:hallo Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin). - Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
- Starte die OTL.exe.
Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen". - Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
Code:
:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes\{2BCC7F73-BB42-4F9C-9B08-E8D25066C6EF}: "URL" = http://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes\{434D310E-6F75-4BD7-9101-FBCA908C35E4}: "URL" = http://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..browser.search.selectedEngine: "Google "
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.de/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
[2010.06.02 17:28:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Extensions
[2012.07.05 09:01:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions
[2010.10.15 00:03:57 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2012.04.20 10:35:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions\nostmp
[2012.06.29 09:05:29 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions\toolbar@ask.com
[2012.05.11 22:46:27 | 000,002,090 | ---- | M] () -- C:\Users\Gudrun\AppData\Roaming\Mozilla\Firefox\Profiles\tgaz0p5z.default\searchplugins\google-.xml
[2012.06.21 14:31:24 | 000,697,058 | ---- | M] () (No name found) -- C:\USERS\GUDRUN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TGAZ0P5Z.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
[2012.05.11 22:42:08 | 000,025,781 | ---- | M] () (No name found) -- C:\USERS\GUDRUN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TGAZ0P5Z.DEFAULT\EXTENSIONS\ADD-TO-SEARCHBOX@MALTEKRAUS.DE.XPI
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001..\Run: [EPSON18F07E (Epson Stylus SX420W)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE /FU "C:\Users\Gudrun\AppData\Local\Temp\E_SB21B.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet File not found
O4 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001..\Run: [TapiMigPlugin] C:\Users\Gudrun\AppData\Local\Microsoft\Windows\3664\TapiMigPlugin.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
[2012.07.17 21:06:59 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Ixil
[2012.07.17 21:06:59 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Baze
[2012.07.16 19:25:05 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Ekizec
[2012.07.16 19:25:05 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Ampe
[2012.07.10 11:42:25 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Yahoo!
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[2012.07.17 21:40:06 | 000,000,788 | ---- | C] () -- C:\Users\Gudrun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk
[2012.07.17 11:59:11 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Ampe
[2012.07.18 01:01:05 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Baze
[2012.04.11 14:38:33 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Downloaded Installations
[2012.07.16 19:25:35 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Ekizec
[2012.07.20 14:42:04 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\hellomoto
[2012.07.20 15:17:14 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Ixil
[2010.10.11 02:50:48 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\WildTangent
[2012.07.20 19:00:13 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Local\NPE
[2012.07.20 18:27:10 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.20 17:58:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.20 17:54:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.17 21:40:06 | 000,000,758 | ---- | M] () -- C:\Users\Gudrun\Desktop\Poker at bet365.lnk
[2012.07.17 21:40:06 | 000,000,788 | ---- | C] () -- C:\Users\Gudrun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk
[2012.07.17 21:40:06 | 000,000,758 | ---- | C] () -- C:\Users\Gudrun\Desktop\Poker at bet365.lnk
[2012.07.10 11:40:19 | 000,001,144 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash] - Schließe alle Programme.
- Klicke auf den Fix Button.
- Wenn OTL einen Neustart verlangt, bitte zulassen.
- Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\ Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |