| 
 :hallo:Fixen mit OTL  Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin). Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.Starte die OTL.exe.Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
  Code: 
 :OTLDRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
 DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
 DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
 DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTIOLib.sys -- (NTIOLib_1_0_C)
 IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
 IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=sb&searchfor={searchTerms}
 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = Alice:80
 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = Alice:80
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes,DefaultScope = {56256A51-B582-467e-B8D4-7786EDA79AE0}
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=sb&searchfor={searchTerms}
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{AE8BC07D-3D59-40FF-98B1-253537917C60}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=LOL&o=16439&src=crm&q={searchTerms}&locale=&apn_ptnrs=OY&apn_dtid=YYYYYYYYDE&apn_uid=2F447C74-9EE8-4B1F-8245-EEA94DD3E6EC&apn_sauid=A2D8D642-A247-4AE2-BDD1-EAC817C5DDE1
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = alice:80
 FF - prefs.js..browser.search.defaultengine: "Ask.com"
 FF - prefs.js..browser.search.defaultenginename: "Ask.com"
 FF - prefs.js..browser.search.order.1: "Ask.com"
 FF - prefs.js..browser.search.order.2: "1und1 Suche"
 FF - prefs.js..browser.search.order.3: "amazon.de"
 FF - prefs.js..browser.search.order.4: "WEB.DE Suche"
 FF - prefs.js..browser.search.selectedEngine: "Google"
 FF - prefs.js..browser.search.useDBForOrder: true
 FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
 
 FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.0.100005
 FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=kwd&searchfor="
 FF - user.js - File not found
 FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
 O3 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
 O3 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
 O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
 O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe ()
 O4 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000..\Run: [Facebook Update] C:\Users\EiLa\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
 O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
 O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
 O7 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
 O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
 O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
 O32 - HKLM CDRom: AutoRun - 1
 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
 O32 - AutoRun File - [2009.04.29 11:02:01 | 000,000,055 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
 O33 - MountPoints2\{2bd15933-c88f-11de-b488-fc97f4fd9540}\Shell - "" = AutoRun
 O33 - MountPoints2\{674b2118-9933-11e1-8427-806e6f6e6963}\Shell - "" = AutoRun
 O33 - MountPoints2\{674b2118-9933-11e1-8427-806e6f6e6963}\Shell\AutoRun\command - "" = D:\DVDSetup.exe
 O33 - MountPoints2\{911558e3-a3ba-11df-9a4f-db38cce6354e}\Shell - "" = AutoRun
 O33 - MountPoints2\{911558e3-a3ba-11df-9a4f-db38cce6354e}\Shell\AutoRun\command - "" = F:\autorun.exe
 O33 - MountPoints2\{98140266-b736-11e0-8aaa-a4d2f637f396}\Shell - "" = AutoRun
 O33 - MountPoints2\{98140266-b736-11e0-8aaa-a4d2f637f396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
 O33 - MountPoints2\{c65d2c29-c815-11de-b497-806e6f6e6963}\Shell - "" = AutoRun
 O33 - MountPoints2\{c65d2c29-c815-11de-b497-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe
 
 [2012.08.04 15:57:49 | 004,503,728 | ---- | M] () -- C:\ProgramData\ras_0oed.pad
 [2012.08.04 15:14:40 | 004,503,728 | ---- | M] () -- C:\ProgramData\23lldnur.pad
 [2012.08.04 15:08:26 | 000,001,883 | ---- | M] () -- C:\Users\EiLa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D1B5B4F1
 
 [2010.03.15 21:58:11 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
 [2010.03.15 21:58:11 | 000,000,000 | ---D | M] (WEB.DE Firefox Addon) -- C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}
 
 
 [2012.08.04 16:19:17 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
 [2012.08.04 16:08:27 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
 [2012.08.04 15:58:11 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
 [2012.08.04 15:59:45 | 000,010,288 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 [2012.08.04 15:59:45 | 000,010,288 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 [2012.08.03 19:42:01 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1398726743-2837821600-1242578985-1000UA.job
 [2012.07.22 22:42:01 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1398726743-2837821600-1242578985-1000Core.job
 :Files
 
 ipconfig /flushdns /c
 :Commands
 [purity]
 [emptytemp]
 [emptyflash]
 Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!Schließe alle Programme.Klicke auf den Fix Button.Wenn OTL einen Neustart verlangt, bitte zulassen.Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log>
 |