:hallo   Fixen mit OTL  Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).  - Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  - Starte die OTL.exe.
  Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".  - Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
      Code:  
 :OTL 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}  
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC  
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7  
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}  
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC  
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0  
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0  
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}  
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC  
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes\{2BCC7F73-BB42-4F9C-9B08-E8D25066C6EF}: "URL" = http://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}  
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\SearchScopes\{434D310E-6F75-4BD7-9101-FBCA908C35E4}: "URL" = http://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2  
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0  
IE - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local  
FF - prefs.js..browser.search.selectedEngine: "Google "  
FF - prefs.js..browser.search.useDBForOrder: true  
FF - prefs.js..browser.startup.homepage: "http://www.google.de/"  
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3  
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21  
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22  
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906  
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23  
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24  
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found  
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found  
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)  
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)  
[2010.06.02 17:28:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Extensions  
[2012.07.05 09:01:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions  
[2010.10.15 00:03:57 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}  
[2012.04.20 10:35:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions\nostmp  
[2012.06.29 09:05:29 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Gudrun\AppData\Roaming\mozilla\Firefox\Profiles\tgaz0p5z.default\extensions\toolbar@ask.com  
[2012.05.11 22:46:27 | 000,002,090 | ---- | M] () -- C:\Users\Gudrun\AppData\Roaming\Mozilla\Firefox\Profiles\tgaz0p5z.default\searchplugins\google-.xml  
[2012.06.21 14:31:24 | 000,697,058 | ---- | M] () (No name found) -- C:\USERS\GUDRUN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TGAZ0P5Z.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI  
[2012.05.11 22:42:08 | 000,025,781 | ---- | M] () (No name found) -- C:\USERS\GUDRUN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TGAZ0P5Z.DEFAULT\EXTENSIONS\ADD-TO-SEARCHBOX@MALTEKRAUS.DE.XPI  
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found  
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)  
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)  
O3 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)  
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)  
O4 - HKLM..\Run: [] File not found  
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)  
O4 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001..\Run: [EPSON18F07E (Epson Stylus SX420W)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE /FU "C:\Users\Gudrun\AppData\Local\Temp\E_SB21B.tmp" /EF "HKCU" File not found  
O4 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet File not found  
O4 - HKU\S-1-5-21-251040059-1165384694-2605183348-1001..\Run: [TapiMigPlugin] C:\Users\Gudrun\AppData\Local\Microsoft\Windows\3664\TapiMigPlugin.exe ()  
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found  
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found  
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1  
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1  
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5  
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3  
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found  
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found  
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found  
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found  
O32 - HKLM CDRom: AutoRun - 1    
[2012.07.17 21:06:59 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Ixil  
[2012.07.17 21:06:59 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Baze  
[2012.07.16 19:25:05 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Ekizec  
[2012.07.16 19:25:05 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Ampe  
[2012.07.10 11:42:25 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Roaming\Yahoo!  
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]  
[2012.07.17 21:40:06 | 000,000,788 | ---- | C] () -- C:\Users\Gudrun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk    
[2012.07.17 11:59:11 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Ampe  
[2012.07.18 01:01:05 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Baze  
[2012.04.11 14:38:33 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Downloaded Installations  
[2012.07.16 19:25:35 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Ekizec  
[2012.07.20 14:42:04 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\hellomoto  
[2012.07.20 15:17:14 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\Ixil  
[2010.10.11 02:50:48 | 000,000,000 | ---D | M] -- C:\Users\Gudrun\AppData\Roaming\WildTangent  
[2012.07.20 19:00:13 | 000,000,000 | ---D | C] -- C:\Users\Gudrun\AppData\Local\NPE  
[2012.07.20 18:27:10 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job  
[2012.07.20 17:58:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job  
[2012.07.20 17:54:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job  
[2012.07.17 21:40:06 | 000,000,758 | ---- | M] () -- C:\Users\Gudrun\Desktop\Poker at bet365.lnk  
[2012.07.17 21:40:06 | 000,000,788 | ---- | C] () -- C:\Users\Gudrun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk  
[2012.07.17 21:40:06 | 000,000,758 | ---- | C] () -- C:\Users\Gudrun\Desktop\Poker at bet365.lnk  
[2012.07.10 11:40:19 | 000,001,144 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk  
  
:Files   
ipconfig /flushdns /c 
:Commands 
[purity] 
[emptytemp] 
[emptyflash]   - Schließe alle Programme.
  - Klicke auf den Fix Button.
  - Wenn OTL einen Neustart verlangt, bitte zulassen.
  - Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
 
Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\    Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!   |