Search Protect - jak usunąć?


(Taurus4) #1

Hey!

 

Mam problem z Search Protect, którego nie widzę w Panelu Sterowania -> Programy, a który potrzebuję usunąć  bo spowolnił mi lapka i jest uciążliwy ze względu na zmiany w wyszukiwarce.

Tu mam raport FRST:

http://wklej.org/id/1633779/

a tutaj Addition:

http://wklej.org/id/1633782/

Proszę o radę bo jestem zielony w tym temacie. Dziękuję.


(apanasiuk) #2

AdwClener pobierz i wyczyść nim system


(Acorus) #3

Otwórz notatnik systemowy i wklej:

HKLM-x32\...\Run: [SDTray] = C:\Program Files (x86)\Spybot - Search Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\...\MountPoints2: {6f2d08e3-b1c7-11e4-a353-002219da9127} - G:\AutoRun.exe
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\...\MountPoints2: {6f2d08fe-b1c7-11e4-a353-002219da9127} - G:\AutoRun.exe
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\...\MountPoints2: {c480bd2c-b218-11e4-95a6-002219da9127} - G:\AutoRun.exe
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\...\MountPoints2: {c480bd3e-b218-11e4-95a6-002219da9127} - G:\AutoRun.exe
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\...\MountPoints2: {c480bd7e-b218-11e4-95a6-001e101f7fb6} - G:\AutoRun.exe
BootExecute: autocheck autochk * sdnclean64.exe
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsts=1423758028from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsts=1423758028from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsts=1423758028from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsts=1423758028from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.key-find.com/web/?type=dsppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
HKU\S-1-5-21-2630530236-1429551317-529928622-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.key-find.com/web/?type=dsppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
SearchScopes: HKU\S-1-5-21-2630530236-1429551317-529928622-1000 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
SearchScopes: HKU\S-1-5-21-2630530236-1429551317-529928622-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXts=1423758292type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2630530236-1429551317-529928622-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXts=1423758292type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2630530236-1429551317-529928622-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.key-find.com/web/?type=dsppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXq={searchTerms}
SearchScopes: HKU\S-1-5-21-2630530236-1429551317-529928622-1000 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXts=1423758292type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2630530236-1429551317-529928622-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.key-find.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAXts=1423758292type=defaultq={searchTerms}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll (Thinknice Co. Limited)
BHO-x32: PriceFountain - {b608cc98-54de-4775-96c9-097de398500c} - C:\Users\KIMB\AppData\Local\PriceFountain\PriceFountainIE.dll No File
FF DefaultSearchEngine: key-find
FF SelectedSearchEngine: key-find
FF Homepage: hxxp://www.key-find.com/?type=hpppts=1423758100from=coruid=HitachiXHTS543225L9A300_081201FB2E00LKD2V2DAX
FF Extension: FF Toolbar - C:\Users\KIMB\AppData\Roaming\Mozilla\Firefox\Profiles\fl4kr5so.default\Extensions\fftoolbar2014@etech.com [2015-02-12]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [Not Found]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [487056 2015-02-12] (SysTool PasSame LIMITED)
S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
2015-02-12 22:52 - 2015-02-12 22:52 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-SD Start Center.lnk
2015-02-12 22:52 - 2015-02-12 22:52 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-SD Start Center.lnk
2015-02-12 22:52 - 2015-02-12 22:52 - 00000000 ____ D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search Destroy 2
2015-02-12 22:52 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-02-12 22:48 - 2015-02-09 17:05 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\KIMB\Desktop\spybot-2.4.exe
2015-02-12 19:36 - 2015-02-12 19:40 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\KIMB\Downloads\sh-remover.exe
2015-02-12 17:26 - 2015-02-12 17:26 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-12 17:24 - 2015-02-12 17:26 - 00000000 ____ D () C:\Program Files (x86)\XTab
2015-02-12 17:21 - 2015-02-12 17:21 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-02-12 17:20 - 2015-02-12 19:49 - 00000000 ____ D () C:\Users\KIMB\AppData\Roaming\key-find
2015-02-12 17:04 - 2015-02-12 17:04 - 00000000 ____ D () C:\Windows\System32\Tasks\Safer-Networking
2015-02-09 14:28 - 2015-02-12 23:03 - 00000000 ____ D () C:\Program Files (x86)\Spybot - Search Destroy 2
2015-02-09 14:28 - 2015-02-12 22:52 - 00000000 ____ D () C:\ProgramData\Spybot - Search Destroy
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Taurus4) #4

Zrobiłem co miałem zrobić, ale kilka razy na wszelki wypadek dokonałem skanowania programem AdwCleaner i ciągle wyskakuje mi następujący komunikat: