Po usunięciu search protect firefox startuje zawsze z google

Witam

Jak w temacie, zainstalowałem z rozpędu search protect instalując coś downloaderem z dobreprogramy. Po Znalazłem gdzieś instrukcję usunięcia tego softu. Po usunięciu firefox cały czas startuje z google jako stroną startową, zmiany na inne nic nie dają. Proszę o sprawdzenie logów z FARBARA.

http://www.wklej.org/id/1760769/

http://www.wklej.org/id/1760770/

 

Z góry dzięki

Otwórz notatnik systemowy i wklej:

Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - \Microsoft\Windows\Time Synchronization\SynchronizeTime No Task File ==== ATTENTION
Task: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} - \Microsoft\Windows\Tcpip\IpAddressConflict1 No Task File ==== ATTENTION
Task: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} - \Microsoft\Windows\Tcpip\IpAddressConflict2 No Task File ==== ATTENTION
Task: {2470470F-2634-478E-B181-571E98A789BB} - \Microsoft\Windows\Multimedia\SystemSoundsService No Task File ==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification No Task File ==== ATTENTION
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - \Microsoft\Windows\Shell\WindowsParentalControlsMigration No Task File ==== ATTENTION
Task: {4C8B01A2-11FF-4C41-848F-508EF4F00CF7} - \Microsoft\Windows\TextServicesFramework\MsCtfMonitor No Task File ==== ATTENTION
Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - \Microsoft\Windows\UPnP\UPnPHostConfig No Task File ==== ATTENTION
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - \Microsoft\Windows\Shell\WindowsParentalControls No Task File ==== ATTENTION
Task: {5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6} - \Microsoft\Windows\Defrag\ScheduledDefrag No Task File ==== ATTENTION
Task: {613612BA-897D-44CE-8DC1-8FC283F9FD51} - \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated) No Task File ==== ATTENTION
Task: {72DB7465-BC54-491B-A92A-4637A28C9BBF} - \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck No Task File ==== ATTENTION
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - \Microsoft\Windows\SystemRestore\SR No Task File ==== ATTENTION
Task: {9979CB83-103A-4105-9E5D-C74B0AF6D198} - \Microsoft\Windows\CertificateServicesClient\UserTask-Roam No Task File ==== ATTENTION
Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - \Microsoft\Windows Defender\MP Scheduled Scan No Task File ==== ATTENTION
Task: {A35BB7A6-5F0C-4C9F-8450-2B3BED532D51} - \Microsoft\Windows\WindowsColorSystem\Calibration Loader No Task File ==== ATTENTION
Task: {A48CABBF-24C8-4B87-B00F-9261807C3B43} - \Microsoft\Windows\AppID\PolicyConverter No Task File ==== ATTENTION
Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - \Microsoft\Windows\Location\Notifications No Task File ==== ATTENTION
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - \Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor No Task File ==== ATTENTION
Task: {C016366B-7126-46CA-B36B-592A3D95A60B} - \Microsoft\Windows\Customer Experience Improvement Program\Consolidator No Task File ==== ATTENTION
Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - \Microsoft\Windows Defender\MpIdleTask No Task File ==== ATTENTION
Task: {CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E} - \Microsoft\Windows\Registry\RegIdleBackup No Task File ==== ATTENTION
Task: {CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186} - \Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask No Task File ==== ATTENTION
Task: {D0250F3F-6480-484F-B719-42F659AC64D5} - \Microsoft\Windows\Windows Error Reporting\QueueReporting No Task File ==== ATTENTION
Task: {DA41DE71-8431-42FB-9DB0-EB64A961DEAD} - \Microsoft\Windows\Maintenance\WinSAT No Task File ==== ATTENTION
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - \Microsoft\Windows\Bluetooth\UninstallDeviceTask No Task File ==== ATTENTION
Task: {FB3C354D-297A-4EB2-9B58-090F6361906B} - \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem No Task File ==== ATTENTION
HKU\S-1-5-21-2031097496-3832952178-1084373235-1000\...\Run: [NextLive] = C:\Windows\SysWOW64\rundll32.exe ",EntryPoint -m l
HKU\S-1-5-21-2031097496-3832952178-1084373235-1000\...\Run: [] = [X]
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dsts=1435571600z=d7b5554dfeb423d7d407ff5g0z8c7w9wcq1b3g1mewfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dsts=1435571600z=d7b5554dfeb423d7d407ff5g0z8c7w9wcq1b3g1mewfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dsts=1435571600z=d7b5554dfeb423d7d407ff5g0z8c7w9wcq1b3g1mewfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXq={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dsts=1435571600z=d7b5554dfeb423d7d407ff5g0z8c7w9wcq1b3g1mewfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXq={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2031097496-3832952178-1084373235-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dsppts=1435571622z=0129ee703faa11ec258ace1gdz6c9w2w2qeb0gdtdmfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXq={searchTerms}
HKU\S-1-5-21-2031097496-3832952178-1084373235-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dsppts=1435571622z=0129ee703faa11ec258ace1gdz6c9w2w2qeb0gdtdmfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXq={searchTerms}
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2031097496-3832952178-1084373235-1000 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2031097496-3832952178-1084373235-1000 - {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsurf.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXts=1435571631type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2031097496-3832952178-1084373235-1000 - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = http://www.istartsurf.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXts=1435571631type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2031097496-3832952178-1084373235-1000 - {C6EF71D6-E3CE-4ACE-84DC-77A0A82968C1} URL = http://www.istartsurf.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXts=1435571631type=defaultq={searchTerms}
SearchScopes: HKU\S-1-5-21-2031097496-3832952178-1084373235-1000 - {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.istartsurf.com/web/?utm_source=butm_medium=corutm_campaign=install_ieutm_content=dsfrom=coruid=HitachiXHTS545050B9A300_101104PBN40317FUEA6EXts=1435571631type=defaultq={searchTerms}
BHO-x32: No Name - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - No File
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.0.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx [Not Found]
U4 JavaQuickStarterService; No ImagePath
U4 nvsvc; No ImagePath
U4 nvUpdatusService; No ImagePath
S3 X6va029; \\C:\Windows\SysWOW64\Drivers\X6va029 [X]
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Zbyt wcześnie się ucieszyłem. Jednak firefox ciągle startuje z google jako stroną startową pomimo zmian. Dodatkowe sugestie?

Sprawdź na nowym profilu.

Przeskanuj programem Malwarebytes Anti-Malware http://www.malwarebytes.org/8/

404 - Page Not Found , użyć zwykłego linku do darmowego downloadu malware?

http://downloads.malwarebytes.org/file/mbam/