Code:
Alles auswählen Aufklappen ATTFilter
All processes killed
========== OTL ==========
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
Prefs.js: ffxtlbr@Facemoods.com:1.2.1 removed from extensions.enabledItems
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\defaults\preferences folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\defaults folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\content\preferences folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\content\images folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\content folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\components folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com\chrome folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\mozilla\Firefox\Profiles\dkk0kp2n.default\extensions\ffxtlbr@Facemoods.com folder moved successfully.
C:\Users\Schatzipu\AppData\Roaming\Mozilla\Firefox\Profiles\dkk0kp2n.default\searchplugins\askcom.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
C:\Programme\ConduitEngine\prxConduitEngine.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64182481-4F71-486b-A045-B233BD0DA8FC}\ deleted successfully.
C:\Programme\facemoods.com\facemoods\1.4.17.6\bh\facemoods.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e111a5c-3d11-4f56-9463-5310c3c69025}\ deleted successfully.
C:\Programme\Freeware.de\prxtbFree.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
File C:\Program Files\ConduitEngine\prxConduitEngine.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93}\ not found.
C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7E111A5C-3D11-4F56-9463-5310C3C69025} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E111A5C-3D11-4F56-9463-5310C3C69025}\ not found.
File C:\Programme\Freeware.de\prxtbFree.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface deleted successfully.
C:\Users\Schatzipu\AppData\Local\Akamai\netsession_win.exe moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
C:\Users\Schatzipu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56700 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Gast
->Temp folder emptied: 224795 bytes
->Temporary Internet Files folder emptied: 4733360 bytes
->Flash cache emptied: 56700 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Schatzipu
->Temp folder emptied: 2146785 bytes
->Temporary Internet Files folder emptied: 13249397 bytes
->Java cache emptied: 18173137 bytes
->Flash cache emptied: 3186801 bytes
User: Thomas
->Temp folder emptied: 0 bytes
User: virus
->Temp folder emptied: 31832 bytes
->Temporary Internet Files folder emptied: 59455 bytes
->Flash cache emptied: 56700 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 5694 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1921367 bytes
RecycleBin emptied: 264386 bytes
Total Files Cleaned = 42,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.31.0 log created on 01082012_015827
Files\Folders moved on Reboot...
File\Folder C:\Windows\temp\TMP00000085B65C30CB6846347C not found!
Registry entries deleted on Reboot...
Grüße,
Olivia