00-BB27-2EFAD423E045} - System32\Tasks\psv_S-domlam => /c regedit.exe /s “C:\ProgramData\Quotenamron\MoveNimbam.reg” & del “C:\ProgramData\Quotenamron\MoveNimbam.reg” & SCHTASKS /Delete /TN “psv_S-domlam” /F <==== UWAGA
Task: {6E3D27BB-BB26-4ED2-B952-0B034C1BDD53} - System32\Tasks{0F7F52D6-3109-4221-84EB-A11009DCE535} => pcalua.exe -a “C:\Program Files\Common Files\U-Ity\uninstall.exe” -c shuz -f “C:\Program Files\Common Files\U-Ity\uninstall.dat” -a uninstallme 1534E834-AAA2-4696-94ED-5D2AF68A7A58 DeviceId=ff5cf34a-d4b7-0d85-3c82-efd485d50f08 BarcodeId=51162003 ChannelId=3 DistributerName=APSFIscFFIE
Task: {6E8107EC-E5CF-4E70-B054-00945EDB86FC} - System32\Tasks\psv_Silhotlam => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Eco-Soft.reg” & del “C:\ProgramData\AppnormanetouQ\Eco-Soft.reg” & SCHTASKS /Delete /TN “psv_Silhotlam” /F <==== UWAGA
Task: {6FF3CA4B-F834-4E5B-9094-993F5903D767} - System32\Tasks\psv_Driping => /c regedit.exe /s “C:\ProgramData\Quotenamron\MedNamtech.reg” & del “C:\ProgramData\Quotenamron\MedNamtech.reg” & SCHTASKS /Delete /TN “psv_Driping” /F <==== UWAGA
Task: {705C4694-F1DF-474E-8603-D12DE91ED2BB} - System32\Tasks\psv_Laeco => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\LatRundom.reg” & del “C:\ProgramData\AppnormanetouQ\LatRundom.reg” & SCHTASKS /Delete /TN “psv_Laeco” /F <==== UWAGA
Task: {711E4101-0DB6-4055-889C-64503076F103} - System32\Tasks\psv_Zottech => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Inchcancore.reg” & del “C:\ProgramData\AppnormanetouQ\Inchcancore.reg” & SCHTASKS /Delete /TN “psv_Zottech” /F <==== UWAGA
Task: {726F739E-FBDB-44B8-ADC6-41BA2ACADCF1} - System32\Tasks\psv_Aptop => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Qvofax.reg” & del “C:\ProgramData\AppnormanetouQ\Qvofax.reg” & SCHTASKS /Delete /TN “psv_Aptop” /F <==== UWAGA
Task: {7EFFDEC9-73E7-41ED-A75C-3B2B260F6C14} - System32\Tasks\psv_StanFresh => /c regedit.exe /s “C:\ProgramData\Quotenamron\Labkix.reg” & del “C:\ProgramData\Quotenamron\Labkix.reg” & SCHTASKS /Delete /TN “psv_StanFresh” /F <==== UWAGA
Task: {86F8C184-3E09-4E2C-93A8-DD71235D7A3D} - System32\Tasks\psv_Med-Ing => /c regedit.exe /s “C:\ProgramData\Quotenamron\Geocof.reg” & del “C:\ProgramData\Quotenamron\Geocof.reg” & SCHTASKS /Delete /TN “psv_Med-Ing” /F <==== UWAGA
Task: {8752EA73-AD88-4A53-8C4C-88A4BDA4FD8F} - System32\Tasks\psv_Don-Eco => /c regedit.exe /s “C:\ProgramData\Quotenamron\Run-Lam.reg” & del “C:\ProgramData\Quotenamron\Run-Lam.reg” & SCHTASKS /Delete /TN “psv_Don-Eco” /F <==== UWAGA
Task: {87E30889-6E91-4CE8-8490-537038C652F5} - System32\Tasks\psv_IsOtflex => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Strongzuntip.reg” & del “C:\ProgramData\AppnormanetouQ\Strongzuntip.reg” & SCHTASKS /Delete /TN “psv_IsOtflex” /F <==== UWAGA
Task: {87F6D0AE-3D2D-4CBA-97EF-1CFA0EC18E80} - System32\Tasks\psv_Strongla => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Cofcof.reg” & del “C:\ProgramData\AppnormanetouQ\Cofcof.reg” & SCHTASKS /Delete /TN “psv_Strongla” /F <==== UWAGA
Task: {89230DD9-985A-4C62-B651-EDDA6851967D} - System32\Tasks\psv_San-Tom => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Quoeco.reg” & del “C:\ProgramData\AppnormanetouQ\Quoeco.reg” & SCHTASKS /Delete /TN “psv_San-Tom” /F <==== UWAGA
Task: {8BCAB2B1-AABD-4B63-84AD-E76554326884} - System32\Tasks\psv_DonRandax => /c regedit.exe /s “C:\ProgramData\Quotenamron\Konklex.reg” & del “C:\ProgramData\Quotenamron\Konklex.reg” & SCHTASKS /Delete /TN “psv_DonRandax” /F <==== UWAGA
Task: {8F474A46-0291-482F-8E16-C2EE2A31C969} - System32\Tasks\psv_Holdin => /c regedit.exe /s “C:\ProgramData\Quotenamron\Domfix.reg” & del “C:\ProgramData\Quotenamron\Domfix.reg” & SCHTASKS /Delete /TN “psv_Holdin” /F <==== UWAGA
Task: {90C2A9D1-5AB8-4BD6-A1F3-46B10F12D2E8} - System32\Tasks\psv_Quotetouch => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Biolottone.reg” & del “C:\ProgramData\AppnormanetouQ\Biolottone.reg” & SCHTASKS /Delete /TN “psv_Quotetouch” /F <==== UWAGA
Task: {92C5455E-F5BE-482C-A17C-85394F029A77} - System32\Tasks\psv_Ozerron => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Round-Tech.reg” & del “C:\ProgramData\AppnormanetouQ\Round-Tech.reg” & SCHTASKS /Delete /TN “psv_Ozerron” /F <==== UWAGA
Task: {A480E6FE-4297-4555-983E-8FE1F4B27532} - System32\Tasks\psv_Joytouch => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Dentoeco.reg” & del “C:\ProgramData\AppnormanetouQ\Dentoeco.reg” & SCHTASKS /Delete /TN “psv_Joytouch” /F <==== UWAGA
Task: {B4C7CEE4-6414-4DE0-8CB1-7FE59FF7D9D7} - System32\Tasks\psv_Y-Nix => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Techhold.reg” & del “C:\ProgramData\AppnormanetouQ\Techhold.reg” & SCHTASKS /Delete /TN “psv_Y-Nix” /F <==== UWAGA
Task: {BB93D3AB-F7ED-4759-92B8-EFD80E07E6AA} - System32\Tasks\psv_Hotron => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Solair.reg” & del “C:\ProgramData\AppnormanetouQ\Solair.reg” & SCHTASKS /Delete /TN “psv_Hotron” /F <==== UWAGA
Task: {BFD8C861-120D-40B4-81F4-F0CE8A0E8C20} - System32\Tasks\psv_MathLux => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Silsiling.reg” & del “C:\ProgramData\AppnormanetouQ\Silsiling.reg” & SCHTASKS /Delete /TN “psv_MathLux” /F <==== UWAGA
Task: {C3A902C1-0D00-46AD-B5C0-3F06D68DA191} - System32\Tasks\psv_Cofdox => /c regedit.exe /s “C:\ProgramData\Quotenamron\ZunOzecore.reg” & del “C:\ProgramData\Quotenamron\ZunOzecore.reg” & SCHTASKS /Delete /TN “psv_Cofdox” /F <==== UWAGA
Task: {D0E645B4-7251-474E-8262-48C0D6F7B759} - System32\Tasks\psv_Sub-Tex => /c regedit.exe /s “C:\ProgramData\Quotenamron\Suntam.reg” & del “C:\ProgramData\Quotenamron\Suntam.reg” & SCHTASKS /Delete /TN “psv_Sub-Tex” /F <==== UWAGA
Task: {D37A5F1B-4081-4D0B-ADCA-6489C8628EBE} - System32\Tasks\psv_Geo-Com => /c regedit.exe /s “C:\ProgramData\Quotenamron\SaoSolstrong.reg” & del “C:\ProgramData\Quotenamron\SaoSolstrong.reg” & SCHTASKS /Delete /TN “psv_Geo-Com” /F <==== UWAGA
Task: {DC55E3F0-8188-4349-BE6C-3DED72066C8C} - System32\Tasks\psv_Nimlam => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Istax.reg” & del “C:\ProgramData\AppnormanetouQ\Istax.reg” & SCHTASKS /Delete /TN “psv_Nimlam” /F <==== UWAGA
Task: {EB9BE2ED-1AEB-4722-A289-25C9AEAE6AFF} - System32\Tasks\psv_SumRemtom => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Kantip.reg” & del “C:\ProgramData\AppnormanetouQ\Kantip.reg” & SCHTASKS /Delete /TN “psv_SumRemtom” /F <==== UWAGA
Task: {EBBD7876-E077-4C80-9F4E-24860C8EB786} - System32\Tasks\psv_Geocof => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\Medsing.reg” & del “C:\ProgramData\AppnormanetouQ\Medsing.reg” & SCHTASKS /Delete /TN “psv_Geocof” /F <==== UWAGA
Task: {F55AD505-7886-4F7C-BFAF-05D03B0678C6} - System32\Tasks\psv_Uniair => /c regedit.exe /s “C:\ProgramData\AppnormanetouQ\OntoLux.reg” & del “C:\ProgramData\AppnormanetouQ\OntoLux.reg” & SCHTASKS /Delete /TN “psv_Uniair” /F <==== UWAGA
ShortcutWithArgument: C:\Users\Home Premium\Desktop\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
ShortcutWithArgument: C:\Users\Home Premium\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
HKLM…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKU\S-1-5-21-1697358837-294415581-2140137246-1000…\Run: [diediih] => C:\Users\Home Premium\diediih.exe [57344 2016-08-25] ()
HKU\S-1-5-21-1697358837-294415581-2140137246-1000…\MountPoints2: G - G:\LaunchU3.exe -a
HKU\S-1-5-21-1697358837-294415581-2140137246-1000…\MountPoints2: {522623c0-6449-11e6-b2bd-485ab6cb772a} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1697358837-294415581-2140137246-1000…\MountPoints2: {eb287e8e-fc9e-11e5-881c-485ab6cb772a} - E:\autorun.exe
AppInit_DLLs: C:\ProgramData\AppnormanetouQ\HoldDonsing.dll => C:\ProgramData\AppnormanetouQ\HoldDonsing.dll [248320 2016-08-31] ()
HKU\S-1-5-21-1697358837-294415581-2140137246-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPdTgOhLERq_2kIbkAWulE-wn6xrSMtAjOAlvEgR_iJH9cjtl3sWjiSXEIsuoOuN5BeKoFeAxqcfVYO08wLfgU1wuCokUluCyrhYl10aR1NUOkLqIGhje5y3GRHWCo6iDQHxNT6trQkxkbG_0Gil43-yhrOScOk&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM -> ielnksrch URL = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPdTgOhLERq_2kIbkAWulE-wn6xrSMtAjOAlvEgR_iJH9cjtl3sWjiSXEIsuoOuN5BeKoFeAxqcfVYO08wLfgU1wuCokUluCyrhYl10aR1NUOkLqIGhje5y3GRHWCo6iDQHxNT6trQkxkbG_0Gil43-yhrOScOk&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1697358837-294415581-2140137246-1000 -> ielnksrch URL =
SearchScopes: HKU\S-1-5-21-1697358837-294415581-2140137246-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HomePage: Default -> hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPdTgOhLERq_2kIbkAWulE-wn6xrSMtAjOAlvEgR_iJH9cjtl3sWjiSXEIsuoOuN5BeMUrakJr-ZG9WvcHzGfzKr4I6kB7yWy09e7bxyBJmVZvZ-BfUuzvzzJWIDcFL3JcQktj3aC74zciBgF5JdhtYU2bN281h
CHR DefaultSearchURL: Default -> hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT3GOWsi_8CTz4dPdTgOhLERq_2kIbkAWulE-wn6xrSMtAjOAlvEgR_iJH9cjtl3sWjiSXEIsuoOuN5BePcVL28XDB8ljky8jh02cZStQKNySJPBWkzIdeURZ-HV-PwJoF6x_m4Gwszi7L-RJrdVXsXL6HTU7MMUJ0ydGvYzPYri9&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
CHR HKLM…\Chrome\Extension: [jidkebcigjgheaahopdnlfaohgnocfai] - hxxps://clients2.google.com/service/update2/crx
S2 AppnormanetouQ; C:\ProgramData\AppnormanetouQ\AppnormanetouQ.exe [400384 2016-08-31] () [Brak podpisu cyfrowego]
S3 AmUStor; system32\drivers\AmUStor.SYS [X]
S3 DSODEV; System32\Drivers\Hantek1008X86.SYS [X]
2017-02-04 11:14 - 2016-08-31 12:41 - 00000000 ____D C:\ProgramData\AppnormanetouQ
2016-04-12 12:33 - 2016-04-12 12:33 - 6504960 _____ () C:\Users\Home Premium\AppData\Roaming\agent.dat
2016-04-12 12:33 - 2016-04-12 12:33 - 0065232 _____ () C:\Users\Home Premium\AppData\Roaming\Config.xml
2016-04-12 12:32 - 2016-04-12 12:32 - 0274508 _____ () C:\Users\Home Premium\AppData\Roaming\inst.lat
2016-04-12 12:32 - 2016-04-12 12:32 - 0014208 _____ () C:\Users\Home Premium\AppData\Roaming\InstallationConfiguration.xml
2016-04-12 12:32 - 2016-04-12 12:32 - 0127488 _____ () C:\Users\Home Premium\AppData\Roaming\Installer.dat
2016-04-12 12:33 - 2016-04-12 12:33 - 0018432 _____ () C:\Users\Home Premium\AppData\Roaming\Main.dat
2016-04-12 12:33 - 2016-04-12 12:33 - 0005568 _____ () C:\Users\Home Premium\AppData\Roaming\md.xml
2016-04-12 12:33 - 2016-04-12 12:33 - 0126464 _____ () C:\Users\Home Premium\AppData\Roaming\noah.dat
2016-04-12 12:34 - 2016-04-12 12:34 - 0032038 _____ () C:\Users\Home Premium\AppData\Roaming\uninstall_temp.ico
2016-04-12 12:33 - 2016-04-12 12:33 - 1932216 _____ () C:\Users\Home Premium\AppData\Roaming\Unophase.bin
2016-04-12 12:33 - 2016-04-12 12:32 - 1211904 _____ () C:\Users\Home Premium\AppData\Roaming\Zathlab.exe
2016-04-12 12:33 - 2016-04-12 12:33 - 1626339 _____ () C:\Users\Home Premium\AppData\Roaming\Zathlab.tst
C:\Users\Home Premium\diediih.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Uruchom jako administrator FRST i kliknij w Fix/Napraw.
Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść).