Vielen Dank!
Habe genau Deine Anweisungen befolgt.
Hier nach dem 'Fixen':
Code:
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry value HKEY_USERS\S-1-5-21-657417494-2717284355-1407466500-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
HKEY_USERS\S-1-5-21-657417494-2717284355-1407466500-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-657417494-2717284355-1407466500-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3BA9576B-D6BE-487A-BC96-D14417CBE30E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BA9576B-D6BE-487A-BC96-D14417CBE30E}\ not found.
HKEY_USERS\S-1-5-21-657417494-2717284355-1407466500-1005\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-657417494-2717284355-1407466500-1005\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-657417494-2717284355-1407466500-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube Download\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Free YouTube Download\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c03cc5b-36ee-11e1-b607-001b21c4f14d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c03cc5b-36ee-11e1-b607-001b21c4f14d}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c03cc5b-36ee-11e1-b607-001b21c4f14d}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c03cc5b-36ee-11e1-b607-001b21c4f14d}\ not found.
File F:\start.exe not found.
========== SERVICES/DRIVERS ==========
Service Lbd stopped successfully!
Service Lbd deleted successfully!
Service gfibto stopped successfully!
Service gfibto deleted successfully!
Service gfiark stopped successfully!
Service gfiark deleted successfully!
========== FILES ==========
C:\Windows\SysNative\drivers\Lbd.sys moved successfully.
C:\Users\*******\AppData\Roaming\LavasoftStatistics folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120524T191114.983933PID9256 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120524T144611.754861PID356 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120523T180653.159441PID5576 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120522T191614.083845PID5144 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120521T201724.118241PID5384 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120520T175101.796241PID5308 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120520T080710.287037PID5272 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120519T144603.448249PID5616 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120519T112751.725837PID5480 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120519T103857.967882PID5688 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120519T095204.071441PID5256 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120518T220155.071017PID8732 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120518T173015.351225PID7768 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs\20120518T165241.189438PID5624 folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus\Logs folder moved successfully.
C:\Users\*********\AppData\Roaming\Ad-Aware Antivirus folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs\20120525T183852.936222PID4564 folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs\20120524T191014.967427PID4620 folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs\20120524T142959.499033PID1492 folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs\20120520T192042.566406PID4480 folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs\20120518T212211.999095PID7432 folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs\20120518T165417.444548PID5284 folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus\Logs folder moved successfully.
C:\Users\Gast\AppData\Roaming\Ad-Aware Antivirus folder moved successfully.
C:\Windows\SysNative\drivers\gfiark.sys moved successfully.
C:\Windows\SysNative\drivers\gfibto.sys moved successfully.
C:\ProgramData\blekko toolbars folder moved successfully.
C:\Program Files (x86)\adawaretb folder moved successfully.
C:\Program Files (x86)\Toolbar Cleaner folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: *********
->Temp folder emptied: 443428417 bytes
->Java cache emptied: 1 bytes
->Flash cache emptied: 1150 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
User: Gast
->Temp folder emptied: 22402670 bytes
->Java cache emptied: 72218 bytes
->Flash cache emptied: 539 bytes
User: *****
->Temp folder emptied: 34974 bytes
->Flash cache emptied: 794 bytes
User: Public
User: *******
->Temp folder emptied: 521827761 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 506 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 225945626 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
RecycleBin emptied: 3840796789 bytes
Total Files Cleaned = 4.820,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12092012_134015
und hier der Bericht von RogueKiller:
Code:
RogueKiller V8.3.2 [Dec 7 2012] durch Tigzy
mail: tigzyRK<at>gmail<dot>com
mail : tigzyRK<at>gmail<dot>com
Kommentare : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Webseite : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/
Betriebssystem : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Gestartet in : Normaler Modus
Benutzer : ******* [Admin Rechte]
Funktion : Scannen -- Datum : 12/09/2012 13:53:07
¤¤¤ Böswillige Prozesse : 0 ¤¤¤
¤¤¤ Registry-Einträge : 5 ¤¤¤
[RUN][SUSP PATH] HKUS\S-1-5-21-657417494-2717284355-1407466500-1005[...]\Run : ConnectionCenter ("C:\Users\Alexander\AppData\Local\Citrix\ICA Client\concentr.exe" /startup) -> GEFUNDEN
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> GEFUNDEN
[HJ SMENU] HKCU\[...]\Advanced : Start_TrackProgs (0) -> GEFUNDEN
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> GEFUNDEN
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> GEFUNDEN
¤¤¤ Bestimmte Dateien / Ordner: ¤¤¤
¤¤¤ Treiber : [NICHT GELADEN] ¤¤¤
¤¤¤ Hosts-Datei: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR überprüfen: ¤¤¤
+++++ PhysicalDrive0: INTEL SSDSA2CW120G3 ATA Device +++++
--- User ---
[MBR] 233130646d5b242858e8d5899324e410
[BSP] 24daf862b0feca9291eb093933b0e7a3 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 114371 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: Hitachi HDS721050CLA362 ATA Device +++++
--- User ---
[MBR] 287f2412cc95d586ff705b3e0625caac
[BSP] 45e381d5278219386b67490017f9ba66 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 276938 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 567173120 | Size: 200000 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive2: Hitachi HDS721050CLA362 ATA Device +++++
--- User ---
[MBR] 2038c3e67fccfcdab3b394f2d910cbd0
[BSP] 70205f2d2b2145cd5bcbc0a9913bc2c2 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 276941 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 567177216 | Size: 199998 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Abgeschlossen : << RKreport[1]_S_12092012_02d1353.txt >>
RKreport[1]_S_12092012_02d1353.txt
Bis bald! Dampfo