Search Protect w tray'u, brak możliwości odinstalowania

Szukałam w panelu sterowania w Dodaj - usuń programy, w Revo Uninstaller , w Programie Files i nigdzie takiego czegoś nie ma poza tą ikoną w tray’u.  Jak to usunąć? Ponadto, że nigdzie po tym nie ma śladu to również Adw cleaner nie pomógł

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.

Uruchom FRST i kliknij Scan. Pokaż raport FRST i Addition.

Raporty umieść na http://wklej.org/ i podaj link.

dzięki za zainteresowanie

http://wklej.org/id/1593194/

http://wklej.org/id/1593197/

Otwórz notatnik systemowy i wklej:

Task: {2EDCC94F-0377-4E6E-B839-AE1C5B1CD26C} - System32\Tasks\1214avUpdateInfo = C:\ProgramData\Avg_Update_1214av\1214av_AVG-Secure-Search-Update.exe [2014-10-26] ()
Task: {3953CE97-43CC-4877-AA7D-5A0452B80E31} - System32\Tasks\0614aUpdateInfo = C:\ProgramData\Avg_Update_0614a\0614a_AVG-Secure-Search-Update.exe [2014-06-19] ()
Task: {6EC6CD30-02BD-414F-9C09-EC01714D19C5} - \DealPlyUpdate No Task File ==== ATTENTION
Task: {7955D1C5-7EF0-4419-80E1-71115C0BE088} - System32\Tasks\1114avUpdateInfo = C:\ProgramData\Avg_Update_1114av\1114av_AVG-Secure-Search-Update.exe [2014-10-08] ()
Task: {8E8EC7CA-91F5-4770-BC61-A332DB646BA8} - System32\Tasks\{1A185EF9-59C7-460E-B08D-3CC47E927BEA} = Firefox.exe http://ui.skype.com/ui/0/4.1.0.179.369/pl/abandoninstall?source=lightinstalleramp;page=tsMainamp;installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;notincluded
Task: {B43BFAAA-3990-4FFD-A6C1-BFDE8DCFBEB0} - \globalUpdateUpdateTaskMachineCore No Task File ==== ATTENTION
Task: {B8762EF7-205B-4CE7-BF23-323B2EE7AB85} - \YourFile Update No Task File ==== ATTENTION
Task: {B9A4F9D1-5520-4DC2-B95E-0011EB8CC6E0} - \Program aktualizacji online firmy Adobe. No Task File ==== ATTENTION
Task: {C038130C-F576-4AAF-9579-D5A94BFADF69} - System32\Tasks\0814avUpdateInfo = C:\ProgramData\Avg_Update_0814av\0814av_AVG-Secure-Search-Update.exe [2014-08-12] ()
Task: {C6256862-9543-4121-84F2-E382F2829512} - System32\Tasks\0414bUpdateInfo = C:\ProgramData\Avg_Update_0414b\0414b_AVG-Secure-Search-Update.exe [2014-04-09] ()
Task: {DFBB1E8E-F00D-45D5-A1E5-38098D2DDAE1} - \globalUpdateUpdateTaskMachineUA No Task File ==== ATTENTION
HKU\S-1-5-21-4030510647-363475-2765870537-1000\...\RunOnce: [Adobe Speed Launcher] = !I
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
Toolbar: HKU\.DEFAULT - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
FF SelectedSearchEngine: omiga-plus
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\omiga-plus.xml
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\di\AppData\Roaming\Mozilla\Firefox\Profiles\vioj3tvj.default\extensions\fftoolbar2014@etech.com
CHR Extension: (No Name) - C:\Users\di\AppData\Local\Google\Chrome\User Data\Default\Extensions\cckahkoimnbpflhhobnanhfdihegpedf [2014-06-14]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158864 2014-12-29] (XTab system)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2015-01-10] (Fuyu LIMITED) [File not signed]
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [39768 2013-02-19] (AVG Technologies)
S3 massfilter_lte; \\C:\Windows\system32\drivers\massfilter_lte.sys [X]
S3 zgdcat; system32\DRIVERS\zgdcat.sys [X]
S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [X]
S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [X]
S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [X]
S3 zgdcnmea; system32\DRIVERS\zgdcnmea.sys [X]
2015-01-10 22:28 - 2015-01-10 22:28 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-01-10 22:27 - 2015-01-10 22:28 - 00000000 ____ D () C:\Program Files (x86)\XTab
2015-01-10 22:26 - 2015-01-11 17:22 - 00000000 ____ D () C:\Users\di\AppData\Roaming\omiga-plus
2015-01-10 22:26 - 2015-01-10 22:26 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-01-12 18:04 - 2013-11-22 20:06 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

A może zechcesz nauczyć mnie takich sztuczek? :wink:

 

Bardzo dziękuję za pomoc!

Trudno by było.Skasuj folder C:\FRST

Skasowałam, zauważyłam w innym temacie

http://wklej.org/id/1647072/

http://wklej.org/id/1647073/

 

Zerknie ktoś? bo znów mi się ten search protect pojawił w tray’u

Odinstaluj Remote Desktop Access (VuuPC),Update Service YourFileDownloader.Otwórz notatnik systemowy i wklej:

Task: {82EBD479-A09E-467B-B5C8-FDF773541524} - System32\Tasks\Update Service YourFileDownloader = C:\Program Files (x86)\YourFileDownloaderUpdater\YourFileDownloaderUpdater.exe ==== ATTENTION
Task: {9DC7D937-09C6-4C29-B43C-45DB81C1C073} - System32\Tasks\SmartWeb Upgrade Trigger Task = C:\Users\di\AppData\Local\SmartWeb\SmartWebHelper.exe ==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hpts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hpts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=dsts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=dsts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hpts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hpts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=dsts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=dsts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639q={searchTerms}
HKU\S-1-5-21-4030510647-363475-2765870537-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hpts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
HKU\S-1-5-21-4030510647-363475-2765870537-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hpts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
HKU\S-1-5-21-4030510647-363475-2765870537-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=dsts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639q={searchTerms}
HKU\S-1-5-21-4030510647-363475-2765870537-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=dsts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639q={searchTerms}
SearchScopes: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://istart.webssearches.com/web/?utm_source=butm_medium=exputm_campaign=install_ieutm_content=dsfrom=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639ts=1424878354type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://istart.webssearches.com/web/?utm_source=butm_medium=exputm_campaign=install_ieutm_content=dsfrom=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639ts=1424878354type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://istart.webssearches.com/web/?utm_source=butm_medium=exputm_campaign=install_ieutm_content=dsfrom=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639ts=1424878354type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?utm_source=butm_medium=exputm_campaign=install_ieutm_content=dsfrom=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639ts=1424878354type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://istart.webssearches.com/web/?utm_source=butm_medium=exputm_campaign=install_ieutm_content=dsfrom=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639ts=1424878354type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-4030510647-363475-2765870537-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://istart.webssearches.com/web/?utm_source=butm_medium=exputm_campaign=install_ieutm_content=dsfrom=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639ts=1424878354type=defaultq={searchTerms}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll (Thinknice Co. Limited)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=scts=1424878228from=expuid=WDCXWD3200BPVT-22ZEST0_WD-WXA1A800263902639
FF SelectedSearchEngine: webssearches
FF HKLM-x32\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\di\AppData\Roaming\Mozilla\Firefox\Profiles\vioj3tvj.default\extensions\searchengine@gmail.com
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\di\AppData\Roaming\Mozilla\Firefox\Profiles\vioj3tvj.default\extensions\faststartff@gmail.com
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
R2 petonuve; C:\Users\di\AppData\Roaming\E2E46440-1424881235-71D9-20D3-1C7508130B7C\jnsmD6AF.tmp [168960 2015-02-25] () [File not signed]
R2 pysucode; C:\Users\di\AppData\Local\E2E46440-1424881346-71D9-20D3-1C7508130B7C\snsx3101.tmp [179712 2015-02-25] () [File not signed]
2015-02-25 16:32 - 2015-02-25 16:32 - 00000000 ____ D () C:\ProgramData\IHProtectUpDate
2015-02-25 16:32 - 2015-02-25 16:32 - 00000000 ____ D () C:\Program Files (x86)\XTab
2015-02-25 16:31 - 2015-02-25 16:34 - 00000000 ____ D () C:\ProgramData\WindowsMangerProtect
2015-02-25 16:29 - 2015-02-25 17:41 - 00000000 ____ D () C:\Program Files (x86)\YourFileDownloaderUpdater
2015-02-25 16:29 - 2015-02-25 16:29 - 00003140 _____ () C:\Windows\System32\Tasks\Update Service YourFileDownloader
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Jesteś mistrzem :slight_smile:

Skasuj folder C:\FRST

W AdwCleaner użyj opcji Odinstaluj.