Plagegeister aller Art und deren Bekämpfung: Lizenz-Daten konnten nicht korrekt geschrieben werden.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
![]() ![]() | ![]() Lizenz-Daten konnten nicht korrekt geschrieben werden. Hallo. Ich habe auf meinem Netbook mit Windows 7 die Cd von "Oxford Advanced Learner's Dictionary 8th Edition" installiert. Nach dem Neustart konnte ich aber the dictionary doch nicht öffnen. Wenn ich auf das Symbol im Desktop klicke, erhalte ich diese Fehlermeldung:"Lizenz-Daten konnten nicht korrekt geschrieben werden. Bitte wenden Sie sich an den Support!" Vor einigen Monaten habe ich mein System formatiert, ich weiss nicht ob das Problem damit zusammenhängt. Ich kenne mich leider mit Rechner nicht so gut aus. Ich würde mich freuen, wenn jemand mir dabei helfen könnte. Vielen Dank im Voraus. LG, Derya |
#2
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Lizenz-Daten konnten nicht korrekt geschrieben werden. Hallo,
Nichtsdestotrotz können wir deinen Rechner natürlich abklopfen wenn du willst
![]() ![]() | ![]() Lizenz-Daten konnten nicht korrekt geschrieben werden. Hallo. Ja ich habe den Support angewendet: aber die haben mir leider nicht weitergeholfen. Ich habe aus Securom AppDaten gelöscht und mein virenprogramm deinstalliert dann wörterbuch neu installiert aber immer wieder dieselbe Fehlermeldung. Ich schicke Ihnen die genauere Antwort vom Support
__________________![]() Leider ist uns dieser Fehler im Zusammenhang mit dem OALD nicht bekannt. Nach eigenen Recherchen scheint es hier ein Problem des Kopierschutzes SecuROM mit Ihrem PC vorzuliegen. „Dieser Fehler tritt normalerweise auf, wenn der Kopierschutz SecuROM nicht wie gewünscht Daten in dem vorgesehenem Unterverzeichnis des Benutzerverzeichnisses des Benutzers unter dem man bei Windows angemeldet ist, schreiben kann. Dies kann mehrere Gründe haben: Der Benutzer mit dem man angemeldet ist, hat nur eingeschränkte Rechte, die keinen vollen Schreibzugriff auf das gewünschte Unterverzeichnis des Benutzers erlauben. Das vorgesehene Unterverzeichnis existiert schon, ist aber schreibgeschützt. Der Benutzername enthält ungewöhnliche Zeichen wie Sonderzeichen oder Umlaute oder er ist sehr lang Ein Programm verhindert den Zugriff auf das gewünschte Unterverzeichnis. Es gibt Antiviren- & Antispyware Programme, die den Zugriff auf das Benutzerverzeichnis überwachen und wenn sie einen fragwürdigen Zugriff registrieren, diesen verhindern. Manchmal kommt es da zu Fehlinterpretationen dieser Programme.“ Bitte deinstallieren Sie den OALD deshalb noch einmal über Start -> Systemsteuerung -> Programme – nach der Deinstallation starten Sie bitte Ihren PC komplett einmal neu - deaktivieren Sie den Virenscanner und versuchen Sie bitte unter Beachtung der oben genannten Hinweise (Administratorrechte und Benutzernamen ohne Sonderzeichen) den OALD noch einmal neu zu installieren – bitte unbedingt eine Vollinstallation des Programms vornehmen. |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Lizenz-Daten konnten nicht korrekt geschrieben werden. Hm mal sehen ob da was dran sein kann. Ich kann dir aber nicht garantieren, dass wir diese Software auf deinen Rechner zum Laufen kriegen Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
Note: Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread. Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards. Erstmal eine Kontrolle mit OTL bitte:
Logfiles bitte immer in CODE-Tags posten
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Lizenz-Daten konnten nicht korrekt geschrieben werden. OTL neu runterladen und nochmal probieren Außerdem musst du abwarten, das Log ist nicht in Nullkommanix fertig ![]() Du siehst ganz unten im OTL-Fenster wie OTL die verschiedenen Verzeichnisse scannt
sorry. es hat geklappt. hat vielleicht zu lange gedauert. auf desktop habe ich 2logfiles gefunden.OTL Logfile:
(end)
Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 19:22:21.0833 2632 avast! Antivirus - ok Im Anschluss: adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen Downloade Dir bitte
Danach eine Kontrolle mit OTL bitte:
hallo. hier sind die ergebnisse [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\S-1-5-21-2070947155-1557344131-3509826172-1000\software\microsoft\internet explorer\main\\Start Page ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_classes_root\appid\babyloniepi.dll Successfully deleted: [Registry Key] hkey_classes_root\babydict Successfully deleted: [Registry Key] hkey_classes_root\babygloss Successfully deleted: [Registry Key] hkey_classes_root\babyloniepi.babyloniebho Successfully deleted: [Registry Key] hkey_classes_root\babyloniepi.babyloniebho.1 Successfully deleted: [Registry Key] hkey_classes_root\babylonofficeaddin.officeaddin Successfully deleted: [Registry Key] hkey_classes_root\babylonofficeaddin.officeaddin.1 Successfully deleted: [Registry Key] hkey_classes_root\babyoptfile Successfully deleted: [Registry Key] hkey_current_user\software\babylon Successfully deleted: [Registry Key] hkey_local_machine\software\babylon Successfully deleted: [Registry Key] hkey_current_user\software\babylontoolbar Successfully deleted: [Registry Key] hkey_current_user\software\conduit Successfully deleted: [Registry Key] hkey_local_machine\software\conduit Failed to delete: [Registry Key] hkey_current_user\software\datamngr Failed to delete: [Registry Key] hkey_local_machine\software\datamngr Failed to delete: [Registry Key] hkey_current_user\software\datamngr_toolbar Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\menuext\translate this web page with babylon Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\menuext\translate with babylon Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\office\powerpoint\addins\babylonofficeaddin.officeaddin Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\office\word\addins\babylonofficeaddin.officeaddin Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\babylon_rasapi32 Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\babylon_rasmancs Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\conduitinstaller_rasapi32 Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\conduitinstaller_rasmancs Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\conduituninstaller_rasapi32 Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\conduituninstaller_rasmancs Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasapi32 Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasmancs Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\app paths\babylon.exe Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT1561552 Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{6ac0bb10-c922-45e2-857d-2a368fe749e5} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} ~~~ Files Successfully deleted: [File] "C:\Users\derya\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\babylon.lnk" Successfully deleted: [File] "C:\end" Successfully deleted: [File] "C:\users\public\desktop\babylon.lnk" Successfully deleted: [File] C:\Windows\prefetch\BABYLON.EXE-45A68AF1.pf ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\babylon" Successfully deleted: [Folder] "C:\Users\derya\AppData\Roaming\babylon" Successfully deleted: [Folder] "C:\Users\derya\appdata\local\babylon" Successfully deleted: [Folder] "C:\Users\derya\appdata\local\conduit" Successfully deleted: [Folder] "C:\Users\derya\appdata\locallow\conduit" Failed to delete: [Folder] "C:\Program Files\babylon" Successfully deleted: [Folder] "C:\Program Files\conduit" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\babylon" ~~~ FireFox Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml" Successfully deleted: [File] C:\Users\derya\AppData\Roaming\mozilla\firefox\profiles\h4n9x1of.default\invalidprefs.js Successfully deleted: [Folder] "C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com" Successfully deleted: [Registry Value] hkey_local_machine\software\mozilla\firefox\extensions\\ocr@babylon.com Emptied folder: C:\Users\derya\AppData\Roaming\mozilla\firefox\profiles\h4n9x1of.default\minidumps [2 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 15.04.2013 at 23:43:54,71 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.200 - Datei am 15/04/2013 um 23:54:18 erstellt # Aktualisiert am 02/04/2013 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzer : derya - DERYA-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\derya\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\derya\AppData\Local\Temp\Uninstall.exe Datei Gelöscht : C:\Users\derya\AppData\Roaming\Mozilla\Firefox\Profiles\6tiiggbw.default\bprotector_extensions.sqlite Datei Gelöscht : C:\Users\derya\AppData\Roaming\Mozilla\Firefox\Profiles\jvs0cn2y.default\bprotector_extensions.sqlite Ordner Gelöscht : C:\Program Files\Babylon Ordner Gelöscht : C:\Users\derya\AppData\Local\Temp\Babylon ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\5fe8ad8bd38ea12 Schlüssel Gelöscht : HKCU\Software\DataMngr Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\5fe8ad8bd38ea12 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B16632F1-24E0-4D99-A68D-70BFB6447C48} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{37425600-CB21-49A0-8659-476FBAB0F8E8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A1489C85-4F6F-48C4-AC9E-18B63AF4703E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{F310F027-15CB-4A7F-B10D-3A4AFB5013A5} Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Babylon Schlüssel Gelöscht : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16476 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v20.0.1 (de) Datei : C:\Users\derya\AppData\Roaming\Mozilla\Firefox\Profiles\h4n9x1of.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [3618 octets] - [15/04/2013 23:54:18] ########## EOF - C:\AdwCleaner[S1].txt - [3678 octets] ##########OTL Logfile: Code:
ATTFilter OTL logfile created on: 16.04.2013 00:06:12 - Run 2 OTL by OldTimer - Version Folder = C:\Users\derya\Desktop Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1013,30 Mb Total Physical Memory | 207,23 Mb Available Physical Memory | 20,45% Memory free 1,99 Gb Paging File | 1,15 Gb Available in Paging File | 57,90% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,79 Gb Total Space | 187,03 Gb Free Space | 80,34% Space Free | Partition Type: NTFS Computer Name: DERYA-PC | User Name: derya | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\derya\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) PRC - C:\Users\derya\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Users\derya\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) PRC - C:\Programme\AVAST Software\Avast\AvastUI.exe (AVAST Software) PRC - C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software) PRC - C:\Programme\Skype\Updater\Updater.exe (Skype Technologies) PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Programme\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Programme\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) PRC - C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Programme\Samsung\Samsung Update Plus\SUPBackGround.exe () PRC - C:\Programme\Paragon Software\PONS 7\PONS.exe () ========== Modules (No Company Name) ========== MOD - C:\Programme\OpenOffice.org 3\program\libxml2.dll () MOD - C:\Programme\Samsung\Samsung Update Plus\SUPBackGround.exe () MOD - C:\Programme\Samsung\Samsung Update Plus\HMXML.dll () MOD - C:\Programme\Paragon Software\PONS 7\PONS.exe () MOD - C:\Programme\Paragon Software\PONS 7\Engine.dll () MOD - C:\Programme\Paragon Software\PONS 7\morphology.dll () MOD - C:\Programme\Paragon Software\PONS 7\QtCore4.dll () MOD - C:\Programme\Paragon Software\PONS 7\iconengines\qsvg1.dll () MOD - C:\Programme\Paragon Software\PONS 7\QtSvg4.dll () MOD - C:\Programme\Paragon Software\PONS 7\QtNetwork4.dll () MOD - C:\Programme\Paragon Software\PONS 7\QtGui4.dll () MOD - C:\Programme\Paragon Software\PONS 7\QtXml4.dll () MOD - C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll () ========== Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (avast! Antivirus) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software) SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies) SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (btwdins) -- C:\Programme\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.) SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV - (BrYNSvc) -- C:\Programme\Browny02\BrYNSvc.exe (Brother Industries, Ltd.) SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (catchme) -- C:\Users\derya\AppData\Local\Temp\catchme.sys File not found DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software) DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software) DRV - (aswVmm) -- C:\Windows\System32\drivers\aswVmm.sys () DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software) DRV - (aswRvrt) -- C:\Windows\System32\drivers\aswRvrt.sys () DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software) DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software) DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software) DRV - (taphss6) -- C:\Windows\System32\drivers\taphss6.sys (Anchorfree Inc.) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (yukonw7) -- C:\Windows\System32\drivers\yk62x86.sys (Marvell) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 57 12 43 4D 62 14 CE 01 [binary data] IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\..\SearchScopes\{23530345-370C-475E-A1B7-29101769EF6E}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=469A2950-8C02-4C3A-856A-F800790215CC&apn_sauid=4BB2C14B-1C96-4E19-80F0-974D9791E0A3 IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1483 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.04.11 22:02:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.11 23:48:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.11 23:47:51 | 000,000,000 | ---D | M] [2013.04.10 21:54:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\derya\AppData\Roaming\mozilla\Extensions [2013.04.13 17:29:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\derya\AppData\Roaming\mozilla\Firefox\Profiles\h4n9x1of.default\Extensions [2013.04.13 17:29:13 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\derya\AppData\Roaming\mozilla\firefox\profiles\h4n9x1of.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.04.15 23:43:18 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions [2013.04.11 22:02:37 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2013.04.11 23:48:14 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012.11.11 19:47:16 | 001,903,520 | ---- | M] (Caminova, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll [2013.04.11 23:48:04 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2013.04.11 23:48:04 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2013.04.11 23:48:04 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2013.04.11 23:48:04 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2013.04.11 23:48:04 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2013.04.11 23:48:04 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml O1 HOSTS File: ([2012.12.20 13:37:32 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [PONS 7] C:\Program Files\Paragon Software\PONS 7\PONS.exe () O4 - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000..\Run: [Spotify Web Helper] C:\Users\derya\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - Startup: C:\Users\derya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\derya\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O4 - Startup: C:\Users\derya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2070947155-1557344131-3509826172-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3D1D805D-972F-4927-91B7-1217F928207E}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EDF786D4-3E50-4680-BF1C-C158320A7F31}: DhcpNameServer = O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.04.15 23:34:17 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2013.04.15 23:34:06 | 000,000,000 | ---D | C] -- C:\JRT [2013.04.15 23:29:52 | 000,551,587 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\derya\Desktop\JRT.exe [2013.04.14 19:17:09 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\derya\Desktop\tdsskiller.exe [2013.04.14 18:27:59 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\derya\Desktop\aswMBR.exe [2013.04.14 14:19:24 | 000,000,000 | ---D | C] -- C:\Users\derya\Desktop\mbar [2013.04.13 17:23:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\derya\Desktop\OTL.exe [2013.04.13 17:07:30 | 000,000,000 | ---D | C] -- C:\Users\derya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxford [2013.04.13 17:07:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oxford [2013.04.11 23:47:44 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013.04.11 22:03:21 | 000,029,816 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2013.04.11 22:03:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.04.11 22:03:20 | 000,368,176 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013.04.11 22:03:17 | 000,060,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2013.04.11 22:03:16 | 000,062,376 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013.04.11 22:03:15 | 000,765,736 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013.04.11 22:03:10 | 000,066,336 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013.04.11 22:02:23 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.04.11 21:46:59 | 000,000,000 | ---D | C] -- C:\Users\derya\AppData\Local\MFAData [2013.04.11 21:46:59 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2013.04.11 21:46:59 | 000,000,000 | ---D | C] -- C:\Users\derya\AppData\Local\Avg2013 [2013.04.10 21:53:43 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2013.04.10 21:18:35 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2013.04.10 21:18:32 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2013.04.10 21:18:30 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2013.04.10 21:18:30 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2013.04.10 21:18:29 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2013.04.10 21:18:24 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2013.04.10 21:18:24 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2013.04.10 21:18:17 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2013.04.10 17:02:07 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2013.04.10 17:01:48 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2013.04.10 17:01:46 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2013.04.10 17:01:39 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll [2013.04.10 17:01:15 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll [2013.04.10 17:01:13 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll [2013.04.09 11:43:55 | 000,000,000 | ---D | C] -- C:\Users\derya\AppData\Local\oald8 [2013.04.09 11:43:33 | 000,000,000 | ---D | C] -- C:\Users\derya\AppData\Roaming\oald8 [2013.04.09 11:43:09 | 000,000,000 | RH-D | C] -- C:\Users\derya\AppData\Roaming\SecuROM [2013.04.09 11:37:19 | 000,000,000 | ---D | C] -- C:\Program Files\Oxford [2013.04.07 11:03:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2013.03.17 18:34:58 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys ========== Files - Modified Within 30 Days ========== [2013.04.16 00:12:05 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.04.16 00:12:05 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.04.16 00:04:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.16 00:04:24 | 796,889,088 | -HS- | M] () -- C:\hiberfil.sys [2013.04.15 23:50:55 | 000,613,083 | ---- | M] () -- C:\Users\derya\Desktop\adwcleaner.exe [2013.04.15 23:30:30 | 000,551,587 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\derya\Desktop\JRT.exe [2013.04.15 23:30:02 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.04.14 19:17:23 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\derya\Desktop\tdsskiller.exe [2013.04.14 19:12:17 | 000,000,512 | ---- | M] () -- C:\Users\derya\Desktop\MBR.dat [2013.04.14 18:29:39 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\derya\Desktop\aswMBR.exe [2013.04.14 14:17:27 | 012,917,756 | ---- | M] () -- C:\Users\derya\Desktop\mbar- [2013.04.14 10:51:06 | 000,691,592 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2013.04.14 10:51:06 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2013.04.13 18:14:35 | 000,377,856 | ---- | M] () -- C:\Users\derya\Desktop\gmer_2.1.19163.exe [2013.04.13 17:23:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\derya\Desktop\OTL.exe [2013.04.13 17:07:30 | 000,001,908 | ---- | M] () -- C:\Users\Public\Desktop\Oxford Advanced Learner's Dictionary - 8th Edition.lnk [2013.04.12 09:32:08 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat [2013.04.12 09:32:08 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013.04.12 09:32:08 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat [2013.04.12 09:32:08 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013.04.11 22:03:22 | 000,002,079 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.04.11 22:03:10 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013.04.10 21:53:46 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.04.10 21:28:13 | 000,288,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013.03.30 10:02:01 | 000,015,760 | ---- | M] () -- C:\Users\derya\Documents\untitled_0.odt [2013.03.30 09:45:57 | 000,000,098 | -H-- | M] () -- C:\Users\derya\Documents\.~lock.atatürk.odt# [2013.03.26 09:42:30 | 000,001,011 | ---- | M] () -- C:\Users\derya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013.03.26 09:41:34 | 000,000,979 | ---- | M] () -- C:\Users\derya\Desktop\Dropbox.lnk [2013.03.19 07:04:13 | 003,968,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe [2013.03.19 07:04:10 | 003,913,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe [2013.03.19 06:48:45 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll ========== Files Created - No Company Name ========== [2013.04.15 23:50:28 | 000,613,083 | ---- | C] () -- C:\Users\derya\Desktop\adwcleaner.exe [2013.04.14 19:12:17 | 000,000,512 | ---- | C] () -- C:\Users\derya\Desktop\MBR.dat [2013.04.14 14:15:21 | 012,917,756 | ---- | C] () -- C:\Users\derya\Desktop\mbar- [2013.04.13 18:14:16 | 000,377,856 | ---- | C] () -- C:\Users\derya\Desktop\gmer_2.1.19163.exe [2013.04.13 17:07:30 | 000,001,908 | ---- | C] () -- C:\Users\Public\Desktop\Oxford Advanced Learner's Dictionary - 8th Edition.lnk [2013.04.11 22:03:22 | 000,002,079 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.04.11 22:03:13 | 000,164,736 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013.04.11 22:03:12 | 000,049,248 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013.04.10 21:53:46 | 000,001,121 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.04.10 21:53:46 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.03.31 10:03:25 | 000,015,760 | ---- | C] () -- C:\Users\derya\Documents\untitled_0.odt [2013.03.30 09:45:57 | 000,000,098 | -H-- | C] () -- C:\Users\derya\Documents\.~lock.atatürk.odt# [2012.12.19 23:08:09 | 000,032,768 | ---- | C] () -- C:\Windows\System32\drivers\sp_rsdrv2.sys [2012.12.19 18:59:16 | 000,021,532 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat [2012.12.19 13:50:29 | 000,000,000 | ---- | C] () -- C:\Windows\RTLInBoth.ini ========== ZeroAccess Check ========== [2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 05:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report > OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 16.04.2013 00:06:12 - Run 2 OTL by OldTimer - Version Folder = C:\Users\derya\Desktop Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 1013,30 Mb Total Physical Memory | 207,23 Mb Available Physical Memory | 20,45% Memory free 1,99 Gb Paging File | 1,15 Gb Available in Paging File | 57,90% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 232,79 Gb Total Space | 187,03 Gb Free Space | 80,34% Space Free | Partition Type: NTFS Computer Name: DERYA-PC | User Name: derya | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6B465CCB-4A89-4440-AE59-63C1C36BF420}" = lport=1542 | protocol=6 | dir=in | name=realtek wps tcp prot | "{8E86C963-CB9A-4610-8BD9-5C569B24F56F}" = lport=53 | protocol=17 | dir=in | name=realtek ap udp prot | "{B7DAFC20-21DE-4A6C-BDC8-27335F519E66}" = lport=1542 | protocol=17 | dir=in | name=realtek wps udp prot | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3ECA47B4-BC57-464A-9515-2F20AB75422D}" = protocol=6 | dir=in | app=c:\users\derya\appdata\roaming\dropbox\bin\dropbox.exe | "{7CF206ED-01A0-4E03-BD15-F2D270F226F3}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{B20B69F7-D568-4E57-BE0F-2A79E7D1BFCD}" = protocol=17 | dir=in | app=c:\users\derya\appdata\roaming\dropbox\bin\dropbox.exe | "TCP Query User{3180332E-057B-41E2-82DC-155C76419750}C:\users\derya\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\derya\appdata\roaming\dropbox\bin\dropbox.exe | "TCP Query User{327C047A-F448-45FB-91AD-B1DDDE1B0406}C:\program files\spyware terminator\spywareterminatorupdate.exe" = protocol=6 | dir=in | app=c:\program files\spyware terminator\spywareterminatorupdate.exe | "TCP Query User{6C3F07EA-F81A-4A9B-A4E1-0446A67EABE1}C:\users\derya\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\derya\appdata\roaming\spotify\spotify.exe | "TCP Query User{CF57D954-9DA0-4883-8C58-0447489C0310}C:\users\derya\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\derya\appdata\roaming\spotify\spotify.exe | "UDP Query User{6CA0C4F2-CFA9-488C-B2D2-241CB64449D5}C:\users\derya\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\derya\appdata\roaming\dropbox\bin\dropbox.exe | "UDP Query User{8AB318CB-68A1-43E9-88C0-2CD7A5BC5321}C:\users\derya\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\derya\appdata\roaming\spotify\spotify.exe | "UDP Query User{B5944BA0-CE51-4292-A21B-148CB118FAC0}C:\program files\spyware terminator\spywareterminatorupdate.exe" = protocol=17 | dir=in | app=c:\program files\spyware terminator\spywareterminatorupdate.exe | "UDP Query User{C9736F0A-74A3-4128-8D93-30017280D577}C:\users\derya\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\derya\appdata\roaming\spotify\spotify.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI - Deutsch "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) "{ADDBDFFF-A9B1-4AAA-94ED-2F754A1F5D5F}" = Document Express DjVu Plug-in "{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}" = Samsung Update Plus "{E2A97415-BD97-4867-B906-05E39E9EE51F}" = HL-2130 "{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AudibleManager" = AudibleManager "avast" = avast! Free Antivirus "HDMI" = Intel(R) Graphics Media Accelerator Driver "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack "Mozilla Firefox 20.0.1 (x86 de)" = Mozilla Firefox 20.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NSIS_oald8" = Oxford Advanced Learner's Dictionary - 8th Edition "Paragon Software PONS 7" = Paragon Software PONS 7 "VLC media player" = VLC media player 2.0.5 ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-2070947155-1557344131-3509826172-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Dropbox" = Dropbox "Spotify" = Spotify ========== Last 20 Event Log Errors ========== [ System Events ] Error - 15.04.2013 17:56:38 | Computer Name = derya-PC | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error - 15.04.2013 18:04:51 | Computer Name = derya-PC | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom < End of report > |
ATTFilter [2013.04.09 11:43:09 | 000,000,000 | RH-D | C] -- C:\Users\derya\AppData\Roaming\SecuROM Rechtsklick auf Ordner "SecuROM" in C:\Users\derya\AppData\Roaming => Eigenschaften => Haken rausnehmen bei schreibgeschützt und übernehmen
![]() |
