Hallo Petra,
===== Punkt 1 =====
hier das Ergebnis vom SystemLook-Scan:
Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 13:02 on 04/08/2012 by sascha
Administrator - Elevation successful
========== filefind ==========
Searching for "explorer.exe"
C:\Windows\explorer.exe --a---- 2871808 bytes [15:52 23/04/2012] [06:19 25/02/2011] 332FEAB1435662FC6C672E25BEB37BE3
C:\Windows\SysWOW64\explorer.exe --a---- 2616320 bytes [15:52 23/04/2012] [05:30 25/02/2011] 8B88EBBB05A0E56B7DCC708498C02B3E
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe --a---- 2868224 bytes [23:56 13/07/2009] [01:39 14/07/2009] C235A51CB740E45FFA0EBFB9BAFCDA64
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe --a---- 2870272 bytes [15:52 23/04/2012] [06:23 26/02/2011] 0862495E0C825893DB75EF44FAEA8E93
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe --a---- 2870784 bytes [15:52 23/04/2012] [06:26 26/02/2011] E38899074D4951D31B4040E994DD7C8D
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe --a---- 2872320 bytes [19:49 18/02/2011] [13:24 20/11/2010] AC4C51EB24AA95B77F705AB159189E24
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe --a---- 2871808 bytes [15:52 23/04/2012] [06:19 25/02/2011] 332FEAB1435662FC6C672E25BEB37BE3
C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe --a---- 2871808 bytes [15:52 23/04/2012] [06:14 26/02/2011] 3B69712041F3D63605529BD66DC00C48
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe --a---- 2613248 bytes [23:41 13/07/2009] [01:14 14/07/2009] 15BC38A7492BEFE831966ADB477CF76F
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe --a---- 2614784 bytes [15:52 23/04/2012] [05:33 26/02/2011] 2AF58D15EDC06EC6FDACCE1F19482BBF
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe --a---- 2614784 bytes [15:52 23/04/2012] [05:51 26/02/2011] 255CF508D7CFB10E0794D6AC93280BD8
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe --a---- 2616320 bytes [19:49 18/02/2011] [12:17 20/11/2010] 40D777B7A95E00593EB1568C68514493
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe --a---- 2616320 bytes [15:52 23/04/2012] [05:30 25/02/2011] 8B88EBBB05A0E56B7DCC708498C02B3E
C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe --a---- 2616320 bytes [15:52 23/04/2012] [05:19 26/02/2011] 0FB9C74046656D1579A64660AD67B746
========== dir ==========
C:\Windows\´÷Ç - Unable to find folder.
C:\Config.Msi - Parameters: "/s"
---Files---
None found.
No folders found.
-= EOF =-
===== Punkt 2 =====
Und noch das OTL-LOG:
Code:
All processes killed
========== OTL ==========
HKEY_USERS\S-1-5-21-3452243748-1991479349-3436702281-1002\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Prefs.js: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 removed from extensions.enabledItems
Prefs.js: "http://www.searchplusnetwork.com/?sp=vit4&q=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IntelTBRunOnce not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{7815BE26-237D-41A8-A98F-F7BD75F71086}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7815BE26-237D-41A8-A98F-F7BD75F71086}\ not found.
File not found.
File not found.
ADS C:\ProgramData\TEMP:966F7784 deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\sascha\Desktop\cmd.bat deleted successfully.
C:\Users\sascha\Desktop\cmd.txt deleted successfully.
C:\Users\sascha\Documents\EmsisoftAntiMalwareSetup.exe moved successfully.
C:\Users\sascha\Desktop\mbam-setup.exe moved successfully.
C:\Users\sascha\Documents\SystemLook.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: sascha
->Temp folder emptied: 7205082 bytes
->Temporary Internet Files folder emptied: 459531 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 56059106 bytes
->Flash cache emptied: 506 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1434023098 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,428.00 mb
OTL by OldTimer - Version 3.2.54.0 log created on 08042012_130919
Files\Folders moved on Reboot...
C:\Users\sascha\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
File C:\Users\sascha\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
Registry entries deleted on Reboot...
Nach dem Reboot habe ich jetzt keine Fehlermeldung vom Windows-Explorer bekommen. 
===== Punkt 3 =====
Habe die Einstellungen mit msconfig vorgenommen.
===== Punkt 4 =====
In Arbeit ....

So, nach dem restart, um die msconfig-Einstellung wirksam zu machen, bekomme ich jetzt also wieder die lästige Windows-Explorer-Fehlermeldung 
Also weiter im abgesicherten Modus.
Dort bekomme ich im ûbrigen auch diese Windows-Explorer-Fehlermeldung. Allerdings kommt sie nach zwei restarts nicht mehr wieder.
Ich erinnere mich, dass ich dies Problem bei den ersten Arbeiten im abgesicherten Modus nicht hatte.
Mache mich jetzt an Punkt 4 ...
So comboFix sagt mir, dass folgendes noch aktiv ist:
antivirus: Avira Desktop
antispyware: Avira Desktop
Eigentlich dachte ich, dass ich alles abgeschaltet hatte.
Der Avira Status sagt auch, dass alles aus ist.
Im Windows task manager sehe ich, dass alle Services von Avira gestopt sind.
Soll ich ComboFix trotzdem laufen lassen?
Gruss
Sascha
Lesezeichen