:hallo: Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin). - Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
- Starte die OTL.exe.
Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen". - Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
Code:
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\system32\Drivers\DgiVecp.sys -- (DgiVecp)
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{D9A80BB3-B0E4-4B4D-93DF-67B60F57DAC5}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{DE9FEAA3-5CD2-4DC3-A08D-D2562FDD252F}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - No CLSID value found
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=109958&tt=290312_bexdll&babsrc=SP_ss&mntrId=07773c98000000000000001e101fabdd
IE - HKCU\..\SearchScopes\{31CF9EBE-5755-4a1d-AC25-2834D952D9B4}: "URL" = http://search.pdfcreator-toolbar.org/search?p=Q&ts=ne&w={searchTerms}&csrc=search-field
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GZEZ_de
IE - HKCU\..\SearchScopes\{D9A80BB3-B0E4-4B4D-93DF-67B60F57DAC5}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKCU\..\SearchScopes\{DE9FEAA3-5CD2-4DC3-A08D-D2562FDD252F}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "softonic-de3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.facebook.de"
FF - prefs.js..extension.gacela.network.proxy.autoconfig_url: ""
FF - prefs.js..extension.gacela.network.proxy.type: 5
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.8
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {afe43e80-0abc-4df2-81a0-3fe44b74abe8}:1.300.367
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065}:3.2.5.2
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.07.25 21:25:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.07.25 21:25:46 | 000,000,000 | ---D | M]
[2012.07.15 21:54:43 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\Manu\AppData\Roaming\mozilla\Firefox\Profiles\rqculffx.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2012.07.28 09:38:49 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Manu\AppData\Roaming\mozilla\Firefox\Profiles\rqculffx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [NeroCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKCU..\Run: [Power2GoExpress] NA File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.09.11 20:53:06 | 000,000,119 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{067da89a-d3ab-11de-bd29-001e68e03a60}\Shell - "" = AutoRun
O33 - MountPoints2\{067da89a-d3ab-11de-bd29-001e68e03a60}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe -- [2009.07.23 16:55:39 | 000,266,240 | R--- | M] (Vodafone)
O33 - MountPoints2\{43899bbc-3a11-11e1-8fc8-001e68e03a60}\Shell - "" = AutoRun
O33 - MountPoints2\{43899bbc-3a11-11e1-8fc8-001e68e03a60}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe -- [2009.07.23 16:55:39 | 000,266,240 | R--- | M] (Vodafone)
O33 - MountPoints2\{49633f3c-02cf-11e1-b173-001e68e03a60}\Shell - "" = AutoRun
O33 - MountPoints2\{49633f3c-02cf-11e1-b173-001e68e03a60}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe -- [2009.07.23 16:55:39 | 000,266,240 | R--- | M] (Vodafone)
O33 - MountPoints2\{52582322-e77b-11e0-856b-001e101f1ed9}\Shell - "" = AutoRun
O33 - MountPoints2\{52582322-e77b-11e0-856b-001e101f1ed9}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe -- [2009.07.23 16:55:39 | 000,266,240 | R--- | M] (Vodafone)
O33 - MountPoints2\{f5d55636-062c-11e1-9f0d-001e101fe70e}\Shell - "" = AutoRun
O33 - MountPoints2\{f5d55636-062c-11e1-9f0d-001e101fe70e}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe -- [2009.07.23 16:55:39 | 000,266,240 | R--- | M] (Vodafone)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe -- [2009.07.23 16:55:39 | 000,266,240 | R--- | M] (Vodafone)
[2012.07.25 18:59:04 | 004,503,728 | ---- | M] () -- C:\ProgramData\z7_0ytr.pad
[2010.12.08 15:47:52 | 000,000,927 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\conduit.xml
[2012.07.24 20:06:38 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-1.xml
[2011.03.02 21:31:10 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-10.xml
[2011.03.04 23:14:00 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-11.xml
[2011.03.26 10:13:36 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-12.xml
[2011.04.07 19:10:21 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-13.xml
[2011.04.29 22:25:33 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-14.xml
[2011.06.21 20:59:15 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-15.xml
[2011.07.02 15:52:06 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-16.xml
[2011.09.30 16:59:53 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-17.xml
[2011.11.08 18:22:41 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-18.xml
[2011.11.29 20:16:57 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-19.xml
[2010.06.27 11:51:38 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-2.xml
[2011.12.23 10:21:33 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-20.xml
[2012.01.07 00:53:02 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-21.xml
[2012.02.26 21:30:03 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-22.xml
[2012.03.29 21:32:03 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-23.xml
[2012.05.13 21:39:30 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-24.xml
[2012.07.01 20:20:07 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-25.xml
[2010.07.24 10:42:00 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-3.xml
[2010.07.25 14:04:24 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-4.xml
[2010.09.11 16:34:33 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-5.xml
[2010.09.17 20:13:09 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-6.xml
[2010.10.20 21:48:38 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-7.xml
[2010.10.29 18:18:21 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-8.xml
[2010.12.10 22:36:29 | 000,000,950 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin-9.xml
[2012.07.24 14:48:30 | 000,000,168 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin.gif
[2012.07.24 14:48:30 | 000,000,618 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin.src
[2011.03.30 16:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\icqplugin.xml
[2012.03.08 19:20:07 | 000,001,734 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\search-the-web.xml
[2009.11.25 22:07:27 | 000,003,915 | ---- | M] () -- C:\Users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\rqculffx.default\searchplugins\sweetim.xml
[2012.07.28 09:36:06 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.28 09:32:43 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.22 08:59:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash] - Schließe alle Programme.
- Klicke auf den Fix Button.
- Wenn OTL einen Neustart verlangt, bitte zulassen.
- Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\ Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |