Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: iexplore.exe 3-mal im Task-Manager

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 25.06.2010, 14:15   #1
LP - Fan
 
iexplore.exe 3-mal im Task-Manager - Standard

iexplore.exe 3-mal im Task-Manager



Guten Tag...

Ich habe seit 2 Tagen das Problem das 2-3 mal die iexplore.exe in meinem Task-Manager auftritt und wenn ich sie beende, sie nach kurzer Zeit wieder da ist...

Ausserdem ist mir aufgefallen das die Exe Dateien "smss.exe" & "services.exe" jeweils doppelt vorkommen.

Ich habe mit CCleaner & Malwarebytes' Anti-Malware alles gestern gereinigt, aber dennoch ist heute wieder die iexplore.exe mehrere male vorhanden...

Ich arbeite ausschliesslich mit dem Mozilla Firefox und benutze den IE nur für Windows updates...

Ausserdem habe ich das Problem wenn ich Musik höre das nach ca. 1 Minute kein Ton mehr da ist und ich bei "Lautstärkeregelung" -> "Wave" den Regler wieder nach oben ziehen muss, aber das müsste ich jede Minute machen, da der Regler sich "automatisch" wieder auf Null setzt...

Bevor ich die iexplore.exe durch die firewall geblockt hatte, kam eine Audio Werbung von einer Waschmittelmarke, was ich sehr seltsam fand und bemerkte darauf hin die mehreren iexplore.exe'n...

Hier nun die Logs von RSIT:

Code:
ATTFilter
logfile of random's system information tool 1.06 2010-06-25 23:52:44

======Uninstall list======

-->C:\Programme\Verschiedenes\Speed2_burnR_mxcdr\unwise.exe
-->C:\WINXP\system32\Macromed\Flash\uninstall_plugin.exe
-->MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINXP\INF\PCHealth.inf
7-Zip 4.65-->"C:\Programme\Verschiedenes\7-Zip\Uninstall.exe"
Acrobat.com-->msiexec /qb /x {C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}
Acrobat.com-->MsiExec.exe /I{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}
Adobe Acrobat 9 Pro - English, Français, Deutsch-->msiexec /I {AC76BA86-1033-F400-7760-000000000004}
Adobe After Effects CS4 Presets-->MsiExec.exe /I{44E240EC-2224-4078-A88B-2CEE0D3016EF}
Adobe After Effects CS4 Third Party Content-->MsiExec.exe /I{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
Adobe After Effects CS4-->MsiExec.exe /I{45EC816C-0771-4C14-AE6D-72D1B578F4C8}
Adobe AIR-->C:\Programme\Gemeinsame Dateien\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
Adobe Asset Services CS4-->MsiExec.exe /I{B9F4561A-924D-4510-A85A-BB0960C338CB}
Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Adobe Color EU Recommended Settings CS4-->MsiExec.exe /I{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}
Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
Adobe Color NA Extra Settings CS4-->MsiExec.exe /I{098A2A49-7CF3-4F08-A38D-FB879117152A}
Adobe Color Video Profiles AE CS4-->MsiExec.exe /I{B15381DD-FF97-4FCD-A881-ED4DB0975500}
Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
Adobe Contribute CS4-->MsiExec.exe /I{A6EC82A0-1414-475D-8AFD-469089F3080D}
Adobe Creative Suite 4 Master Collection-->C:\Programme\Gemeinsame Dateien\Adobe\Installers\b2d6abde968e6f277ddbfd501383e02\Setup.exe --uninstall=1
Adobe Creative Suite 4 Master Collection-->MsiExec.exe /I{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}
Adobe CS4 American English Speech Analysis Models-->MsiExec.exe /I{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}
Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}
Adobe Dreamweaver CS4-->MsiExec.exe /I{30C8AA56-4088-426F-91D1-0EDFD3A25678}
Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C}
Adobe Dynamiclink Support-->MsiExec.exe /I{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}
Adobe Encore CS4 Codecs-->MsiExec.exe /I{FB2A5FCC-B81B-48C2-A009-7804694D83E9}
Adobe Encore CS4-->MsiExec.exe /I{5EAD5443-7194-46CC-A055-428E6ABB1BAF}
Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
Adobe Fireworks CS4-->MsiExec.exe /I{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}
Adobe Flash CS4 Extension - Flash Lite STI others-->MsiExec.exe /I{47C6F987-685A-41AE-B092-E75B277AEE39}
Adobe Flash CS4 STI-other-->MsiExec.exe /I{BD3374D3-C2E6-42B7-A80B-E850B6886246}
Adobe Flash CS4-->MsiExec.exe /I{F6E99614-F042-4459-82B7-8B38B2601356}
Adobe Flash Player 10 ActiveX-->C:\WINXP\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 ActiveX-->MsiExec.exe /X{3A6829EF-0791-4FDD-9382-C690DD0821B9}
Adobe Flash Player 10 Plugin-->MsiExec.exe /X{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}
Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
Adobe Illustrator CS4-->MsiExec.exe /I{87532CAB-7932-4F84-8937-823337622807}
Adobe InDesign CS4 Application Feature Set Files (Roman)-->MsiExec.exe /I{2BAF2B96-7560-48B4-87D4-10178DDBE217}
Adobe InDesign CS4 Common Base Files-->MsiExec.exe /I{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}
Adobe InDesign CS4 Icon Handler-->MsiExec.exe /I{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}
Adobe InDesign CS4-->MsiExec.exe /I{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}
Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
Adobe Media Encoder CS4 Additional Exporter-->MsiExec.exe /I{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}
Adobe Media Encoder CS4 Dolby-->MsiExec.exe /I{EE353798-E875-42E0-B58D-7E6696182EA8}
Adobe Media Encoder CS4 Exporter-->MsiExec.exe /I{561968FD-56A1-49FD-9ED0-F55482C7C5BC}
Adobe Media Encoder CS4 Importer-->MsiExec.exe /I{8186FF34-D389-4B7E-9A2F-C197585BCFBD}
Adobe Media Encoder CS4-->MsiExec.exe /I{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}
Adobe Media Player-->msiexec /qb /x {39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe MotionPicture Color Files CS4-->MsiExec.exe /I{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}
Adobe OnLocation CS4-->MsiExec.exe /I{7406DF60-016D-476B-A2C7-55D997592047}
Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
Adobe Premiere Pro CS4 Functional Content-->MsiExec.exe /I{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}
Adobe Premiere Pro CS4 Third Party Content-->MsiExec.exe /I{C938BE91-3BB5-4B84-9EF6-88F0505D0038}
Adobe Premiere Pro CS4-->MsiExec.exe /I{D499F8DE-3F31-4900-9157-61061613704B}
Adobe Reader 9.3.2 - Deutsch-->MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A93000000001}
Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
Adobe Setup-->MsiExec.exe /I{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}
Adobe SGM CS4-->MsiExec.exe /I{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}
Adobe Shockwave Player 11.5-->"C:\WINXP\system32\Adobe\Shockwave 11\uninstaller.exe"
Adobe SING CS4-->MsiExec.exe /I{4A52555C-032A-4083-BDD9-6A85ABFB39A8}
Adobe Soundbooth CS4 Codecs-->MsiExec.exe /I{52232EF4-CC12-4C21-ABCF-ADB79618302D}
Adobe Soundbooth CS4-->MsiExec.exe /I{14F70205-1940-4000-88C7-BE799A6B2CAD}
Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
Adobe Version Cue CS4 Server-->MsiExec.exe /I{1B7C06E1-4888-47A6-992A-0990B9683486}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
aerosoft's - AES-Base&&AirportPack  - FS2004-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{20A96613-3802-436C-842E-653C62FABA0D}\Setup.exe"  -uninst 
aerosoft's - German Aiports 4 - Version 3.2 Update - FS2004-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{2B0000B7-89C7-49FD-B9CC-139CA2456822}\Setup.exe"  -uninst 
aerosoft's - German Airports 2 X - FS2004-->C:\Programme\InstallShield Installation Information\{0705EEB6-2F15-4D19-B37D-84C953E93D18}\setup.exe -runfromtemp -l0x0007 -removeonly
aerosoft's - German Airports 3 - FS2004-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{ECE1939E-3491-409E-87B7-E7DF65E7B909}\Setup.exe"  -uninst 
aerosoft's - German Airports 4 - FS2004-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{674D3526-6B4F-468A-9802-1130A39B1562}\Setup.exe"  -uninst 
aerosoft's - German Football Stadiums - FS2004-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{3CDBA499-FB8B-4FFC-A374-F5AA59AB534D}\Setup.exe"  -uninst 
aerosoft's - Lissabon 2008-->C:\Programme\InstallShield Installation Information\{4C4494AC-E3E4-4675-8973-1B6403429C02}\setup.exe -runfromtemp -l0x0007 -uninst -removeonly
aerosoft's - London Heathrow 2008-->C:\Programme\InstallShield Installation Information\{C0A6901F-C919-47A3-A4D9-E2056314086B}\setup.exe -runfromtemp -l0x0007 -uninst -removeonly
aerosoft's - Madrid 2008-->C:\Programme\InstallShield Installation Information\{0FC39141-1BB8-4C29-9D74-A6710131B74F}\setup.exe -runfromtemp -l0x0007 -uninst -removeonly
aerosoft's - Mega Airport Frankfurt - FS2004-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{34BDC9DA-9320-491C-AA40-B0D98A0EBA9C}\Setup.exe"  -uninst 
aerosoft's - Mega Airport Paris CDG-->C:\Programme\InstallShield Installation Information\{51D199F4-5593-4BC9-B2A5-BB1CDE0C894A}\setup.exe -runfromtemp -l0x0007 -removeonly
ASIO4ALL-->C:\Programme\Hardware\ASIO4ALL v2\uninstall.exe
Assassin's Creed II-->"C:\Spiele\Steam\steam.exe" steam://uninstall/33230
AT&T Natural Voices Audrey v. 1.4-->"C:\Programme\Verschiedenes\AT&T Natural Voices\data\en_uk\Audrey\unins000.exe"
AT&T Natural Voices Crystal v. 1.4-->"C:\Programme\Verschiedenes\AT&T Natural Voices\data\en_us\Crystal\unins000.exe"
AT&T Natural Voices Mike v. 1.4-->"C:\Programme\Verschiedenes\AT&T Natural Voices\data\en_us\Mike\unins000.exe"
ATI - Dienstprogramm zur Deinstallation der Software-->C:\Programme\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0 
ATI Display Driver-->rundll32 C:\WINXP\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Avira AntiVir Personal - Free Antivirus-->C:\Programme\Sicherheit\Avira\AntiVir Desktop\setup.exe /REMOVE
Bus Driver Gold 1.1 -->C:\WINXP\uninstall\Bus Driver Gold\setup.exe
CamStudio-->C:\Programme\CamStudio\uninstall.exe
Canon iP4600 series Printer Driver-->"C:\WINXP\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4600_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4600_series /L0x0007
Canon Utilities My Printer-->C:\Programme\Canon\MyPrinter\uninst.exe uninst.ini
Catalyst Control Center - Branding-->MsiExec.exe /I{D9D93D74-107D-4BD3-87D0-AABCF7C98BD5}
CCleaner-->"C:\Programme\Sicherheit\CCleaner\uninst.exe"
CDBurnerXP-->"C:\Programme\Brennsoftware\CDBurnerXP\unins000.exe"
Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
ConvertHelper 2.2-->"C:\Programme\Verschiedenes\ConvertHelper\unins000.exe"
Dev-C++ 5 beta 9 release (4.9.9.2)-->"C:\Programme\Verschiedenes\Dev-Cpp\uninstall.exe"
Die Sims™ 3 Luxus-Accessoires-->"C:\Programme\InstallShield Installation Information\{71828142-5A24-4BD0-97E7-976DA08CE6CF}\setup.exe" -runfromtemp -l0x0007 -removeonly
Die Sims™ 3 Reiseabenteuer-->"C:\Programme\InstallShield Installation Information\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}\setup.exe" -runfromtemp -l0x0007 -removeonly
Die Sims™ 3 Traumkarrieren-->"C:\Programme\InstallShield Installation Information\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}\Sims3EP02Setup.exe" -runfromtemp -l0x0007 -removeonly
Die Sims™ 3-->"C:\Programme\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\setup.exe" -runfromtemp -l0x0007 -removeonly
DiRT2-->"C:\Programme\InstallShield Installation Information\{52D1D62C-FEAB-4580-849E-1DB624BADBBD}\setup.exe" -runfromtemp -l0x0007 -removeonly
DiRT2-->MsiExec.exe /I{434D0820-3AA6-493A-80B9-301000028501}
DivX Plus Web Player-->C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DivX\DivX7\DivX Web Player\DivXWebPlayerUninstall.exe /PLUGIN
DivX-Setup-->C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
Dual-Core Optimizer-->MsiExec.exe /X{9FD6F1A8-5550-46AF-8509-271DF0E768B5}
EditVoicepack-->MsiExec.exe /I{1EC65D1D-3911-4F7D-8B6A-63C69EDBFC6E}
FL Studio 8-->C:\Programme\Verschiedenes\FL Studio 8\uninstall.exe
FL Studio 9-->C:\Programme\Verschiedenes\FL Studio 9\uninstall.exe
Flight Environment-->C:\Spiele\Microsoft Flight Simulator 2004\UnFE2004.exe
Fraps (remove only)-->"C:\Spiele\Zubehör\Fraps\uninstall.exe"
Free MKV Video2Dvd 3.12-->"C:\Programme\Free MKV Video2Dvd\unins000.exe"
FSFDT FSCopilot-->C:\Spiele\Zubehör\FS2004 Copilot 1.6\uninstallFSCopilot.exe
Grand Theft Auto IV-->"C:\Programme\InstallShield Installation Information\{579BA58C-F33D-4970-9953-B94B43768AC3}\setup.exe" -runfromtemp -l0x0007 -removeonly
Grand Theft Auto IV-->MsiExec.exe /I{5454083B-1308-4485-BF17-1110000B8301}
Grand Theft Auto: Episodes From Liberty City-->"C:\Programme\InstallShield Installation Information\{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}\setup.exe" -runfromtemp -l0x0007 -removeonly
Grand Theft Auto: Episodes from Liberty City-->MsiExec.exe /I{5454083B-1308-4485-BF17-111000028701}
GRID-->"C:\Programme\InstallShield Installation Information\{5A0B7BA5-4682-4273-81C2-69B17E649103}\setup.exe" -runfromtemp -l0x0007 -removeonly
Hardcore-->C:\Programme\Verschiedenes\FL Plugins\Hardcore\uninstall.exe
HD Tune Pro 4.01-->"C:\Programme\Hardware\HD Tune Pro\unins000.exe"
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINXP\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall  /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINXP\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix für Windows XP (KB942288-v3)-->"C:\WINXP\$NtUninstallKB942288-v3$\spuninst\spuninst.exe"
Hotfix für Windows XP (KB979306)-->"C:\WINXP\$NtUninstallKB979306$\spuninst\spuninst.exe"
Hotfix für Windows XP (KB981793)-->"C:\WINXP\$NtUninstallKB981793$\spuninst\spuninst.exe"
Hydra VSTi/DXi v1.2-->C:\Programme\Verschiedenes\VSTPlugins\Hydra\unins000.exe
ICQ 6.5 Build #2024 Banner Remover 1.0-->"C:\Programme\Internet\ICQ-Banner-Remover\unins000.exe"
ICQ Away Reader 1.4-->"C:\Programme\Internet\ICQ Away Reader\unins000.exe"
ICQ6.5-->"C:\Programme\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
IL Autogun-->C:\Programme\Verschiedenes\FL Plugins\IL Autogun\uninstall.exe
IL Gross Beat-->C:\Programme\Verschiedenes\FL Plugins\IL Gross Beat\uninstall.exe
IL Ogun-->C:\Programme\Verschiedenes\FL Plugins\IL Ogun\uninstall.exe
IL Vocodex-->C:\Programme\Verschiedenes\FL Plugins\IL Vocodex\uninstall.exe
IrfanView (remove only)-->C:\Programme\Verschiedenes\IrfanView\iv_uninstall.exe
iZotope Ozone 4-->"C:\Programme\Verschiedenes\FL Plugins\Ozone 4\unins000.exe"
Java(TM) 6 Update 18-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216018FF}
Java(TM) SE Development Kit 6 Update 18-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160180}
JCreator LE 4.50-->"C:\Programme\Verschiedenes\JCreatorV4LE\unins000.exe"
Joboshare AVI to DVD Converter-->C:\Programme\Joboshare\AVI to DVD Converter\Uninstall.exe
Just Flight Traffic 2005 v1.00-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{F4E07A79-CB8F-43AC-882C-F7542856D573}\setup.exe" -l0x7 
kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
LUXONIX LFX-1310-->"C:\WINXP\IFinst27.exe" -UC:\Programme\Verschiedenes\VSTPlugins\Vstplugins\IFU15B.inf
MAGIX 3D Maker (embeded)-->C:\Programme\Verschiedenes\Common\3D_Maker_embeded\unwise.exe
MAGIX Video deluxe 15 Premium 8.0.0.62 (D)-->C:\Programme\Verschiedenes\Magix Video DeLuxe 15 Premium\unwise.exe
Malwarebytes' Anti-Malware-->"C:\Programme\Sicherheit\Malwarebytes' Anti-Malware\unins000.exe"
Maximus-->C:\Programme\Verschiedenes\FL Plugins\Maximus\uninstall.exe
Medieval CUE Splitter-->MsiExec.exe /I{B96D2269-568B-4CBF-9332-12FAE8B158F7}
Microsoft .NET Framework 1.1 German Language Pack-->MsiExec.exe /X{E78BFA60-5393-4C38-82AB-E8019E464EB4}
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\WINXP\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINXP\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU-->MsiExec.exe /I{C314CE45-3392-3B73-B4E1-139CD41CA933}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 German Language Pack-->c:\WINXP\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 German Language Pack\setup.exe
Microsoft .NET Framework 3.0 German Language Pack-->MsiExec.exe /X{F2A7F421-1679-48D5-B918-96999014ED53}
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU-->MsiExec.exe /I{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU-->c:\WINXP\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - deu\setup.exe
Microsoft .NET Framework 3.5 Language Pack SP1 - deu-->MsiExec.exe /I{052FDD78-A6EA-3187-8386-C82F4CA3A929}
Microsoft .NET Framework 3.5 SP1-->C:\WINXP\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile DEU Language Pack-->C:\WINXP\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1031 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile DEU Language Pack-->MsiExec.exe /X{F750C986-5310-3A5A-95F8-4EC71C8AC01C}
Microsoft .NET Framework 4 Client Profile-->C:\WINXP\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Flight Simulator 2004 - Das Jahrhundert der Luftfahrt-->"C:\Spiele\Microsoft Flight Simulator 2004\UNINSTAL.EXE" /runtemp /addremove
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}
Microsoft Games for Windows - LIVE-->MsiExec.exe /X{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110407-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{09298F26-A95C-31E2-9D95-2C60F586F075}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
Morphine-->C:\Programme\Verschiedenes\FL Plugins\Morphine\uninstall.exe
Mozilla Firefox (3.6.3)-->C:\Programme\Internet\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
Native Instruments Pro-53-->C:\PROGRA~1\VERSCH~1\FLPLUG~1\Pro-53\UNWISE.EXE C:\PROGRA~1\VERSCH~1\FLPLUG~1\Pro-53\INSTALL.LOG
NextUp.com-NeoSpeech Kate16 Voice-->MsiExec.exe /X{452167AD-8C66-4726-9F6D-F27CFE13B8A3}
NextUp.com-NeoSpeech Paul16 Voice-->MsiExec.exe /X{48D7FBA8-624C-4160-8A1D-D62619C2A693}
NextUp-Acapela Brightspeech Heather22 US English Voice-->MsiExec.exe /X{511ECAD8-3F08-4A16-A808-E20E5C44D93B}
NVIDIA PhysX-->MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
O&O Defrag Professional-->MsiExec.exe /I{D75814C1-5AA5-4198-BFF6-093A226D9F0D}
OpenAL-->"C:\Programme\OpenAL\OalinstGridRelease.exe" /U
PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
Pixel Bender Toolkit-->MsiExec.exe /I{43509E18-076E-40FE-AF38-CA5ED400A5A9}
PoiZone-->C:\Programme\Verschiedenes\FL Plugins\PoiZone\uninstall.exe
Pro Evolution Soccer 2010-->MsiExec.exe /X{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}
RAD Video Tools-->"C:\Programme\Verschiedenes\RADVideo\uninstall.exe"
Rapture3D 2.3.22 Game-->"C:\Programme\BRS\unins000.exe"
Ray Adams ATI Tray Tools-->"C:\Programme\Hardware\ATI Tray Tools\uninstall.exe"
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x7  -removeonly
reFX Nexus VSTi RTAS v2.2.0-->"C:\Programme\Verschiedenes\VSTPlugins\Nexus\Uninstall Nexus\unins000.exe"
reFX Vanguard VSTi RTAS v1.8.0-->"C:\Programme\Verschiedenes\VSTPlugins\Vanguard\Uninstall\unins000.exe"
rgc:audio z3ta+ 1.5-->"C:\Programme\Verschiedenes\FL Plugins\z3ta+\unins000.exe"
Rob Papen Albino 3-->C:\Programme\Verschiedenes\VSTPlugins\UninstalAlbino3.exe
Rob Papen Predator V1.1.0-->"C:\Programme\Verschiedenes\VSTPlugins\Predator\unins000.exe"
Sakura-->C:\Programme\Verschiedenes\FL Plugins\Sakura\uninstall.exe
Sanse Playlister Ver1.4-->"C:\Programme\Hardware\Sanse Playlister\unins000.exe"
Sawer-->C:\Programme\Verschiedenes\FL Plugins\Sawer\uninstall.exe
SHOUTcast Source DSP 1.9.0 (remove only)-->C:\Programme\Verschiedenes\Winamp\uninst-dsp.exe
Sicherheitsupdate für Windows Internet Explorer 8 (KB978207)-->"C:\WINXP\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
Sicherheitsupdate für Windows Internet Explorer 8 (KB981332)-->"C:\WINXP\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
Sicherheitsupdate für Windows Internet Explorer 8 (KB982381)-->"C:\WINXP\ie8updates\KB982381-IE8\spuninst\spuninst.exe"
Sicherheitsupdate für Windows Media Player (KB978695)-->"C:\WINXP\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB923789)-->C:\WINXP\system32\MacroMed\Flash\genuinst.exe C:\WINXP\system32\MacroMed\Flash\KB923789.inf
Sicherheitsupdate für Windows XP (KB971468)-->"C:\WINXP\$NtUninstallKB971468$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB975560)-->"C:\WINXP\$NtUninstallKB975560$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB975561)-->"C:\WINXP\$NtUninstallKB975561$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB975562)-->"C:\WINXP\$NtUninstallKB975562$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB975713)-->"C:\WINXP\$NtUninstallKB975713$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB977816)-->"C:\WINXP\$NtUninstallKB977816$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB977914)-->"C:\WINXP\$NtUninstallKB977914$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB978037)-->"C:\WINXP\$NtUninstallKB978037$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB978262)-->"C:\WINXP\$NtUninstallKB978262$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB978338)-->"C:\WINXP\$NtUninstallKB978338$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB978542)-->"C:\WINXP\$NtUninstallKB978542$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB978601)-->"C:\WINXP\$NtUninstallKB978601$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB978706)-->"C:\WINXP\$NtUninstallKB978706$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB979309)-->"C:\WINXP\$NtUninstallKB979309$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB979482)-->"C:\WINXP\$NtUninstallKB979482$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB979559)-->"C:\WINXP\$NtUninstallKB979559$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB979683)-->"C:\WINXP\$NtUninstallKB979683$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB980195)-->"C:\WINXP\$NtUninstallKB980195$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB980218)-->"C:\WINXP\$NtUninstallKB980218$\spuninst\spuninst.exe"
Sicherheitsupdate für Windows XP (KB980232)-->"C:\WINXP\$NtUninstallKB980232$\spuninst\spuninst.exe"
SopCast 3.2.9-->C:\Programme\Internet\SopCast\uninst.exe
Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
Split/Second-->"C:\Programme\InstallShield Installation Information\{28526951-55EF-4901-A0CA-B9AC966D1DD1}\setup.exe" -runfromtemp -l0x0407  -removeonly
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
Sunbelt Personal Firewall-->MsiExec.exe /X{82B1150E-9B37-49FC-83EB-D52197D900D0}
SWAT 4-->C:\PROGRA~1\GEMEIN~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}  uninstall
Sylenth1 v2.20-->"C:\Programme\Verschiedenes\VSTPlugins\Sylenth1\unins000.exe"
Synapse Junglist VSTi v3.2-->C:\PROGRA~1\VERSCH~1\VSTPLU~1\Junglist\UNWISE.EXE C:\PROGRA~1\VERSCH~1\VSTPLU~1\Junglist\INSTALL.LOG
TeamSpeak 3 Client-->"C:\Spiele\Zubehör\TeamSpeak 3 Client\uninstall.exe"
Test Drive Unlimited-->MsiExec.exe /X{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}
TextAloud-->"C:\Programme\Verschiedenes\TextAloud\unins000.exe"
Text-To-Speech-Runtime-->MsiExec.exe /X{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}
Tom Clancy's H.A.W.X-->"C:\Programme\InstallShield Installation Information\{6E36A172-06FB-4BC8-B7FC-D30D219E6776}\setup.exe" -runfromtemp -l0x0007 -removeonly
Tom Clancy's Splinter Cell Conviction-->"C:\Programme\InstallShield Installation Information\{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}\setup.exe" -runfromtemp -l0x0007 -removeonly
TortoiseSVN 1.6.7.18415 (32 bit)-->MsiExec.exe /X{5DC6B387-DCD5-4B66-B866-434020FF2ECC}
Toxic Biohazard-->C:\Programme\Verschiedenes\FL Plugins\Toxic Biohazard\uninstall.exe
TuneUp Utilities-->C:\Programme\Sicherheit\TuneUp Utilities 2010\TUInstallHelper.exe --Trigger-Uninstall
TVAnts 1.0-->C:\PROGRA~1\Internet\TVAnts\UNWISE.EXE C:\PROGRA~1\Internet\TVAnts\INSTALL.LOG
TVUPlayer 2.5.2.2-->C:\Programme\Internet\TVUPlayer\uninst.exe
Ubisoft Game Launcher-->"C:\Programme\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409  -removeonly
Ultimate Terrain - Canada & Alaska-->C:\Spiele\Microsoft Flight Simulator 2004\UnUTCanada.exe
Ultimate Terrain - Europe-->C:\Spiele\Microsoft Flight Simulator 2004\Europe_Uninstall.exe
Ultimate Terrain - USA-->C:\Spiele\Microsoft Flight Simulator 2004\UnUTUSA.exe
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINXP\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update für Windows Internet Explorer 8 (KB975364)-->"C:\WINXP\ie8updates\KB975364-IE8\spuninst\spuninst.exe"
Update für Windows Internet Explorer 8 (KB976662)-->"C:\WINXP\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
Update für Windows Internet Explorer 8 (KB980182)-->"C:\WINXP\ie8updates\KB980182-IE8\spuninst\spuninst.exe"
Update für Windows Internet Explorer 8 (KB980302)-->"C:\WINXP\ie8updates\KB980302-IE8\spuninst\spuninst.exe"
Update für Windows Internet Explorer 8 (KB982632)-->"C:\WINXP\ie8updates\KB982632-IE8\spuninst\spuninst.exe"
UUSee ²¥·Å²å¼þ»ù´¡°ü 6.1.317.1-->C:\Programme\Gemeinsame Dateien\uusee\uninst.exe
UUSee ÍøÂçµçÊÓ [6.10.317.6]-->C:\Programme\Internet\uusee\uninstuusee.exe
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Veetle TV 0.9.16-->C:\Programme\Internet\Veetle\UninstallVeetleTV.exe
VIA Plattform-Geräte-Manager-->C:\PROGRA~1\GEMEIN~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169} 
Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
VLC media player 1.0.5-->C:\Programme\Verschiedenes\VLC\uninstall.exe
VP6 VFW Codec-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{A23866A0-738B-4091-9924-0B0DE3988A15}\Setup.exe" -l0x9 
Waves Mercury Bundle-->C:\PROGRA~1\VERSCH~1\FLPLUG~1\Waves\Logs\WAVESM~1\UNWISE.EXE C:\PROGRA~1\VERSCH~1\FLPLUG~1\Waves\Logs\WAVESM~1\INSTALL.LOG
Winamp-->"C:\Programme\Verschiedenes\Winamp\UninstWA.exe"
Windows Internet Explorer 8-->"C:\WINXP\ie8\spuninst\spuninst.exe"
Windows Management Framework Core-->"C:\WINXP\$968930Uinstall_KB968930$\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Programme\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINXP\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation Language Pack (DEU)-->MsiExec.exe /X{92DF2F1B-F63C-4D9A-B3E1-B2D11AE29790}
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows-Treiberpaket - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)-->C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINXP\system32\DRVSTORE\amdk8_C710CEED791003E4D635992B02471584893356A0\amdk8.inf
WinRAR-->C:\Programme\Verschiedenes\WinRAR\uninstall.exe
xp-AntiSpy 3.97-6-->C:\Programme\Sicherheit\xp-AntiSpy\Uninstall.exe
Xvid 1.2.2 final uninstall-->"C:\Programme\Codecs\Xvid\unins000.exe"

======Hosts File======

127.0.0.1 im.adtech.de
127.0.0.1 adserver.adtech.de
127.0.0.1 adtech.de
127.0.0.1 ar.atwola.com
127.0.0.1 atwola.com
127.0.0.1 adserver.71i.de
127.0.0.1 adicqserver.71i.de
127.0.0.1 71i.de
127.0.0.1 serial.alcohol-soft.com
127.0.0.1 www.alcohol-soft.com

======Security center information======

AV: AntiVir Desktop (disabled)
FW: Sunbelt Personal Firewall

======System event log======

Computer Name: MEINPC
Event Code: 20159
Message: Die Verbindung mit "Versatel DSL", hergestellt durch den Benutzer "galicic@versatel" unter Verwendung des Geräts "PPPoE8-0", wurde getrennt.

Record Number: 28388
Source Name: RemoteAccess
Time Written: 20100616002529.000000+120
Event Type: Informationen
User: 

Computer Name: MEINPC
Event Code: 20158
Message: Der Benutzer "galicic@versatel" hat eine Verbindung mit "Versatel DSL" hergestellt, unter Verwendung des Geräts "PPPoE8-0".

Record Number: 28387
Source Name: RemoteAccess
Time Written: 20100615224300.000000+120
Event Type: Informationen
User: 

Computer Name: MEINPC
Event Code: 20159
Message: Die Verbindung mit "Versatel DSL", hergestellt durch den Benutzer "galicic@versatel" unter Verwendung des Geräts "PPPoE8-0", wurde getrennt.

Record Number: 28386
Source Name: RemoteAccess
Time Written: 20100615224257.000000+120
Event Type: Informationen
User: 

Computer Name: MEINPC
Event Code: 20158
Message: Der Benutzer "galicic@versatel" hat eine Verbindung mit "Versatel DSL" hergestellt, unter Verwendung des Geräts "PPPoE8-0".

Record Number: 28385
Source Name: RemoteAccess
Time Written: 20100615222842.000000+120
Event Type: Informationen
User: 

Computer Name: MEINPC
Event Code: 20159
Message: Die Verbindung mit "Versatel DSL", hergestellt durch den Benutzer "galicic@versatel" unter Verwendung des Geräts "PPPoE8-0", wurde getrennt.

Record Number: 28384
Source Name: RemoteAccess
Time Written: 20100615222839.000000+120
Event Type: Informationen
User: 

=====Application event log=====

Computer Name: MEINPC
Event Code: 11724
Message: Produkt: FIFA 10 -- Entfernung erfolgreich.

Record Number: 1186
Source Name: MsiInstaller
Time Written: 20100309140105.000000+060
Event Type: Informationen
User: MEINPC\LP-Fan

Computer Name: MEINPC
Event Code: 1000
Message: Fehlgeschlagene Anwendung fifa10.exe, Version 0.0.0.0, fehlgeschlagenes Modul fifa10.exe, Version 0.0.0.0, Fehleradresse 0x00212cd8.

Record Number: 1185
Source Name: Application Error
Time Written: 20100309135323.000000+060
Event Type: Fehler
User: 

Computer Name: MEINPC
Event Code: 1000
Message: Fehlgeschlagene Anwendung fifa10.exe, Version 0.0.0.0, fehlgeschlagenes Modul fifa10.exe, Version 0.0.0.0, Fehleradresse 0x00212cd8.

Record Number: 1184
Source Name: Application Error
Time Written: 20100309135218.000000+060
Event Type: Fehler
User: 

Computer Name: MEINPC
Event Code: 11707
Message: Produkt: FIFA 10 -- Installation erfolgreich.

Record Number: 1183
Source Name: MsiInstaller
Time Written: 20100309133102.000000+060
Event Type: Informationen
User: MEINPC\LP-Fan

Computer Name: MEINPC
Event Code: 11724
Message: Produkt: FIFA 10 -- Entfernung erfolgreich.

Record Number: 1182
Source Name: MsiInstaller
Time Written: 20100309131229.000000+060
Event Type: Informationen
User: MEINPC\LP-Fan

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Programme\ATI Technologies\ATI.ACE\Core-Static;C:\WINXP\system32\WindowsPowerShell\v1.0;C:\Programme\Gemeinsame Dateien\DivX Shared\;C:\Programme\TortoiseSVN\bin;C:\Programme\Gemeinsame Dateien\iZotope\Runtimes;C:\WINXP\system32\WindowsPowerShell\v1.0
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=4b02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.PSC1;.PSC1
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"PSModulePath"=C:\WINXP\system32\WindowsPowerShell\v1.0\Modules\

-----------------EOF-----------------
         
--- --- ---

Code:
ATTFilter
Logfile of random's system information tool 1.07 (written by random/random)
Run by LP-Fan at 2010-06-25 23:52:36
Microsoft Windows XP Professional Service Pack 3
System drive C: has 507 GB (71%) free of 714 GB
Total RAM: 2046 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:52:42, on 25.06.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\Programme\Sicherheit\Avira\AntiVir Desktop\sched.exe
C:\Programme\Sicherheit\Avira\AntiVir Desktop\avguard.exe
C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Programme\Internet\Sunbelt Personal Firewall\SbPFLnch.exe
C:\Programme\Internet\Sunbelt Personal Firewall\SbPFSvc.exe
C:\Programme\Sicherheit\Avira\AntiVir Desktop\avshadow.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\Explorer.EXE
C:\Programme\Internet\Sunbelt Personal Firewall\SbPFCl.exe
C:\Programme\TortoiseSVN\bin\TSVNCache.exe
C:\Programme\Sicherheit\Avira\AntiVir Desktop\avgnt.exe
C:\Programme\Hardware\ATI Tray Tools\atitray.exe
C:\Programme\Internet\Mozilla Firefox\firefox.exe
C:\Programme\Sicherheit\Malwarebytes' Anti-Malware\mbam.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\System Volume Information\Microsoft\smss.exe
D:\Downloaded\RSIT.exe
C:\Programme\trend micro\LP-Fan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Programme\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Programme\Verschiedenes\TextAloud\TAForIE.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Programme\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Sicherheit\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Programme\Sicherheit\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Programme\Hardware\ATI Tray Tools\atitray.exe"
O8 - Extra context menu item: An vorhandene PDF-Datei anfügen - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Linkziel an vorhandene PDF-Datei anhängen - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Linkziel in Adobe PDF konvertieren - res://C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\VERSCH~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: ʹÓÃUUSee¼ÓËÙ²¥·Å - C:\Programme\Internet\uusee\geturltoplay.htm
O8 - Extra context menu item: ʹÓÃUUSeeÏÂÔØ - C:\Programme\Internet\uusee\geturltodown.htm
O9 - Extra button: СÓÎÏ· - {998A88A0-A355-809B-831C-B83A80000991} - h**p://www.ugege.com/ (file missing)
O9 - Extra 'Tools' menuitem: СÓÎÏ· - {998A88A0-A355-809B-831C-B83A80000991} - h**p://www.ugege.com/ (file missing)
O9 - Extra button: Æô¶¯UUSee ÍøÂçµçÊÓ - {998A88A0-A355-809B-831C-B83A80000992} - C:\Programme\Internet\uusee\UUSeePlayer.exe
O9 - Extra 'Tools' menuitem: Æô¶¯UUSee ÍøÂçµçÊÓ - {998A88A0-A355-809B-831C-B83A80000992} - C:\Programme\Internet\uusee\UUSeePlayer.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\Internet\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\Internet\ICQ6.5\ICQ.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - h**p://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263482665828
O17 - HKLM\System\CCS\Services\Tcpip\..\{9155C698-5561-4F8D-86AB-882BDCBC597F}: NameServer = 62.220.18.38 89.246.64.38
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINXP\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINXP\system32\browseui.dll
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Sicherheit\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Sicherheit\Avira\AntiVir Desktop\avguard.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Programme\Hardware\Defrag\oodag.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Programme\Internet\Sunbelt Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Programme\Internet\Sunbelt Personal Firewall\SbPFSvc.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Programme\Sicherheit\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 7205 bytes

======Scheduled tasks folder======

C:\WINXP\tasks\Automatische Problemsuche.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - C:\Programme\Adobe\/Adobe Contribute CS4/contributeieplugin.dll [2008-09-10 136560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-04-03 349640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Programme\Java\jre6\bin\jp2ssv.dll [2010-03-16 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-16 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-04-03 349640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F053C368-5458-45B2-9B4D-D8914BDDDBFF} - TextAloud - C:\Programme\Verschiedenes\TextAloud\TAForIE.dll [2009-01-14 660992]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-04-03 349640]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - C:\Programme\Adobe\/Adobe Contribute CS4/contributeieplugin.dll [2008-09-10 136560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Programme\Sicherheit\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Programme\Sicherheit\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AtiTrayTools"=C:\Programme\Hardware\ATI Tray Tools\atitray.exe [2007-05-22 521128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Programme\Verschiedenes\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Programme\Brennsoftware\Alcohol 120\axcmd.exe [2009-12-23 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Programme\Canon\MyPrinter\BJMyPrt.exe [2008-03-18 1848648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINXP\system32\ctfmon.exe [2010-01-14 24064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
c:\Programme\Microsoft IntelliType Pro\itype.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINXP\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Programme\Hardware\Defrag\oodtray.exe [2009-09-12 2524416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINXP\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-21 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayServer]
C:\Programme\Verschiedenes\Magix Video DeLuxe 15 Premium\TrayServer.exe [2008-08-07 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Programme\Verschiedenes\Winamp\winampa.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINXP\system32\Ati2evxx.dll [2009-07-21 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINXP\system32\WPDShServiceObj.dll [2009-08-03 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoRecentDocsNetHood"=1
"NoDriveAutorun"=67108815

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINXP\Network Diagnostic\xpnetdiag.exe"="C:\WINXP\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\WINXP\system32\sessmgr.exe"="C:\WINXP\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Programme\Internet\ICQ6.5\ICQ.exe"="C:\Programme\Internet\ICQ6.5\ICQ.exe:*:Enabled:ICQ.exe"
"C:\Programme\Internet\uusee\UUSeePlayer.exe"="C:\Programme\Internet\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Programme\Internet\ICQ6.5\ICQ.exe"="C:\Programme\Internet\ICQ6.5\ICQ.exe:*:Enabled:ICQ.exe"

======List of files/folders created in the last 1 months======

2010-06-25 23:52:37 ----D---- C:\Programme\trend micro
2010-06-25 23:52:36 ----D---- C:\rsit
2010-06-25 23:39:04 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\Malwarebytes
2010-06-25 23:38:55 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2010-06-25 12:37:23 ----HDC---- C:\WINXP\ie8
2010-06-25 01:08:36 ----D---- C:\WINXP\system32\winrm
2010-06-25 01:08:36 ----D---- C:\WINXP\system32\GroupPolicy
2010-06-25 01:08:32 ----HDC---- C:\WINXP\$968930Uinstall_KB968930$
2010-06-25 01:08:24 ----D---- C:\WINXP\$NtUninstallKB968930$
2010-06-25 01:05:50 ----HDC---- C:\WINXP\$NtUninstallKB979559$
2010-06-25 01:03:35 ----HDC---- C:\WINXP\$NtUninstallKB975562$
2010-06-25 01:01:23 ----HDC---- C:\WINXP\$NtUninstallKB979482$
2010-06-25 01:00:14 ----HDC---- C:\WINXP\$NtUninstallKB980195$
2010-06-25 00:57:48 ----HDC---- C:\WINXP\$NtUninstallKB978695_WM9$
2010-06-25 00:57:41 ----HDC---- C:\WINXP\$NtUninstallKB980218$
2010-06-25 00:55:57 ----A---- C:\WINXP\system32\SET32F.tmp
2010-06-25 00:55:57 ----A---- C:\WINXP\system32\SET32E.tmp
2010-06-25 00:55:56 ----A---- C:\WINXP\system32\SET333.tmp
2010-06-25 00:55:56 ----A---- C:\WINXP\system32\SET32D.tmp
2010-06-25 00:55:55 ----A---- C:\WINXP\system32\SET332.tmp
2010-06-25 00:55:55 ----A---- C:\WINXP\system32\SET32A.tmp
2010-06-25 00:55:55 ----A---- C:\WINXP\system32\SET329.tmp
2010-06-24 16:55:11 ----HD---- C:\WINXP\PIF
2010-06-24 03:35:34 ----D---- C:\Programme\Cacheman
2010-06-23 22:58:38 ----A---- C:\WINXP\v2d.INI
2010-06-23 20:03:22 ----D---- C:\Temp
2010-06-23 19:56:41 ----D---- C:\Programme\Free MKV Video2Dvd
2010-06-23 14:55:50 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\Dicsoft Software
2010-06-23 14:55:29 ----D---- C:\Programme\Dicsoft
2010-06-23 01:15:02 ----A---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\EasyToolz.ini
2010-06-22 14:37:46 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Test Drive Unlimited
2010-06-21 22:09:13 ----A---- C:\WINXP\AISmooth11.INI
2010-06-21 19:05:03 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\InstallShield
2010-06-11 17:42:37 ----D---- C:\Programme\Joboshare
2010-06-11 14:54:14 ----A---- C:\WINXP\system32\WNASPI32.DLL
2010-06-11 14:41:46 ----A---- C:\WINXP\Easy Avi Divx Xvid to DVD Burner.INI
2010-06-06 13:07:40 ----D---- C:\Programme\VirtualDJ
2010-06-05 13:02:32 ----HDC---- C:\WINXP\$NtUninstallKB981793$

======List of files/folders modified in the last 1 months======

2010-06-25 23:52:37 ----RD---- C:\Programme
2010-06-25 23:51:54 ----D---- C:\WINXP\Temp
2010-06-25 23:38:57 ----D---- C:\WINXP\system32\drivers
2010-06-25 23:38:55 ----D---- C:\Programme\Sicherheit
2010-06-25 23:25:50 ----D---- C:\WINXP\Debug
2010-06-25 23:25:50 ----D---- C:\WINXP
2010-06-25 23:07:57 ----SHD---- C:\WINXP\Installer
2010-06-25 23:07:03 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\vlc
2010-06-25 12:40:55 ----D---- C:\WINXP\system32\CatRoot2
2010-06-25 12:40:44 ----D---- C:\WINXP\system32
2010-06-25 12:39:05 ----HD---- C:\WINXP\inf
2010-06-25 12:39:05 ----D---- C:\Programme\Internet Explorer
2010-06-25 12:39:03 ----D---- C:\WINXP\system32\CatRoot
2010-06-25 12:38:36 ----DC---- C:\WINXP\system32\dllcache
2010-06-25 12:37:23 ----D---- C:\WINXP\system32\de-de
2010-06-25 12:08:18 ----SHD---- C:\System Volume Information
2010-06-25 01:15:22 ----D---- C:\WINXP\security
2010-06-25 01:14:10 ----RSD---- C:\WINXP\assembly
2010-06-25 01:14:10 ----D---- C:\WINXP\Microsoft.NET
2010-06-25 01:13:20 ----A---- C:\WINXP\system32\PerfStringBackup.INI
2010-06-25 01:10:35 ----D---- C:\WINXP\WinSxS
2010-06-25 01:08:44 ----D---- C:\WINXP\system32\config
2010-06-25 01:08:43 ----D---- C:\WINXP\Help
2010-06-25 01:08:37 ----D---- C:\WINXP\system32\wbem
2010-06-25 01:05:58 ----D---- C:\WINXP\ie8updates
2010-06-25 01:05:55 ----HD---- C:\WINXP\$hf_mig$
2010-06-25 00:01:32 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\dvdcss
2010-06-24 15:22:46 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\uTorrent
2010-06-24 03:35:40 ----A---- C:\WINXP\system.ini
2010-06-23 19:56:52 ----RSD---- C:\WINXP\Fonts
2010-06-22 23:18:12 ----HD---- C:\Programme\InstallShield Installation Information
2010-06-22 23:06:03 ----D---- C:\Spiele
2010-06-22 16:52:01 ----D---- C:\WINXP\Uninstall
2010-06-21 21:37:40 ----D---- C:\WINXP\system32\Adobe
2010-06-21 17:48:30 ----SD---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\Microsoft
2010-06-06 20:54:57 ----D---- C:\Dokumente und Einstellungen\LP-Fan\Anwendungsdaten\ICQ
2010-06-05 23:48:03 ----D---- C:\Programme\Verschiedenes
2010-06-05 18:09:10 ----D---- C:\WINXP\system32\DirectX
2010-05-28 21:37:34 ----A---- C:\WINXP\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD-Prozessortreiber; C:\WINXP\system32\DRIVERS\AmdK8.sys [2006-07-02 43520]
R1 atitray;atitray; \??\C:\Programme\Hardware\ATI Tray Tools\atitray.sys []
R1 avgio;avgio; \??\C:\Programme\Sicherheit\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINXP\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 SbFw;SbFw; C:\WINXP\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; C:\WINXP\system32\drivers\sbhips.sys [2008-06-21 66600]
R1 ssmdrv;ssmdrv; C:\WINXP\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 adfs;adfs; C:\WINXP\system32\drivers\adfs.sys [2010-05-06 73312]
R2 Aspi32;Aspi32; C:\WINXP\System32\drivers\aspi32.sys [2008-05-06 16512]
R2 atksgt;atksgt; C:\WINXP\system32\DRIVERS\atksgt.sys [2010-03-21 281760]
R2 avgntflt;avgntflt; C:\WINXP\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 lirsgt;lirsgt; C:\WINXP\system32\DRIVERS\lirsgt.sys [2010-03-21 25888]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINXP\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINXP\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Arp1394;1394-ARP-Clientprotokoll; C:\WINXP\system32\DRIVERS\arp1394.sys [2009-12-08 60800]
R3 ati2mtag;ati2mtag; C:\WINXP\system32\DRIVERS\ati2mtag.sys [2009-07-21 3565056]
R3 FETNDIS;VIA PCI 10/100-MBit/s-Fast Ethernetadapter-NT-Treiber; C:\WINXP\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINXP\system32\drivers\mbamswissarmy.sys []
R3 NIC1394;1394-Netzwerktreiber; C:\WINXP\system32\DRIVERS\nic1394.sys [2009-12-08 61824]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\WINXP\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINXP\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2-aktivierter Hub; C:\WINXP\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbprint;Microsoft USB-Druckerklasse; C:\WINXP\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB-Scannertreiber; C:\WINXP\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINXP\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 AmdPPM;AMD HwPState Prozessortreiber; C:\WINXP\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
S3 61883;61883-Einheitsgerät; C:\WINXP\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 abrgbioj;abrgbioj; C:\WINXP\system32\drivers\abrgbioj.sys []
S3 Avc;AVC-Gerät; C:\WINXP\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 CCDECODE;Untertiteldecoder; C:\WINXP\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Microsoft HID Class-Treiber; C:\WINXP\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MarvinBus;Pinnacle Marvin Bus; C:\WINXP\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINXP\system32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\WINXP\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI-Codec; C:\WINXP\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV-/Videoverbindung; C:\WINXP\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 QCDonner;Logitech QuickCam Express; C:\WINXP\system32\DRIVERS\OVCD.sys [2001-08-17 28032]
S3 SLIP;BDA Slip De-Framer; C:\WINXP\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 StarOpen;StarOpen; C:\WINXP\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 streamip;BDA-IPSink; C:\WINXP\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Programme\Sicherheit\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
S3 USBSTOR;USB-Massenspeichertreiber; C:\WINXP\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext-Codec; C:\WINXP\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINXP\system32\DRIVERS\WudfPf.sys [2009-08-03 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINXP\system32\DRIVERS\wudfrd.sys [2009-08-03 82944]
S4 IntelIde;IntelIde; C:\WINXP\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Planer; C:\Programme\Sicherheit\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 AntiVirService;Avira AntiVir Guard; C:\Programme\Sicherheit\Avira\AntiVir Desktop\avguard.exe [2010-05-30 267432]
R2 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-05-06 655624]
R2 SbPF.Launcher;SbPF.Launcher; C:\Programme\Internet\Sunbelt Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Programme\Internet\Sunbelt Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R2 UxTuneUp;TuneUp Designerweiterung; C:\WINXP\System32\svchost.exe [2008-04-14 14336]
S3 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINXP\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINXP\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 O&O Defrag;O&O Defrag; C:\Programme\Hardware\Defrag\oodag.exe [2009-09-12 1488128]
S3 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Programme\Sicherheit\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-02-01 1043784]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINXP\system32\svchost.exe [2008-04-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINXP\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 Adobe Version Cue CS4;Adobe Version Cue CS4; C:\Programme\Gemeinsame Dateien\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2010-05-06 288112]
S4 aspnet_state;ASP.NET-Zustandsdienst; C:\WINXP\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINXP\system32\Ati2evxx.exe [2009-07-21 602112]
S4 ATI Smart;ATI Smart; C:\WINXP\system32\ati2sgag.exe [2009-07-21 593920]
S4 CachemanService;Cacheman Service; C:\Programme\Cacheman\CachemanServ.exe []
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINXP\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 idsvc;Windows CardSpace; C:\WINXP\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2010-03-16 153376]
S4 NetTcpPortSharing;Net.Tcp-Portfreigabedienst; C:\WINXP\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMSAccessU;NMSAccessU; C:\Programme\Brennsoftware\CDBurnerXP\NMSAccessU.exe [2009-11-12 71096]
S4 ose;Office Source Engine; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 TuneUp.Defrag;TuneUp Drive Defrag-Dienst; C:\Programme\Sicherheit\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-02-17 435016]
S4 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; C:\Programme\Windows Media Player\WMPNetwk.exe [2006-11-03 920576]
S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINXP\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------
         
--- --- ---

schonmal im vorraus...

Gruss
LP - Fan

Geändert von LP - Fan (25.06.2010 um 14:21 Uhr)

 

Themen zu iexplore.exe 3-mal im Task-Manager
32 bit, analysis, antivir, antivir guard, avgntflt.sys, bho, browser, browseui preloader, desktop, device driver, drvstore, dsl, excel, exe dateien, firefox, flash player, fontcache, gereinigt, helper, hotfix.exe, hängen, iexplore.exe, indesign, install.exe, installation, internet, internet explorer, location, logfile, malwarebytes' anti-malware, mozilla, msiexec, msiexec.exe, nexus, plug-in, problem, registry, rundll, security, security update, staropen, system, third party, werbung, windows, windows internet, windows internet explorer, windows xp




Ähnliche Themen: iexplore.exe 3-mal im Task-Manager


  1. iexplore.exe öffnet sich automatisch im Task-Manager
    Plagegeister aller Art und deren Bekämpfung - 25.03.2012 (12)
  2. iexplore.exe / über 10 mal im Task Manager / Prozess belegt Arbeitsspeicher
    Plagegeister aller Art und deren Bekämpfung - 23.02.2011 (20)
  3. iexplore multipel im task manager, wave auf null
    Log-Analyse und Auswertung - 09.08.2010 (9)
  4. IEXPLORE.EXE im Task Manager, PC lahm, ie öffnet ab und zu Werbung
    Log-Analyse und Auswertung - 15.07.2010 (1)
  5. 2-4x iexplore.exe im Task-Manager (Lautstärke unverändert)
    Plagegeister aller Art und deren Bekämpfung - 12.07.2010 (23)
  6. IEXPLORE.EXE mehrmals im Task-Manager
    Log-Analyse und Auswertung - 18.01.2010 (28)
  7. 2 mal iexplore.exe im task-manager
    Log-Analyse und Auswertung - 15.01.2010 (5)
  8. Task-Manager, iexplore.exe 2 mal oder öfter, hohe Speicherkapazität
    Log-Analyse und Auswertung - 10.12.2009 (3)
  9. iexplore.exe wird doppelt im Task Manager angezeigt
    Log-Analyse und Auswertung - 15.11.2009 (5)
  10. iexplore.exe 2 mal in Task-Manager
    Plagegeister aller Art und deren Bekämpfung - 16.09.2009 (7)
  11. iexplore.exe 2 mal im Task-Manager
    Mülltonne - 15.09.2009 (1)
  12. iexplore.exe erscheint immer wieder im Task-Manager
    Log-Analyse und Auswertung - 10.08.2008 (3)
  13. Iexplore.exe 2 mal im Task Manager !HILFE!
    Log-Analyse und Auswertung - 02.08.2007 (15)
  14. Unbekannter Task im Task-Manager Win XP
    Plagegeister aller Art und deren Bekämpfung - 16.01.2007 (1)
  15. IEXPLORE.EXE doppelt im Task-Manager
    Log-Analyse und Auswertung - 25.01.2006 (3)
  16. Task Manager,Geräte Manager,regedit öffnen sich nicht!
    Log-Analyse und Auswertung - 11.04.2005 (1)
  17. problem mit iexplore.exe im task-manager
    Plagegeister aller Art und deren Bekämpfung - 12.08.2004 (1)

Zum Thema iexplore.exe 3-mal im Task-Manager - Guten Tag... Ich habe seit 2 Tagen das Problem das 2-3 mal die iexplore.exe in meinem Task-Manager auftritt und wenn ich sie beende, sie nach kurzer Zeit wieder da ist... - iexplore.exe 3-mal im Task-Manager...
Archiv
Du betrachtest: iexplore.exe 3-mal im Task-Manager auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.