Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin). - Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
- Starte die OTL.exe.
Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen". - Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
Code:
:OTL
MOD - [2012.07.25 08:54:57 | 000,134,712 | ---- | M] () -- C:\Users\User\AppData\Roaming\14001.004\components\AcroFF004.dll
SRV - [2012.07.27 18:50:05 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.07.27 18:49:50 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2012.07.27 18:49:48 | 000,375,760 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2012.07.27 18:49:47 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.07.27 18:49:46 | 000,619,472 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Stopped] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe -- (AntiVirFirewallService)
SRV - [2012.07.20 20:12:43 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {812E8CF0-5D0D-4BB2-9345-E63F60397BDB}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{812E8CF0-5D0D-4BB2-9345-E63F60397BDB}: "URL" = http://www.google.de/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "BrotherSoft Extreme Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.de/"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=112555&tt=280612_7_&babsrc=KW_ss&mntrId=c42efc85000000000000001109172d39&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ao312opt.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}: C:\Users\User\AppData\Roaming\14001.004 [2012.07.25 08:54:57 | 000,000,000 | ---D | M]
[2012.04.15 19:03:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2012.07.20 20:12:48 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\ao312opt.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2012.03.15 01:46:44 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\ao312opt.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.20 18:24:52 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\ao312opt.default\extensions\bbrs_002@blabbers.com
[2012.07.25 08:54:57 | 000,000,000 | ---D | M] (Java Link Helper) -- C:\USERS\USER\APPDATA\ROAMING\14001.004
[2012.07.21 20:14:09 | 000,702,524 | ---- | M] () (No name found) -- C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AO312OPT.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {51A86BB3-6602-4C85-92A5-130EE4864F13} - No CLSID value found.
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\User\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [EPSON Stylus SX400 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEGE.EXE /FU "C:\Windows\TEMP\E_S6CB6.tmp" /EF "HKCU" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Reg Error: Key error.)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4417fdbd-9166-11e1-9b1e-0013d37b3218}\Shell - "" = AutoRun
O33 - MountPoints2\{4417fdbd-9166-11e1-9b1e-0013d37b3218}\Shell\AutoRun\command - "" = K:\NokiaPCIA_Autorun.exe
[2012.07.27 23:19:35 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2012.07.25 09:51:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\.terasology
[2012.07.25 08:54:57 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\14001.004
[2012.07.23 13:38:54 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\14001.003
[2012.07.23 11:31:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\.minecraft
[2012.07.22 10:47:23 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\UAs
[2012.07.22 08:17:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\14001.002
[2012.07.22 08:16:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\xmldm
[2012.07.22 08:16:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\kock
[2012.07.21 00:07:27 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Nuclear Coffee
[2012.07.27 23:13:23 | 004,503,728 | ---- | M] () -- C:\ProgramData\zak_lo0i7g.pad
[2012.07.27 22:29:38 | 000,007,601 | ---- | M] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012.07.27 13:10:19 | 004,503,728 | ---- | M] () -- C:\ProgramData\z7_0ytr.pad
[2012.07.27 13:09:37 | 000,268,944 | ---- | M] () -- C:\Users\User\AppData\Roaming\AcroIEHelpe176.dll
[2012.07.27 13:09:37 | 000,006,400 | ---- | M] () -- C:\Users\User\AppData\Roaming\BAcroIEHelpe176.dll
[2012.07.27 13:09:26 | 000,000,034 | ---- | M] () -- C:\Users\User\AppData\Roaming\blckdom.res
[2012.07.26 09:35:49 | 000,268,944 | ---- | M] () -- C:\Users\User\AppData\Roaming\AcroIEHelpe175.dll
[2012.07.19 13:57:18 | 004,503,728 | ---- | M] () -- C:\ProgramData\to_r0tsef.pad
[2012.03.09 17:37:46 | 000,002,048 | -HS- | C] () -- C:\Users\User\AppData\Local\dd740b76\@
[2012.02.07 14:47:13 | 000,002,048 | -HS- | C] () -- C:\Users\User\AppData\Local\{52900143-3419-b828-feed-0c96d2d3c0a1}\@
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z...ZZ..Z.Z.Z.ZZ:1
[2012.07.27 23:13:06 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.27 17:49:36 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash]
- Schließe alle Programme.
- Klicke auf den Fix Button.
- Wenn OTL einen Neustart verlangt, bitte zulassen.
- Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\ Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |