![]() |
| |||||||
Log-Analyse und Auswertung: Google etc. Suchbox im Firefox-Browser verschwundenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #10 | |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Google etc. Suchbox im Firefox-Browser verschwunden Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\Setup_wm.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows NT\Accessories\wordpad.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmplayer.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpsideshowgadget.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Sidebar <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: c:\program files\quicktime\quicktimeplayer.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpnetwk.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\WORDICON.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: c:\program files\common files\adobe\cepservicemanager4\cepservicemanager.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmprph.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\PPTICO.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpconfig.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpnscfg.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Adobe Media Player\Adobe Media Player.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\OIS.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\MSPUB.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmlaunch.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: c:\program files\adobe\adobe creative cloud\acc\/../coresync/coresync.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpnscfg.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Defender <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\WMPDMC.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\excelcnv.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: c:\program files\secunia\psi\psi_tray.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Internet Explorer <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Avira\AntiVir Desktop\avgnt.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpshare.exe <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Microsoft Office\Office14\XLICONS.EXE <====== ATTENTION
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Group Policy restriction on software: C:\Program Files\Windows Media Player\wmpenc.exe <====== ATTENTION
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000\...\Run: [Spotify Web Helper] => C:\Users\Imperator\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-06-10] (Spotify Ltd)
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000\...\Run: [WinPatrol] => C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [441408 2013-09-24] (BillP Studios)
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\Imperator\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-06-10] (Spotify Ltd)
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WinPatrol] => C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [441408 2013-09-24] (BillP Studios)
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2634268287-1079703000-1957501563-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2634268287-1079703000-1957501563-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2634268287-1079703000-1957501563-1003-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2634268287-1079703000-1957501563-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
GroupPolicyUsers\S-1-5-21-2634268287-1079703000-1957501563-1004\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-2634268287-1079703000-1957501563-1003\User: Group Policy restriction detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Emptytemp:
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
frisches FRST log bitte. Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| Themen zu Google etc. Suchbox im Firefox-Browser verschwunden |
| adobe, adware, antivir, antivirus, avira, chromium, cpu, defender, dvdvideosoft ltd., email, fehlermeldung, flash player, google, hijack, hijackthis, homepage, install.exe, installation, linkury, mozilla, photoshop, refresh, registry, scan, security, services.exe, svchost.exe, system, viren, windows |