Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( nicht woanders hin ). Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc. Starte die OTL.exe . Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen". Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes: Code:
Alles auswählen Aufklappen ATTFilter
:OTL
MOD - c:\ProgramData\bProtectorForWindows\2.1.419.7\protector.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll ()
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (NVHDA) -- system32\drivers\nvhda32v.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (adfs) -- File not found
DRV - (ADASPROT) -- C:\Program Files\Advanced System Optimizer 3\adasprot32.sys File not found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304564
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {D34CDAC2-393E-4234-B4E4-3A504D059420}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = ^http://.*\.babylon\.com/\?.*AF=114022.*
IE - HKCU\..\SearchScopes\{D34CDAC2-393E-4234-B4E4-3A504D059420}: "URL" = http://www.google.de/search?q={searchTerms}&rlz=1I7GGHP_deDE493
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - prefs.js..extensions.enabledItems: MapShare-status@tomtom.com:1.7
FF - prefs.js..extensions.enabledItems: baseTheme@tomtom.com:1.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Lotja\AppData\Roaming\IDM\idmmzcc3 [2012.06.21 22:18:46 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Lotja\AppData\Roaming\IDM\idmmzcc5 [2012.07.04 09:50:40 | 000,000,000 | ---D | M]
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Browser companion helper] C:\Program Files\BrowserCompanion\BCHelper.exe /T=3 /CHI={$CHROM_GUID_UNINSTALLS} File not found
O4 - HKLM..\Run: [PCE Print Dispatcher] C:\Windows\System32\pcPDisp.exe (pdfconverter.com)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKCU..\Run: [AdobeBridge] File not found
O20 - AppInit_DLLs: (c:\progra~2\bprote~1\21419~1.7\protec~1.dll) - c:\ProgramData\bProtectorForWindows\2.1.419.7\protector.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{a629a5e7-bf06-11df-a2e5-001fe2f499c4}\Shell - "" = AutoRun
O33 - MountPoints2\{a629a5e7-bf06-11df-a2e5-001fe2f499c4}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{a629a5ed-bf06-11df-a2e5-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{a629a5ed-bf06-11df-a2e5-001e101fe5e1}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
[2012.07.29 08:07:13 | 000,078,023 | ---- | M] () -- C:\ProgramData\nvModes.001
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:FC420CE6
@Alternate Data Stream - 833 bytes -> C:\Users\Lotja\Documents\message.eml:OECustomProperty
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C31F31E6
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
[2012.07.27 22:17:28 | 000,000,000 | ---D | C] -- C:\Users\Lotja\AppData\Roaming\searchplugins
[2012.07.27 21:16:09 | 000,000,000 | ---D | C] -- C:\Users\Lotja\bProtectorForWindows
[2012.07.27 15:10:02 | 000,000,000 | ---D | C] -- C:\Users\Lotja\searchplugins
[2012.07.27 13:13:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\searchplugins
[2012.07.27 13:13:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\bProtectorForWindows
[2012.07.27 12:39:21 | 000,000,000 | ---D | C] -- C:\Users\Lotja\Desktop\bProtectorForWindows
[2012.07.27 11:25:15 | 000,000,000 | ---D | C] -- C:\Users\Lotja\Desktop\searchplugins
[2012.07.16 13:01:46 | 000,000,000 | ---D | C] -- C:\Windows\System32\searchplugins
[2012.07.16 13:01:46 | 000,000,000 | ---D | C] -- C:\Windows\System32\bProtectorForWindows
[2012.07.16 13:00:22 | 000,000,000 | ---D | C] -- C:\Users\Lotja\Documents\Flash Slideshow Maker Professional
[2012.07.01 11:42:19 | 000,001,851 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.07.21 17:32:49 | 000,000,000 | ---D | C] -- C:\Users\Lotja\temp
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash]
Schließe alle Programme. Klicke auf den Fix Button. Wenn OTL einen Neustart verlangt, bitte zulassen. Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\ Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!