:hallo: Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin). - Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
- Starte die OTL.exe.
Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen". - Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:
Code:
:OTL
SRV - [2012.01.10 16:39:03 | 003,014,656 | ---- | M] () [Auto | Stopped] -- C:/Program Files/Common Files/Akamai/netsession_win_b427739.dll -- (Akamai)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\LVUSBSta.sys -- (LVUSBSta)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ironto&s={searchTerms}&f=4
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2866295
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {b9d63c58-90cc-428b-8d3b-cbb88eb07e7e} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ironto&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=100581&tt=110911_startpage
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{AD0F01B0-014D-459F-92B2-D933DA373547}: "URL" = http://www.google.de/search?q={searchTerms}&rlz=1I7ADRA_deDE403
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2866295
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
Hosts file not found
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B9D63C58-90CC-428B-8D3B-CBB88EB07E7E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4 - HKLM..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart File not found
O4 - HKLM..\Run: [Java] C:\Users\Kevin\AppData\Roaming\Java.exe File not found
O4 - HKCU..\Run: [Driver Updater] File not found
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Java = C:\Users\Kevin\AppData\Roaming\Java.exe
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
[2012.08.15 20:34:36 | 004,503,728 | ---- | M] () -- C:\ProgramData\ism_0_llatsni.pad
[2012.08.14 17:05:57 | 004,503,728 | ---- | M] () -- C:\ProgramData\23lldnur.pad
[2012.08.14 02:13:52 | 000,001,895 | ---- | M] () -- C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:CB0AACC9
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:0888F409
[2012.08.15 00:22:55 | 000,000,000 | ---D | C] -- C:\Users\Kevin\Desktop\965TOGQJ
[2012.08.15 20:33:52 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.08.15 20:21:44 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_trash_log.cmd
[2012.08.15 01:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At8.job
[2012.08.15 01:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At7.job
[2012.08.15 01:15:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.08.15 00:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At6.job
[2012.08.15 00:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At5.job
[2012.08.14 23:41:09 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At52.job
[2012.08.14 23:41:09 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At50.job
[2012.08.14 23:41:09 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At48.job
[2012.08.14 23:41:09 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At46.job
[2012.08.14 23:41:09 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At51.job
[2012.08.14 23:41:09 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At49.job
[2012.08.14 23:41:09 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At47.job
[2012.08.14 23:41:09 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At45.job
[2012.08.14 19:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At44.job
[2012.08.14 19:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At43.job
[2012.08.14 18:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At42.job
[2012.08.14 18:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At41.job
[2012.08.14 17:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At40.job
[2012.08.14 17:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At39.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At30.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At28.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At26.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At24.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At22.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At20.job
[2012.08.14 12:41:40 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At18.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At29.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At27.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At25.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At23.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At21.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At19.job
[2012.08.14 12:41:40 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At17.job
[2012.08.14 05:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At16.job
[2012.08.14 05:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At15.job
[2012.08.14 04:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At14.job
[2012.08.14 04:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At13.job
[2012.08.14 03:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At12.job
[2012.08.14 03:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At11.job
[2012.08.14 02:35:00 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At10.job
[2012.08.14 02:35:00 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At9.job
[2012.08.13 20:16:28 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At38.job
[2012.08.13 20:16:28 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At36.job
[2012.08.13 20:16:28 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At34.job
[2012.08.13 20:16:28 | 000,000,352 | ---- | M] () -- C:\Windows\tasks\At32.job
[2012.08.13 20:16:28 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At37.job
[2012.08.13 20:16:28 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At35.job
[2012.08.13 20:16:28 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At33.job
[2012.08.13 20:16:28 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\At31.job
[2011.11.05 21:05:21 | 000,000,000 | ---D | M] -- C:\Users\Kevin\AppData\Roaming\Babylon
[2011.11.05 01:28:00 | 000,000,504 | ---- | M] () -- C:\Windows\Tasks\At1.job
[2011.11.05 01:30:00 | 000,000,504 | ---- | M] () -- C:\Windows\Tasks\At2.job
[2011.11.05 01:30:00 | 000,000,504 | ---- | M] () -- C:\Windows\Tasks\At3.job
[2011.11.05 01:30:00 | 000,000,504 | ---- | M] () -- C:\Windows\Tasks\At4.job
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp] - Schließe alle Programme.
- Klicke auf den Fix Button.
- Wenn OTL einen Neustart verlangt, bitte zulassen.
- Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log> Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |