Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Antivir hat den Trojaner TR/Shakat.o.566 gefunden

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 08.02.2011, 20:08   #1
Katti169
 
Antivir hat den Trojaner TR/Shakat.o.566 gefunden - Standard

Antivir hat den Trojaner TR/Shakat.o.566 gefunden



Hallo zusammen,

Antivir hat auf meinem Laptop (Windows Vista) gestern abend den Trojaner "TR/Shakat.o.566" gefunden diesen hab ich dann in Quarantäne verschoben. Im Anhang ein Screenshot von der Quarantäne-Verwaltung in Antivir.
Die Datei sagt mir gar nichts...
Ich habe auch noch keine Infos über den Trojaner im Netz gefunden...

Danach habe ich Antivir und SUPERAntiSpyware noch mal das System checken lassen, die haben dann nichts mehr gefunden (ausser Cookies).

Kann ich die Datei jetzt einfach löschen und der Trojaner ist weg? Ich glaube leider, dass es nicht so einfach ist...

Ich danke euch jetzt schon mal für eure Hilfe!

Liebe Grüße
Katti

Nachdem ich in dem Forum ein bisschen gestöbert habe, habe ich noch mal Malware Bytes gestartet. Hier hat 19 identifizierte Objekte gefunden.
Die habe ich dann in Quarantäne gschoben und nach dem Neustart wurde folgender Log protokolliert:

Code:
ATTFilter
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
 
Datenbank Version: 5714
 
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
 
08.02.2011 22:37:11
mbam-log-2011-02-08 (22-37-11).txt
 
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 282971
Laufzeit: 1 Stunde(n), 46 Minute(n), 56 Sekunde(n)
 
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 3
Infizierte Registrierungsschlüssel: 7
Infizierte Registrierungswerte: 4
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 5
 
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Speichermodule:
C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\components\pdfforgeToolbarFF.dll (Adware.WidgiToolbar) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll (PUP.Dealio) -> Delete on reboot.
C:\Program Files\pdfforge Toolbar\SearchSettingsRes409.dll (PUP.Dealio) -> Delete on reboot.
 
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\CLSID\{e312764e-7706-43f1-8dab-fcdd2b1e416d} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e312764e-7706-43f1-8dab-fcdd2b1e416d} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e312764e-7706-43f1-8dab-fcdd2b1e416d} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b922d405-6d13-4a2b-ae89-08a030da4402} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b922d405-6d13-4a2b-ae89-08a030da4402} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b922d405-6d13-4a2b-ae89-08a030da4402} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b922d405-6d13-4a2b-ae89-08a030da4402} (PUP.Dealio) -> Quarantined and deleted successfully.
 
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\components\pdfforgeToolbarFF.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{e312764e-7706-43f1-8dab-fcdd2b1e416d} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b922d405-6d13-4a2b-ae89-08a030da4402} (PUP.Dealio) -> Quarantined and deleted successfully.
 
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
 
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
 
Infizierte Dateien:
C:\Program Files\Mozilla Firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}\components\pdfforgeToolbarFF.dll (Adware.WidgiToolbar) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\components\SearchSettingsFF.dll (PUP.Dealio) -> Delete on reboot.
C:\Program Files\pdfforge Toolbar\SearchSettingsRes409.dll (PUP.Dealio) -> Delete on reboot.
C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll (PUP.Dealio) -> Quarantined and deleted successfully.
C:\Program Files\pdfforge Toolbar\WidgiHelper.exe (PUP.Dealio) -> Quarantined and deleted successfully.
         
Ist das gut oder schlecht?

Danke!

Und dann hab ich jetzt noch mal OTL nach folgender Anweisung ausgeführt:

# Doppelklick auf die OTL.exe
# Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
# Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
# Unter Extra Registry, wähle bitte Use SafeList
# Klicke nun auf Run Scan links oben

(das habe ich in einem anderen Thema hier gefunden)

Dabei sind folgende Logs rausgekommen:

OTL.txt
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 08.02.2011 22:51:22 - Run 1
OTL by OldTimer - Version 3.2.20.6     Folder = C:\Users\Katrin\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 40,00% Memory free
4,00 Gb Paging File | 2,00 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 43,95 Gb Total Space | 5,14 Gb Free Space | 11,71% Space Free | Partition Type: NTFS
Drive D: | 97,29 Gb Total Space | 72,49 Gb Free Space | 74,51% Space Free | Partition Type: NTFS
 
Computer Name: NB-KATRIN | User Name: Katrin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Katrin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Greenshot\Greenshot.exe ()
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\System Control Manager\MGSysCtrl.exe (Mirco-Star International  CO., LTD.)
PRC - C:\Program Files\System Control Manager\MSIService.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe (Just Great Software)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
PRC - C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.)
PRC - C:\Windows\System32\lxczcoms.exe ( )
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Katrin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (Micro Star SCM) -- C:\Program Files\System Control Manager\MSIService.exe ()
SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (lxcz_device) -- C:\Windows\System32\lxczcoms.exe ( )
 
 
========== Driver Services (SafeList) ==========
 
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (RTL8187Se) -- C:\Windows\System32\drivers\RTL8187Se.sys (Realtek Semiconductor Corporation                           )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (JMCR) -- C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Tosrfusb) -- C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\System32\drivers\snp2uvc.sys ()
DRV - (nvstor32) -- C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (netr28) -- C:\Windows\System32\drivers\netr28.sys (Ralink Technology, Corp.)
DRV - (Tosrfcom) -- C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (enecir) -- C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (tosrfbd) -- C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (tosporte) -- C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) -- C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (TosRfSnd) -- C:\Windows\System32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (tosrfbnp) -- C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (ReallusionVirtualAudio) -- C:\Windows\System32\drivers\RLVrtAuCbl.sys ()
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (tosrfnds) -- C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msi.com.tw
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msi.com.tw
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.wer-kennt-wen.de/"
FF - prefs.js..extensions.enabledItems: {B922D405-6D13-4A2B-AE89-08A030DA4402}:1.1.1
FF - prefs.js..extensions.enabledItems: search@searchsettings.com:1.2.2
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p="
 
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.03.03 20:11:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.10.11 17:59:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.12.14 19:41:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.10.11 17:59:38 | 000,000,000 | ---D | M]
 
[2010.09.12 12:38:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Katrin\AppData\Roaming\mozilla\Extensions
[2010.09.12 12:38:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Katrin\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.02.08 20:59:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Katrin\AppData\Roaming\mozilla\Firefox\Profiles\zjexupj8.default\extensions
[2010.04.12 18:15:41 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Katrin\AppData\Roaming\mozilla\Firefox\Profiles\zjexupj8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.01.15 19:32:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Katrin\AppData\Roaming\mozilla\Firefox\Profiles\zjexupj8.default\extensions\toolbar_extras@de.yahoo.com
[2010.12.13 20:46:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2009.08.15 17:12:47 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.12.13 20:46:04 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009.09.22 20:02:06 | 000,000,000 | ---D | M] (pdfforge Toolbar Plugin) -- C:\Program Files\mozilla firefox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}
[2009.09.22 20:02:06 | 000,000,000 | ---D | M] (Search Settings Plugin) -- C:\Program Files\mozilla firefox\extensions\search@searchsettings.com
[2009.01.15 19:31:46 | 000,000,000 | ---D | M] (Yahoo! Deutschland Toolbar und Extras) -- C:\Program Files\mozilla firefox\extensions\toolbar_extras@de.yahoo.com
[2008.03.15 14:56:14 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2008.10.13 19:34:40 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2008.02.19 15:40:48 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2006.12.03 16:59:22 | 000,000,986 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2008.07.15 15:23:13 | 000,000,810 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [lxczbmgr.exe] C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [ Malwarebytes Anti-Malware  (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe (Mirco-Star International  CO., LTD.)
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SearchSettings]  File not found
O4 - HKLM..\Run: [WinampAgent]  File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [Greenshot] C:\Program Files\Greenshot\Greenshot.exe ()
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [MsgCenterExe]  File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Katrin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Katrin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Katrin\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.02.08 22:50:12 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Users\Katrin\Desktop\OTL.exe
[2011.02.08 20:45:41 | 000,000,000 | ---D | C] -- C:\Users\Katrin\AppData\Roaming\Malwarebytes
[2011.02.08 20:45:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.02.08 20:45:22 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.02.08 20:44:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.02.08 20:44:13 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.02.08 20:44:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.02.08 19:11:31 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2011.02.07 20:44:10 | 000,000,000 | ---D | C] -- C:\Users\Katrin\AppData\Roaming\SUPERAntiSpyware.com
[2011.02.07 20:44:10 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011.02.07 20:44:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011.02.07 20:43:57 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011.02.07 19:34:48 | 000,000,000 | ---D | C] -- C:\Users\Katrin\Desktop\PARIS
[2011.01.20 21:41:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011.01.20 21:41:22 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011.01.18 19:11:49 | 000,000,000 | ---D | C] -- C:\Users\Katrin\Desktop\fotos papa netz
[2011.01.13 20:40:05 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll
[2011.01.13 20:39:59 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
[2010.09.14 19:44:44 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxczserv.dll
[2010.09.14 19:44:44 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxczusb1.dll
[2010.09.14 19:44:44 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxczinpa.dll
[2010.09.14 19:44:44 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxcziesc.dll
[2010.09.14 19:44:44 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXCZhcp.dll
[2010.09.14 19:44:43 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxczpmui.dll
[2010.09.14 19:44:43 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxczlmpm.dll
[2010.09.14 19:44:43 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxczprox.dll
[2010.09.14 19:44:43 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxczpplc.dll
[2010.09.14 19:44:42 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxczhbn3.dll
[2010.09.14 19:44:42 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxczcomc.dll
[2010.09.14 19:44:42 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxczcomm.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011.02.08 22:50:23 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Katrin\Desktop\OTL.exe
[2011.02.08 22:46:53 | 000,623,280 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.02.08 22:46:53 | 000,591,320 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.02.08 22:46:53 | 000,125,378 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.02.08 22:46:53 | 000,103,194 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.02.08 22:40:36 | 000,070,046 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011.02.08 22:40:08 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.02.08 22:40:08 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.02.08 22:39:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.02.08 22:39:54 | 1878,093,824 | -HS- | M] () -- C:\hiberfil.sys
[2011.02.08 22:35:09 | 000,003,547 | ---- | M] () -- C:\Users\Katrin\Desktop\log malwarebytes
[2011.02.08 20:45:26 | 000,000,828 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.02.08 20:04:51 | 000,138,234 | ---- | M] () -- C:\Users\Katrin\Desktop\meldung antivir.png
[2011.02.07 20:44:00 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.01.22 15:00:32 | 000,136,825 | ---- | M] () -- C:\Users\Katrin\Desktop\snack gutschein.pdf
[2011.01.18 19:20:11 | 000,037,888 | ---- | M] () -- C:\Users\Katrin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011.02.08 22:35:09 | 000,003,547 | ---- | C] () -- C:\Users\Katrin\Desktop\log malwarebytes
[2011.02.08 20:45:26 | 000,000,828 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.02.08 20:04:50 | 000,138,234 | ---- | C] () -- C:\Users\Katrin\Desktop\meldung antivir.png
[2011.02.07 20:44:00 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011.01.22 15:00:32 | 000,136,825 | ---- | C] () -- C:\Users\Katrin\Desktop\snack gutschein.pdf
[2010.11.13 14:25:58 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010.11.13 14:25:58 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.09.14 19:47:50 | 000,000,108 | ---- | C] () -- C:\Windows\Lexstat.ini
[2010.09.14 19:44:44 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxczutil.dll
[2010.09.14 19:44:44 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXCZinst.dll
[2010.03.18 20:13:22 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2009.09.22 20:01:36 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2009.06.18 12:32:23 | 000,000,137 | ---- | C] () -- C:\Windows\ETOSP.INI
[2009.03.03 21:25:22 | 000,024,206 | ---- | C] () -- C:\Users\Katrin\AppData\Roaming\UserTile.png
[2009.02.18 22:05:40 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.01.24 13:22:03 | 000,000,512 | ---- | C] () -- C:\Windows\ODBC.INI
[2009.01.03 15:02:35 | 000,000,097 | ---- | C] () -- C:\Windows\WirelessFTP.INI
[2009.01.02 23:55:23 | 000,037,888 | ---- | C] () -- C:\Users\Katrin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.01.02 22:56:10 | 000,031,616 | ---- | C] () -- C:\Windows\System32\drivers\RLVrtAuCbl.sys
[2008.10.07 14:47:45 | 000,000,000 | ---- | C] () -- C:\Windows\tosOBEX.INI
[2008.10.07 12:42:06 | 001,748,352 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
[2008.10.07 12:42:06 | 000,028,672 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys
[2008.10.07 12:32:45 | 000,070,046 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008.10.07 12:23:04 | 000,070,046 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2007.12.22 00:46:32 | 000,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2007.10.25 17:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007.02.07 17:58:12 | 000,039,899 | ---- | C] () -- C:\Windows\System32\rtsicis.ini
[2007.01.22 08:49:34 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxczcoin.dll
[2006.11.02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.06.07 13:23:04 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxczcnv7.dll
[2006.03.27 11:19:14 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxczvs.dll
[2006.03.07 11:59:04 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxczcnv6.dll
[2006.01.10 17:11:06 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxczcnv5.dll
[2006.01.10 17:11:06 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxczcnv4.dll
[2005.07.23 05:30:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
 
< End of report >
         
--- --- ---

[/CODE]

Extras.txt
OTL Logfile:
Code:
ATTFilter
OTL Extras logfile created on: 08.02.2011 22:51:22 - Run 1
OTL by OldTimer - Version 3.2.20.6     Folder = C:\Users\Katrin\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 40,00% Memory free
4,00 Gb Paging File | 2,00 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 43,95 Gb Total Space | 5,14 Gb Free Space | 11,71% Space Free | Partition Type: NTFS
Drive D: | 97,29 Gb Total Space | 72,49 Gb Free Space | 74,51% Space Free | Partition Type: NTFS
 
Computer Name: NB-KATRIN | User Name: Katrin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.txt [@ = txtfile] -- C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe (Just Great Software)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0015C17C-40D9-46DB-A64B-477C7698CFF3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | 
"{080658B8-2634-4FE3-914D-9DD2F6C5AA41}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{165F4079-3EB7-47AF-B970-DB97DD03CDE7}" = lport=139 | protocol=6 | dir=in | app=system | 
"{16E33255-4511-4833-B441-7856FB29B787}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{1E594057-ACBA-476B-AD6D-966837AA65C5}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{217EF49C-ECEF-43A1-BC59-91DEBAB3EC2C}" = lport=138 | protocol=17 | dir=in | app=system | 
"{24F04A07-3510-4E1C-9DB4-3EF0DDC03085}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{30B9DE04-0EE0-4617-85B8-DD1CE7425F21}" = rport=139 | protocol=6 | dir=out | app=system | 
"{32B4AEDC-9FFC-4BA9-9D03-1047F2B5BD34}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{3836FA40-6471-4479-BE07-5576C96659CF}" = lport=137 | protocol=17 | dir=in | app=system | 
"{399C4791-4566-47FA-8296-B85254F1FAF5}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | 
"{42AFA43A-AB46-4197-AD8A-A8781BF55790}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{45483517-117E-476F-88AE-4130E7568EF7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{492FCC48-7400-4E18-BF21-717BEF49A838}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | 
"{4ADA75A8-E20C-4012-83FF-822B56D6706F}" = rport=445 | protocol=6 | dir=out | app=system | 
"{4C146043-0C55-40E4-9230-E3A78BA956FC}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{4D17B220-17F4-4FC4-A6D3-5327AD423FEB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{5C3C2CCA-1407-4C3A-A392-1C6C7BAC7F74}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{74BFCE68-0330-4F05-863A-4E92A4DD214B}" = rport=138 | protocol=17 | dir=out | app=system | 
"{79BFC481-DBD7-4B22-B923-9B71945D1031}" = lport=445 | protocol=6 | dir=in | app=system | 
"{920CE57A-0A86-44AA-A896-012A1AD2745C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{96465393-D552-4FD6-A9C5-B7945EF4BCF4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{9D7572A1-B66B-4B40-A201-3CA3F6AFB033}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | 
"{A49A409E-90A0-41F3-9856-8411C0A9DA81}" = rport=2869 | protocol=6 | dir=out | app=system | 
"{A6DC8519-D3BD-4334-B338-51F17D9BBE32}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{AA66E02B-1D78-4E64-96B4-3B568D65954E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{AFE8A460-DD21-4B9F-9C5F-5BF0A3078EB1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | 
"{B628B289-ECA2-442D-A515-DE0C46E2CE17}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{BE3CFCD4-AD06-42A3-9E8E-61B6C478D3A3}" = rport=137 | protocol=17 | dir=out | app=system | 
"{C0076FF7-8B92-4468-8D11-1D9E3A1AB599}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{C16ADE55-3289-43DF-8F5E-2F5557D78C0A}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{C3D9B5F2-7B96-4421-B107-9D1E4B237C13}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{CBB7C140-7688-46EC-BBD5-8521F667AAA6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | 
"{D9AD899A-43DE-482A-B63D-7B7AE27EC109}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{FA00AD1C-BF56-45E4-B238-1AC5D55B4995}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04759288-F136-4DA9-9C7E-C46F28B5FD24}" = protocol=6 | dir=out | app=system | 
"{06FBC27B-0B86-471D-9958-84C9BB940E0B}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | 
"{1109360E-5BDA-4CFB-BFD7-8810B888C752}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | 
"{18E1CB6D-5406-4726-9BFD-B4BCB49A2B75}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{1A033A39-AD3C-457E-B0A9-C0493144ADC2}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | 
"{20B3A8C0-E3C7-43DC-9002-2B0E84A6BE73}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | 
"{289871BC-503B-43D6-B6EA-872EC34EE209}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe | 
"{2944FB8B-0FF8-40DA-84D3-5A41B2F4C4DD}" = protocol=17 | dir=in | app=c:\windows\system32\lxczcoms.exe | 
"{3DBCB800-B280-47E0-847F-396409277D67}" = protocol=17 | dir=in | app=c:\program files\avira\antivir personaledition classic\avnotify.exe | 
"{3F899980-86EB-4B59-87BD-01C5E1B1DD80}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | 
"{40B9E581-271B-42CC-89AD-CE9C9A984918}" = protocol=6 | dir=in | app=c:\program files\avira\antivir personaledition classic\update.exe | 
"{449D1856-D14E-4C22-9409-840B008DC42B}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | 
"{451B6642-B292-4986-9907-6E3D08BC45CF}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | 
"{586B14F3-E6CD-4591-ACA4-26D5AEFAB776}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{5CCA3850-86C8-452F-A387-F69AE1755100}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe | 
"{5D065818-5C31-448D-B6BD-D1AD69D6545B}" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\eccenter1.exe | 
"{5E56EBF8-2BC5-4423-99E8-314679C0799A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{632115F2-D1C3-43A3-89AC-3F1A8D495213}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe | 
"{64FDB81C-D43E-43B0-92BA-B01441A1F37B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{6D25EFAD-98C6-4170-BCA0-88F3227C07D5}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe | 
"{747F1DEC-FBD1-4564-91EF-8D6D327606CE}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe | 
"{780335F0-723E-42E6-B4F4-E4F3CF4B68D8}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxczpswx.exe | 
"{7B12C88F-977D-4FD4-B3B5-87ACE5C0540C}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | 
"{7DC73998-3D41-4B33-84EC-E563C429B146}" = protocol=6 | dir=in | app=c:\windows\system32\lxczcoms.exe | 
"{7EDB033B-9D8F-463D-A483-DBC4BFA7B8DD}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{7F6176A1-0CA0-4BC9-8E26-BB38EBEDF307}" = protocol=17 | dir=in | app=c:\program files\icq7.1\aolload.exe | 
"{822E73FE-8E53-4FE1-A5C1-D096C12B8121}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | 
"{92F2EEEC-8CF4-4E04-8986-203509B9D1FD}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxczpswx.exe | 
"{97E420B6-6C02-44D1-8DEF-A3A9F6DCA64B}" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe | 
"{A2073916-FA5C-4523-B40F-6F3E1FA48DCF}" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe | 
"{B5DF57F9-00D6-45C3-8382-488BBDD8FF34}" = protocol=6 | dir=in | app=c:\program files\avira\antivir personaledition classic\avcenter.exe | 
"{BA48AF5C-C5B8-4706-9E0D-84FA701FF978}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{C50CDF52-A70A-45D5-8FF8-07EFFFF707AB}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | 
"{CA11BE99-3ABD-44A5-9BF8-E2DFE0786288}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe | 
"{CA66661C-2EC9-40F5-B492-DCDF43DE28F3}" = protocol=6 | dir=in | app=c:\program files\avira\antivir personaledition classic\avnotify.exe | 
"{D377CD3B-7E13-457C-B08C-1619FE1DD65D}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | 
"{D4C31A13-EEBF-4A59-8FC3-2440B1E4DAA4}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{D6F94DF4-3FDD-4BEF-97A6-B469471A425A}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | 
"{D777E59C-F3CC-4B15-99F2-8049821472D6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{D8FBAF93-471C-4DA6-84BF-9AB0366B5266}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | 
"{E27B6EB3-45E3-488C-BDCA-AA229A551133}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | 
"{E325B64F-FFC6-4608-9267-646495B7C6AA}" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\eccenter1.exe | 
"{E589C28E-BAEA-44AF-AE2A-AC0B9EF10CD1}" = protocol=17 | dir=in | app=c:\program files\avira\antivir personaledition classic\update.exe | 
"{F3442F37-62F6-4AC1-ABB2-9928B12194A0}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe | 
"{F5327B6E-BB20-468B-BCB4-3041B9EFD894}" = protocol=6 | dir=in | app=c:\program files\icq7.1\aolload.exe | 
"{F96BBD54-567C-4C05-8548-D9302784C005}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe | 
"{FCF58D36-969C-4AB5-808E-121DAB18633D}" = protocol=17 | dir=in | app=c:\program files\avira\antivir personaledition classic\avcenter.exe | 
"TCP Query User{05CFB29F-9DD4-4755-8966-BBA0B051FBB2}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | 
"TCP Query User{D82CBB3F-2F40-491D-AD36-BD676CE578FB}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe | 
"TCP Query User{EC267F92-42AA-414B-8DAA-A08573A7675A}C:\program files\icq7.1\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq7.1\icq.exe | 
"UDP Query User{2E47B4AD-3EBC-4281-94D5-672646663C52}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | 
"UDP Query User{86911C66-2EC8-49C8-A5DC-3E5418464715}C:\program files\icq7.1\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq7.1\icq.exe | 
"UDP Query User{9FF73C40-24BC-41CC-9746-CC5E4F5E8A65}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{04B45310-A5FE-4425-BFCA-1A6D8920DE74}" = OpenOffice.org 3.0
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07690F1C-04B1-4060-9691-6748ED1826B9}" = MSI Software Install
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}" = BurnRecovery
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = USB 2.0 Camera
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4EA2F95F-A537-4d17-9E7F-6B3FF8D9BBE3}" = Microsoft Works
"{4EF8BE6A-899C-4196-94E7-297C5F7A203E}" = pdfforge Toolbar v1.1.1
"{542068F1-9AAE-4E1B-8ACA-094FE03728BE}" = Carambis Driver Updater
"{59C4F14F-7590-45FC-BE9F-A67AB3590709}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3BE3F1E-2472-4211-8735-E8239BE49D9F}" = Ulead Burn.Now 4.5
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}" = WinZip 11.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D1504C77-1B19-4AF0-8DEC-946666123B55}" = CrazyTalk Cam Suite
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{ED9C5D25-55DF-48D8-9328-2AC0D75DE5D8}" = System Control Manager
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD0}" = Paint.NET v3.5.5
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"5D38134BF8A10D640B30E6B014EECDBC5F881E3D" = Windows Driver Package - ENE (enecir) HIDClass  (04/29/2008 2.5.0.0)
"7-Zip" = 7-Zip 9.20
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CDex" = CDex extraction audio
"EditPad Lite" = Just Great Software EditPad Lite 6.4.3
"FileZilla Client" = FileZilla Client 3.3.2.1
"Greenshot_is1" = Greenshot
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{59C4F14F-7590-45FC-BE9F-A67AB3590709}" = iTunes
"InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"InstallShield_{A3BE3F1E-2472-4211-8735-E8239BE49D9F}" = Ulead Burn.Now 4.5 SE
"InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"JDiskReport 1.3.2" = JGoodies JDiskReport 1.3.2
"Lexmark 1200 Series" = Lexmark 1200 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Mozilla Firefox (3.0.4)" = Mozilla Firefox (3.0.4)
"Mozilla Thunderbird (3.1.7)" = Mozilla Thunderbird (3.1.7)
"NVIDIA Drivers" = NVIDIA Drivers
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinRAR archiver" = WinRAR Archivierer
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 05.12.2010 09:32:42 | Computer Name = nb-katrin | Source = WinMgmt | ID = 10
Description = 
 
Error - 05.12.2010 15:35:52 | Computer Name = nb-katrin | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 05.12.2010 15:35:52 | Computer Name = nb-katrin | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 05.12.2010 15:36:00 | Computer Name = nb-katrin | Source = WinMgmt | ID = 10
Description = 
 
Error - 07.12.2010 13:58:31 | Computer Name = nb-katrin | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 07.12.2010 13:58:31 | Computer Name = nb-katrin | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 07.12.2010 13:59:50 | Computer Name = nb-katrin | Source = WinMgmt | ID = 10
Description = 
 
Error - 08.12.2010 14:30:29 | Computer Name = nb-katrin | Source = WinMgmt | ID = 10
Description = 
 
Error - 08.12.2010 14:30:35 | Computer Name = nb-katrin | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
Error - 08.12.2010 14:30:35 | Computer Name = nb-katrin | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description = 
 
[ System Events ]
Error - 06.02.2011 12:45:41 | Computer Name = nb-katrin | Source = netbt | ID = 4321
Description = Der Name "NB-KATRIN      :20" konnte nicht auf der Schnittstelle mit
 IP-Adresse 192.168.2.101  registriert werden. Der Computer mit IP-Adresse 169.254.212.160
 hat nicht  zugelassen, dass dieser Computer diesen Namen verwendet.
 
Error - 06.02.2011 13:17:56 | Computer Name = nb-katrin | Source = ipnathlp | ID = 31004
Description = 0 Bytes Speicher konnten durch den DNS-Proxy-Agenten nicht zugeordnet
 werden. Möglicherweise ist nicht genügend Speicher vorhanden oder ein interner 
Fehler ist im Speicher-Manager aufgetreten.
 
Error - 07.02.2011 14:12:51 | Computer Name = nb-katrin | Source = HTTP | ID = 15016
Description = 
 
Error - 07.02.2011 14:12:52 | Computer Name = nb-katrin | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = 
 
Error - 07.02.2011 17:09:30 | Computer Name = nb-katrin | Source = HTTP | ID = 15016
Description = 
 
Error - 07.02.2011 17:09:30 | Computer Name = nb-katrin | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = 
 
Error - 08.02.2011 13:35:21 | Computer Name = nb-katrin | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = 
 
Error - 08.02.2011 13:35:21 | Computer Name = nb-katrin | Source = HTTP | ID = 15016
Description = 
 
Error - 08.02.2011 17:40:03 | Computer Name = nb-katrin | Source = HTTP | ID = 15016
Description = 
 
Error - 08.02.2011 17:40:04 | Computer Name = nb-katrin | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = 
 
 
< End of report >
         
--- --- ---

[/CODE]

Hoffe das hilft euch einigermaßen weiter, ich habe die Quarantäne jetzt noch nicht gelöscht - weder bei Antivir noch bei Malware.

Viele Grüße und gute Nacht
Katti

Hallo zusammen,

leider hat mir noch keiner geantwortet - ist der Trojaner so unbedeutend?
Wäre nett wenn ihr mir eine Info geben würdet, ich weiß echt nicht was ich damit jetzt machen soll ohne den Laptop neu aufzusetzen....

Danke!!!!
Angehängte Grafiken
Dateityp: png meldung antivir.png (135,0 KB, 249x aufgerufen)

 

Themen zu Antivir hat den Trojaner TR/Shakat.o.566 gefunden
abend, adware.widgitoolbar, anhang, antivir, audacity, ausser, avgntflt.sys, checken, cookies, corp./icp, datei, einfach, gestern, glaube, hallo zusammen, home premium, ieframe.dll, infos, install.exe, ip-adresse, laptop, location, löschen, malware bytes, mozilla thunderbird, nvlddmkm.sys, nvstor.sys, oldtimer, pdfforge toolbar, plug-in, programdata, quarantäne, saver, sched.exe, screenshot, searchplugins, shell32.dll, shortcut, skype.exe, start menu, studio, superantispyware, system, troja, trojaner, usb 2.0, vista, windows, windows vista, zusammen




Ähnliche Themen: Antivir hat den Trojaner TR/Shakat.o.566 gefunden


  1. Mehrere Trojaner gefunden von AntiVir
    Log-Analyse und Auswertung - 12.03.2012 (9)
  2. TR/Shakat.o.909 von Avira Antivir in A0050266.exe gefunden!
    Log-Analyse und Auswertung - 18.11.2011 (6)
  3. TR/Shakat.o.909
    Plagegeister aller Art und deren Bekämpfung - 14.11.2011 (4)
  4. antivir hat trojaner gefunden
    Plagegeister aller Art und deren Bekämpfung - 22.09.2011 (41)
  5. TR/Shakat.o.300 von AntiVir erkannt, AdWords Anzeigen werden gehijackt
    Plagegeister aller Art und deren Bekämpfung - 21.02.2011 (22)
  6. Trojaner gefunden mit Avira AntiVir
    Plagegeister aller Art und deren Bekämpfung - 19.04.2010 (4)
  7. Trojaner TR/Crypt.FKM.Gen von Antivir gefunden
    Log-Analyse und Auswertung - 19.03.2010 (1)
  8. AntiVir/AVG/HJT haben Trojaner gefunden?
    Log-Analyse und Auswertung - 21.09.2009 (4)
  9. Trojaner ZPack.Gen gefunden von Antivir
    Plagegeister aller Art und deren Bekämpfung - 17.07.2009 (25)
  10. Trojaner TR/Crypt.FKM.Gen nur von Antivir gefunden
    Log-Analyse und Auswertung - 15.07.2009 (19)
  11. Hilfe Trojaner bei Antivir gefunden
    Plagegeister aller Art und deren Bekämpfung - 28.04.2009 (0)
  12. AntiVir hat Trojaner gefunden-TR/Dropper.Gen
    Log-Analyse und Auswertung - 19.04.2009 (13)
  13. Trojaner von Avira AntiVir gefunden
    Log-Analyse und Auswertung - 05.12.2008 (2)
  14. (b)Trojaner mit AntiVir gefunden(/b)
    Mülltonne - 01.11.2008 (0)
  15. AntiVir hat den Trojaner TR/Small.ben.2 gefunden
    Plagegeister aller Art und deren Bekämpfung - 01.10.2008 (2)
  16. Trojaner von Antivir gefunden
    Log-Analyse und Auswertung - 04.09.2008 (2)
  17. AntiVir Trojaner/Virus gefunden - was nun?
    Plagegeister aller Art und deren Bekämpfung - 01.02.2008 (14)

Zum Thema Antivir hat den Trojaner TR/Shakat.o.566 gefunden - Hallo zusammen, Antivir hat auf meinem Laptop (Windows Vista) gestern abend den Trojaner "TR/Shakat.o.566" gefunden diesen hab ich dann in Quarantäne verschoben. Im Anhang ein Screenshot von der Quarantäne-Verwaltung in - Antivir hat den Trojaner TR/Shakat.o.566 gefunden...
Archiv
Du betrachtest: Antivir hat den Trojaner TR/Shakat.o.566 gefunden auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.