Firefox - jak usunąć stronę startową netmahal.com?


(Klaudiarudzka1) #1

Witam, od jakiegoś czasu strona głowna mojej przeglądarki Firefox to - netmahal.com

Jak mogę to usunąć?

 

(Nie wiem czy dobry dział, jak coś proszę o przeniesienie.)


(Acorus) #2

Pobierz Farbar Recovery Scan Tool http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ zgodny z wersją systemu 32-bit lub 64-bit.


(Klaudiarudzka1) #3

http://wklej.org/id/1678049/

 

http://wklej.org/id/1678050/


(dereza) #4

Miałem ten sam problem,wejdź w menu firefox, kliknij na pomoc ,czyli pytajnik(?)następnie kliknij w Informacje dla pomocy technicznej i po prawej będziesz mieć tabelkę z odśwież program firefox(może być też restes firefoxa,u mnie było odświeżenie),po tej operacji zniknie ci ta uciążliwa strona

Zobacz też w dodatkach,czy masz jak masz to usuń tak samo z dodaj lub usuń programy w panelu sterowania


(Acorus) #5

Otwórz notatnik systemowy i wklej:

Task: {13D4A83C-58A8-4C60-84FA-3B79CB07A123} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-1 = C:\Program Files\Plus-HD-9.1\Plus-HD-9.1-codedownloader.exe ==== ATTENTION
Task: {19C50CB2-E441-41C0-BDE6-D47CDA9A59F5} - System32\Tasks\pricemeterdownloader = C:\Users\Klauduś\AppData\Local\PriceMeter\pricemeterd.exe ==== ATTENTION
Task: {30DD133B-6D88-40CA-9DA9-55A3CC1EEEA7} - \APSnotifierPP2 No Task File ==== ATTENTION
Task: {33F6ACFD-62B6-4125-9504-D68F68652C92} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-7 = C:\Program Files\Plus-HD-9.1\Plus-HD-9.1-nova.exe ==== ATTENTION
Task: {382E0A36-1EA0-4A45-8E97-CF413602404C} - \APSnotifierPP3 No Task File ==== ATTENTION
Task: {4E282ED8-C25F-4D3E-8222-709FDEC785EF} - System32\Tasks\Price Fountain = C:\Users\KLAUDU~1\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE ==== ATTENTION
Task: {566A29FF-87E2-4AE6-A5CB-CD13A3921F5E} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-4 = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-4.exe ==== ATTENTION
Task: {7784F309-07F2-4E53-942F-C0D780B20D54} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-5 = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-5.exe ==== ATTENTION
Task: {A8FACEFB-CD12-49C6-9C16-0D6760DA2620} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-2 = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-2.exe ==== ATTENTION
Task: {CAC50143-3197-4839-AF94-8D308ED3EB2E} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-3 = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-3.exe ==== ATTENTION
Task: {D6D90364-E9ED-4E4F-AABB-39CAAD5F48FE} - \APSnotifierPP1 No Task File ==== ATTENTION
Task: {E1A90440-2EDB-4D02-BAA4-9038F194DB44} - \BlockAndSurf Update No Task File ==== ATTENTION
Task: {F2432C5E-EDAD-44BA-BA3F-EFFC4D46BC29} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-11 = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-11.exe ==== ATTENTION
Task: {F8A2ADC9-F4AF-4D6B-BA82-89FFB054F23C} - System32\Tasks\SaveSense = C:\Users\KLAUDU~1\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE ==== ATTENTION
Task: {FA651B30-893E-489C-BD61-DF2F312D1EC0} - System32\Tasks\76be98a2-caba-4502-a815-a52409c417de-6 = C:\Program Files\Plus-HD-9.1\Plus-HD-9.1-novainstaller.exe ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-1.job = C:\Program Files\Plus-HD-9.1\Plus-HD-9.1-codedownloader.exe5/EhDtX /lsWNHJfv=task /BxSDWnLe='Plus-HD-9.1' /LqAWIoT=52916 /oWiqlmZV='001257' /uokac='0' /tngQGBsRr='0' /rTzNWfVE=4D1E2517CE4B40109561DA11EC9D9DFAIE /WSMuw=48511b1bf82b6329b11b3dd0e7a45999 /tNHToLnF=1_34_06_10 /QXTPexWA=1.34.6.10 /CdVjuwYo=1402941488 /EqvuSdV=http:/stats.datagenserv.com /rAoJpQ=http:/errors.datagenserv.com /VgjVj=http:/js.datagenserv.com /OeDgJWOPy=ch /URQrKZ=http:/js.clientdemocloud.com /RVZymz /vlNeNn='{asw:[4, 1, 0]}' /OCzOzLS='http:/update.datagenserv.com/ie_code_agent_updates/{CAMP_ID}/update.jso ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-11.job = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-11.exe ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-2.job = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-2.exeë/MnxpkMhr /BxSDWnLe='Plus-HD-9.1' /LqAWIoT=52916 /oWiqlmZV='001257' /uokac='0' /tngQGBsRr='0' /rTzNWfVE=4D1E2517CE4B40109561DA11EC9D9DFAIE /WSMuw=48511b1bf82b6329b11b3dd0e7a45999 /tNHToLnF=1_34_06_10 /CdVjuwYo=1402941488 /EqvuSdV=http:/stats.datagenserv.com /rAoJpQ=http:/errors.datagenserv.com /IbSYjvD=11111111-1111-1111-1111-110511291116 /OeDgJWOPy=ch /QUhlSmC /RVZymz /OCzOzLS='http:/update.datagenserv.com/ie_enable_agent_updates/{CAMP_ID}/update.jso ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-3.job = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-3.exe ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-4.job = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-4.exe‘/pXNVah /BxSDWnLe='Plus-HD-9.1' /queerqrZ C:\Program Files\Plus-HD-9.1\52916.xpi' /LqAWIoT=52916 /oWiqlmZV='001257' /uokac='0' /tngQGBsRr='0' /rTzNWfVE=4D1E2517CE4B40109561DA11EC9D9DFAIE /WSMuw=48511b1bf82b6329b11b3dd0e7a45999 /tNHToLnF=1_34_06_10 /QXTPexWA=1.34.6.10 /CdVjuwYo=1402941488 /EqvuSdV=http:/stats.datagenserv.com /rAoJpQ=http:/errors.datagenserv.com /POEJZ=300 /CapqCFpJL=a54e453c-130a-4769-9333-c5ec2aa914c5@9bd7cc89-9c7c-44e9-a03b-042b92d363f0.com /lLOzCN=0.94 /bgxsu=aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916 /XAqpbvAxc=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/52916.rdf /wfjMXrECM='Plus-HD-9.1' /zdUONgYHk='Turn YouTube videos to High Definition by default' /ImWYGoT='Plus HD' /OeDgJWOPy=ch /vlNeNn='{asw:[4, 1, 0]}' /RVZymz /ZMLfqPh /uzsZXC /OCzOzLS='http:/update.datagenserv.com/ff_agent_updates/{CAMP_ID}/update.jso ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-5.job = C:\Program Files\Plus-HD-9.1\76be98a2-caba-4502-a815-a52409c417de-5.exe/RuijXFx /BxSDWnLe='Plus-HD-9.1' /LqAWIoT=52916 /oWiqlmZV='001257' /uokac='0' /tngQGBsRr='0' /rTzNWfVE=4D1E2517CE4B40109561DA11EC9D9DFAIE /WSMuw=48511b1bf82b6329b11b3dd0e7a45999 /tNHToLnF=1_34_06_10 /CdVjuwYo=1402941488 /EqvuSdV=http:/stats.datagenserv.com /rAoJpQ=http:/errors.datagenserv.com /LEXAKETKs=http:/ipgeoapi.com/ /xpRfEFRL=http:/update.datagenserv.com /ZToPrcz=2 /YqIgTr=http:/logs.datagenserv.com /OCzOzLS='http:/update.datagenserv.com/updater_agent_updates/{CAMP_ID}/update.jso ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-6.job = C:\Program Files\Plus-HD-9.1\Plus-HD-9.1-novainstaller.exe/GHJZrtq /BxSDWnLe='Plus-HD-9.1' /LqAWIoT=52916 /oWiqlmZV='001257' /uokac='0' /tngQGBsRr='0' /rTzNWfVE=4D1E2517CE4B40109561DA11EC9D9DFAIE /WSMuw=48511b1bf82b6329b11b3dd0e7a45999 /tNHToLnF=1_34_06_10 /QXTPexWA=1.34.6.10 /CdVjuwYo=1402941488 /EqvuSdV=http:/stats.datagenserv.com /rAoJpQ=http:/errors.datagenserv.com /VgjVj=http:/js.datagenserv.com /OeDgJWOPy=ch /wKXssQQ /RPtnoDVv='nova' /URQrKZ=http:/js.clientdemocloud.com /vlNeNn='{asw:[4, 1, 0]}' /lsWNHJfv=task /OCzOzLS='http:/update.datagenserv.com/novacode/{CAMP_ID}/update.jso ==== ATTENTION
Task: C:\Windows\Tasks\76be98a2-caba-4502-a815-a52409c417de-7.job = C:\Program Files\Plus-HD-9.1\Plus-HD-9.1-nova.exe#/BxSDWnLe='Plus-HD-9.1' /LqAWIoT=52916 /oWiqlmZV='001257' /uokac='0' /tngQGBsRr='0' /rTzNWfVE=4D1E2517CE4B40109561DA11EC9D9DFAIE /WSMuw=48511b1bf82b6329b11b3dd0e7a45999 /tNHToLnF=1_34_06_10 /QXTPexWA=1.34.6.10 /CdVjuwYo=1402941488 /EqvuSdV=http:/stats.datagenserv.com /rAoJpQ=http:/errors.datagenserv.com /VgjVj=http:/js.datagenserv.com /OeDgJWOPy=ch /wKXssQQ /RPtnoDVv='nova' /URQrKZ=http:/js.clientdemocloud.com /vlNeNn='{asw:[4, 1, 0]}' /OCzOzLS='http:/update.datagenserv.com/novarun/{CAMP_ID}/update.jso ==== ATTENTION
Task: C:\Windows\Tasks\CmB5aFNwrEUf.job = C:\Users\Klauduý˙\AppData\Roaming\CmB5aFNwrEUf.exe
Task: C:\Windows\Tasks\Price Fountain.job = C:\Users\KLAUDU~1\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE ==== ATTENTION
Task: C:\Windows\Tasks\SaveSense.job = C:\Users\KLAUDU~1\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE ==== ATTENTION
HKLM\...\Run: [AirCardEnabler] = [X]
HKLM\...\Run: [fst_pl_130] = [X]
HKLM\...\Run: [fst_pl_129] = [X]
ShellIconOverlayIdentifiers: [00avast] - {472083B0-C522-11CF-8763-00608CC02F24} = No File
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.netmahal.com/?bd=dsoem=ntsvcuid=SAMSUNGXHM321HI_S24PJ1KZ400213version=2.0.0.1288pid=414031160cs=383d3c3d1600c83c3c87dd6a2ca2881dq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.netmahal.com/?bd=dsoem=ntsvcuid=SAMSUNGXHM321HI_S24PJ1KZ400213version=2.0.0.1288pid=414031160cs=383d3c3d1600c83c3c87dd6a2ca2881dq={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492aid=199itype=aver=13337tm=376src=dsp={searchTerms}
SearchScopes: HKLM - {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://search.netmahal.com/?bd=dsoem=ntsvcuid=SAMSUNGXHM321HI_S24PJ1KZ400213version=2.0.0.1288pid=414031160cs=383d3c3d1600c83c3c87dd6a2ca2881dq={searchTerms}
SearchScopes: HKU\.DEFAULT - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492aid=199itype=aver=12791tm=376src=dsp={searchTerms}
SearchScopes: HKU\S-1-5-21-375576244-3175298552-77264437-1000 - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}form=MSSEDFpc=MSSE
SearchScopes: HKU\S-1-5-21-375576244-3175298552-77264437-1000 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492aid=199itype=aver=13337tm=376src=dsp={searchTerms}
SearchScopes: HKU\S-1-5-21-375576244-3175298552-77264437-1000 - {E921F400-D383-4B1B-9DE6-FCFCACFC1173} URL = http://search.netmahal.com/?bd=dsoem=ntsvcuid=SAMSUNGXHM321HI_S24PJ1KZ400213version=2.0.0.1288pid=414031160cs=383d3c3d1600c83c3c87dd6a2ca2881dq={searchTerms}
Hosts:
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\default-search.xml [2014-07-11]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\netmahal.xml [2014-12-25]
CHR HomePage: Default - hxxp://isearch.omiga-plus.com/?type=hpts=1418321514from=coruid=SAMSUNGXHM321HI_S24PJ1KZ400213
CHR StartupUrls: Default - "hxxp://isearch.omiga-plus.com/?type=hpts=1418321514from=coruid=SAMSUNGXHM321HI_S24PJ1KZ400213"
CHR DefaultSearchKeyword: Default - omiga-plus
CHR DefaultSearchURL: Default - http://isearch.omiga-plus.com/web/?type=dsts=1418321514from=coruid=SAMSUNGXHM321HI_S24PJ1KZ400213q={searchTerms}
CHR HKLM\...\Chrome\Extension: [fjbbjfdilbioabojmcplalojlmdngbjl] - C:\Users\Klauduś\AppData\Local\Temp\swlfiles\smileyswelovetoolbar.crx [Not Found]
S3 EagleXNt; \\C:\Windows\system32\drivers\EagleXNt.sys [X]
S1 iSafeKrnlMon; \\C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [X]
S3 JMCR; system32\DRIVERS\jmcr.sys [X]
S3 SWUMX20; system32\DRIVERS\swumx20.sys [X]
2015-04-01 20:14 - 2015-04-02 16:03 - 00000000 ____ D () C:\Program Files\disco games
2015-03-31 10:14 - 2015-03-31 10:14 - 0004387 _____ () C:\Users\Klauduś\AppData\Roaming\CmB5aFNwrEUf
2015-04-03 15:49 - 2015-04-03 15:49 - 1224704 _____ () C:\Users\Klauduś\AppData\Roaming\CmB5aFNwrEUf.exe
2014-06-16 21:13 - 2014-06-16 21:13 - 0623600 _____ (Click Me In Limited) C:\Users\Klauduś\AppData\Local\nsmAEEC.tmp
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Klaudiarudzka1) #6

Dziękuje Acorus, pomogło :slight_smile:


(Acorus) #7

Skasuj folder C:\FRST