|
Plagegeister aller Art und deren Bekämpfung: Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.07.2013, 07:20 | #1 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Hallo zusammen - bin neu hier - und noch völlig irritert Obwohl auf dieser 500 GB-Platte ca. 130 MB belegt sind (was ich über Eigenschaften auch nach wie vor sehen kann), kann ich die Daten nicht mehr einsehen. Auch nicht auf einem anderen PC ... Nun suche ich und grüble nach möglichen Ursachen ... Arbeite unter Win 7 (64 bit) und habe mir vor ein paar Tagen aus gegebenem Anlass eine "Schattenkopie (?)" auf diese Festplatte erstellt ... Habe bisher mit chkdsk geprüft und aktuell läuft die Freeware-Version von GetDataBack drüber (seit mehr als 12 Stunden) ... Würde gern 2 Screenshots hier reinstellen, weiß aber leider nicht wie das mit der URL geht ... Der MSE-Bildschirm meldet im Verlauf vom 12./13.Juli den " exploit java/cve-2012-0507 " den ich mir wohl verg. Woche über ein Java-Update eingefangen habe ... aber er meldet auch, dass er diesen unter Quarantäne gestellt und keine Schadsoftware auf meinem Rechner gefunden habe. Kann dieser Virus etwas mit dem Problem auf meiner ext. Festplatte zu tun haben? Was ist zu tun? Ich wäre wirklich sehr dankbar für hilfreichen Hinweis ... |
20.07.2013, 09:03 | #2 |
/// the machine /// TB-Ausbilder | Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
20.07.2013, 09:32 | #3 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? FRST Logfile:
__________________FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-07-2013 Ran by Martina (administrator) on 20-07-2013 10:23:15 Running from C:\Users\Martina\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (iAnywhere Solutions, Inc.) C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe (SafeNet, Inc) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe () C:\Program Files (x86)\Join Air\AssistantServices.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Dropbox, Inc.) C:\Users\Martina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\Program Files (x86)\Secure Banking\sbservice.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe () C:\Program Files (x86)\Join Air\UIExec.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Runtime Software) C:\Program Files (x86)\Runtime Software\GetDataBack\gdb.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\NaturallySpeaking11\Program\natspeak.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking11\dgnuiasvr.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking11\dgnuiasvr_x64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-08] (ELAN Microelectronics Corp.) HKLM\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-06-20] (Microsoft Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [170496 2013-02-01] (Sun Microsystems, Inc.) HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2013-07-12] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6199128 2013-07-12] (Lenovo(beijing) Limited) HKCU\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe [11480920 2013-06-19] (NTeWORKS) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [HP Officejet Pro 8600 (NET)] - C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2676584 2011-09-09] (Hewlett-Packard Co.) HKCU\...\Run: [SecureBanking] - C:\Program Files (x86)\Secure Banking\SecureBanking.exe [507904 2013-06-30] (Secure Banking) HKCU\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKLM-x32\...\Run: [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291648 2012-05-21] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [Dolby Advanced Audio v2] - "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [331BigDog] - C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-11-24] (Vimicro) HKLM-x32\...\Run: [UpdatePRCShortCut] - "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [UIExec] - "C:\Program Files (x86)\Join Air\UIExec.exe" [132608 2009-08-31] () HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG) HKLM-x32\...\Run: [DNS7reminder] - "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini" [328992 2010-10-27] (Nuance Communications, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [PDF Converter Registry Controller] - "C:\Program Files (x86)\ScanSoft\PDF Converter\RegistryController.exe" [102400 2003-08-19] (ScanSoft, Inc.) HKLM-x32\...\Run: [PDFConverterReminder] - "C:\PROGRA~2\ScanSoft\PDFCON~1\EReg\EReg.exe" -r "C:\PROGRA~2\ScanSoft\PDFCON~1\EReg\ereg.ini" [729088 2003-08-19] () HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-05-30] (Geek Software GmbH) HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe /show [52584 2013-05-17] (Lenovo) HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe /show [52584 2013-05-17] (Lenovo) HKU\Neipp BD\...\Run: [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19875432 2013-06-21] (Skype Technologies S.A.) HKU\Neipp BD\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe /startup [11480920 2013-06-19] (NTeWORKS) HKU\Neipp BD\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - "C:\Program Files (x86)\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe" /PROMPT /CMPID=JUNE2013_TB [1266712 2013-06-03] (AVG Secure Search) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [1266712 2013-06-03] () AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [215400 2012-06-22] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Martina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet Pro 8600\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B2A2C0143DD1AD17&affID=120695&tt=250613_gr5&tsp=4928 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms} BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: haufereader - No CLSID Value - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: haufereader - No CLSID Value - Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default FF user.js: detected! => C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll (AVG Technologies) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\searchplugins\webwebweb.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml FF Extension: HTTPS-Everywhere - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\https-everywhere@eff.org FF Extension: DownloadHelper - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: about-addons-memory - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\about-addons-memory@tn123.org.xpi FF Extension: ffext_basicchromeext - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\ffext_basicchromeext@startpage24.xpi FF Extension: suspendbackgroundtabs - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\suspendbackgroundtabs@adblockplus.org.xpi FF Extension: tfdlookup - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\tfdlookup@nohup.in.xpi FF Extension: No Name - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi FF Extension: No Name - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] C:\ProgramData\AVG Secure Search\FireFoxExt\15.3.0.11 ==================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S3 HRService; C:\Program Files (x86)\Haufe\iDesk\iDeskService\iDeskService.exe [71024 2010-10-25] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation) R2 Lexware_Datenbank_Plus; C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [83248 2010-11-05] (iAnywhere Solutions, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-06-20] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-06-20] (Microsoft Corporation) R2 SentinelKeysServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [374048 2010-10-20] (SafeNet, Inc.) R2 SentinelProtectionServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1250592 2010-10-20] (SafeNet, Inc) R2 SentinelSecurityRuntime; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [292128 2010-10-20] (SafeNet, Inc.) R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [241664 2009-08-31] () R2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [1598128 2013-06-27] (AVG Secure Search) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-06-27] (AVG Technologies) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation) R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.) S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [59048 2010-10-20] (SafeNet, Inc.) R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [952832 2011-12-06] (Vimicro Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-20 10:22 - 2013-07-20 10:22 - 00000000 ____D C:\FRST 2013-07-20 10:21 - 2013-07-20 10:21 - 01779345 _____ (Farbar) C:\Users\Martina\Downloads\FRST64.exe 2013-07-19 19:00 - 2013-07-19 19:00 - 00001988 _____ C:\Users\Public\Desktop\GetDataBack for FAT.lnk 2013-07-19 19:00 - 2013-07-19 19:00 - 00000000 ____D C:\Program Files (x86)\Runtime Software 2013-07-19 18:42 - 2013-07-19 18:42 - 03723592 _____ (Piriform Ltd) C:\Users\Martina\Downloads\rcsetup147.exe 2013-07-16 01:46 - 2013-07-20 09:53 - 00000654 _____ C:\Windows\setupact.log 2013-07-16 01:46 - 2013-07-16 01:46 - 00000000 _____ C:\Windows\setuperr.log 2013-07-16 01:44 - 2013-07-16 01:44 - 00010459 _____ C:\Users\Martina\Documents\Mappe1.xlsx 2013-07-15 15:43 - 2013-07-15 16:06 - 00000000 ____D C:\Users\Martina\Documents\01 B U S I N E S S 2013-07-15 12:39 - 2013-07-15 12:39 - 00001264 _____ C:\Users\Martina\Desktop\Revo Uninstaller.lnk 2013-07-15 12:39 - 2013-07-15 12:39 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-07-15 12:38 - 2013-07-15 12:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Martina\Downloads\revosetup95.exe 2013-07-15 11:31 - 2013-07-15 15:53 - 00000000 ____D C:\Users\Martina\Documents\Lenovo Notebook 2013-07-14 13:29 - 2013-07-14 13:29 - 00003110 _____ C:\Windows\System32\Tasks\{E645551B-CF7C-4A84-BA2A-BE7C4FDB61BD} 2013-07-14 11:17 - 2013-07-14 11:17 - 03357912 _____ (Piriform Ltd) C:\Users\Martina\Downloads\ccsetup403_slim.exe 2013-07-14 11:08 - 2013-07-14 11:08 - 00000000 ____D C:\Users\Martina\AppData\Local\PDF24 2013-07-14 10:28 - 2013-07-14 10:29 - 00000000 ____D C:\Users\Neipp BD\Bilder 2013-07-14 09:25 - 2013-07-14 09:27 - 00000000 ____D C:\Windows\system32\MRT 2013-07-13 15:21 - 2013-07-13 15:21 - 00013312 ___SH C:\Users\Martina\Desktop\Thumbs.db 2013-07-13 09:53 - 2013-07-19 13:49 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A5D247D3-B96E-4A7A-8CC3-F568284A7C55} 2013-07-12 13:12 - 2013-07-12 13:11 - 00039008 _____ (Lenovo.) C:\Windows\system32\Drivers\LhdX64.sys 2013-07-12 13:10 - 2013-07-12 13:11 - 22302856 _____ (Lenovo Group ) C:\Users\Martina\Downloads\cagt26ww.exe 2013-07-12 13:06 - 2013-07-12 13:06 - 00000000 ____D C:\Program Files (x86)\Secure Banking 2013-07-12 13:03 - 2013-07-12 13:03 - 00441354 _____ (Hopfgartner Niklas ) C:\Users\Martina\Downloads\setup152.exe 2013-07-12 09:38 - 2013-07-12 09:38 - 00000000 ____D C:\Users\Martina\AppData\Local\LSC 2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo 2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\LSC 2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Lenovo 2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Windows\Downloaded Installations 2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-07-12 09:34 - 2013-07-12 09:35 - 33963136 _____ (Lenovo Group Limited) C:\Users\Martina\Downloads\lscsetup_x64_21003.exe 2013-07-12 09:08 - 2013-07-12 09:08 - 03429528 _____ (Lenovo Group ) C:\Users\Martina\Downloads\l1egc02us24.exe 2013-07-11 10:59 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-11 10:59 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-11 10:59 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-11 10:59 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-11 10:59 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-11 10:59 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-11 10:59 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-11 10:59 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-11 10:59 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-11 10:59 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-11 10:59 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-11 10:59 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-11 10:59 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-11 10:59 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-11 10:58 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-11 10:58 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-11 10:58 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-11 10:58 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-11 10:58 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-11 10:58 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-11 10:58 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-11 10:58 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-11 10:58 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-11 10:58 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-11 10:58 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-11 05:44 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 05:44 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 05:44 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-11 05:44 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 05:44 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-11 05:44 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-11 05:44 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-08 09:32 - 2013-07-08 09:34 - 51415040 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x64-de-de.exe 2013-07-08 08:57 - 2013-07-08 08:58 - 30091776 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-07-06 21:57 - 2013-07-06 21:57 - 00070581 _____ C:\Users\Martina\Desktop\Steuer 11.ESt2011 2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\Documents\Steuerfälle 2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\AppData\Local\AAV 2013-07-06 14:40 - 2013-07-12 12:54 - 00000000 ____D C:\Users\Martina\AppData\Roaming\BatteryBar 2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ___HD C:\Lenovo 2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ____D C:\ProgramData\CyberLink 2013-07-06 11:19 - 2013-07-06 11:19 - 00002299 _____ C:\Users\Public\Desktop\Steuer-Spar-Erklärung Selbstständige 2012.lnk 2013-07-06 11:04 - 2013-07-06 11:19 - 00000000 ____D C:\Program Files (x86)\Akademische Arbeitsgemeinschaft 2013-07-06 11:02 - 2013-07-06 11:17 - 00000000 ____D C:\ProgramData\AAV 2013-07-03 14:09 - 2013-07-03 14:09 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Morgen&Morgen 2013-07-03 06:53 - 2013-07-03 06:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-06-30 15:56 - 2013-06-30 15:56 - 00001710 _____ C:\Users\Public\Desktop\Kunden gewinnen am Telefon.lnk 2013-06-30 15:56 - 2013-06-30 15:56 - 00000000 ____D C:\Program Files\Haufe 2013-06-30 15:55 - 1998-11-17 14:44 - 00328704 _____ (InstallShield Software Corporation ) C:\Windows\IsUn0407.exe 2013-06-29 09:27 - 2013-06-29 09:27 - 02828552 _____ (AVAST Software) C:\Users\Martina\Downloads\avast-browser-cleanup_8.0.1484.29.exe 2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick 2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Babylon 2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\ProgramData\Babylon 2013-06-27 00:25 - 2013-06-27 00:26 - 00003718 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml ==================== One Month Modified Files and Folders ======= 2013-07-20 10:22 - 2013-07-20 10:22 - 00000000 ____D C:\FRST 2013-07-20 10:21 - 2013-07-20 10:21 - 01779345 _____ (Farbar) C:\Users\Martina\Downloads\FRST64.exe 2013-07-20 10:17 - 2013-01-06 17:51 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 09:54 - 2013-05-16 17:52 - 00001595 _____ C:\Users\Martina\AppData\Roaming\SAS7_000.DAT 2013-07-20 09:53 - 2013-07-16 01:46 - 00000654 _____ C:\Windows\setupact.log 2013-07-20 09:53 - 2012-12-21 22:41 - 01114481 _____ C:\Windows\WindowsUpdate.log 2013-07-20 09:28 - 2012-12-22 22:31 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-20 05:35 - 2013-01-06 17:51 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 05:24 - 2011-04-12 09:43 - 00654400 _____ C:\Windows\system32\perfh007.dat 2013-07-20 05:24 - 2011-04-12 09:43 - 00130240 _____ C:\Windows\system32\perfc007.dat 2013-07-20 05:24 - 2009-07-14 07:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-19 19:00 - 2013-07-19 19:00 - 00001988 _____ C:\Users\Public\Desktop\GetDataBack for FAT.lnk 2013-07-19 19:00 - 2013-07-19 19:00 - 00000000 ____D C:\Program Files (x86)\Runtime Software 2013-07-19 19:00 - 2012-12-30 13:43 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Skype 2013-07-19 18:42 - 2013-07-19 18:42 - 03723592 _____ (Piriform Ltd) C:\Users\Martina\Downloads\rcsetup147.exe 2013-07-19 18:38 - 2009-07-14 06:45 - 00026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-19 18:38 - 2009-07-14 06:45 - 00026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-19 18:32 - 2013-05-09 10:29 - 00000000 ___RD C:\Users\Martina\Dropbox 2013-07-19 18:32 - 2013-05-09 10:25 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Dropbox 2013-07-19 18:31 - 2013-06-03 13:48 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2013-07-19 18:31 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-19 13:51 - 2013-02-15 14:35 - 00000000 ____D C:\Users\Martina\Documents\02 My Privacy 2013-07-19 13:49 - 2013-07-13 09:53 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A5D247D3-B96E-4A7A-8CC3-F568284A7C55} 2013-07-16 09:12 - 2012-12-29 22:39 - 00000000 ____D C:\Users\Martina 2013-07-16 01:46 - 2013-07-16 01:46 - 00000000 _____ C:\Windows\setuperr.log 2013-07-16 01:44 - 2013-07-16 01:44 - 00010459 _____ C:\Users\Martina\Documents\Mappe1.xlsx 2013-07-15 16:06 - 2013-07-15 15:43 - 00000000 ____D C:\Users\Martina\Documents\01 B U S I N E S S 2013-07-15 16:04 - 2012-12-21 22:48 - 00000000 ____D C:\Users\Neipp BD 2013-07-15 15:53 - 2013-07-15 11:31 - 00000000 ____D C:\Users\Martina\Documents\Lenovo Notebook 2013-07-15 12:39 - 2013-07-15 12:39 - 00001264 _____ C:\Users\Martina\Desktop\Revo Uninstaller.lnk 2013-07-15 12:39 - 2013-07-15 12:39 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-07-15 12:39 - 2013-07-15 12:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Martina\Downloads\revosetup95.exe 2013-07-15 10:57 - 2012-12-26 21:37 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-15 10:57 - 2012-12-26 21:37 - 00000000 ____D C:\ProgramData\Skype 2013-07-14 13:29 - 2013-07-14 13:29 - 00003110 _____ C:\Windows\System32\Tasks\{E645551B-CF7C-4A84-BA2A-BE7C4FDB61BD} 2013-07-14 13:29 - 2013-05-25 13:59 - 00000000 ____D C:\Program Files (x86)\MahJongg Meister 3 2013-07-14 11:19 - 2013-06-19 10:00 - 00000000 ____D C:\Program Files\CCleaner 2013-07-14 11:17 - 2013-07-14 11:17 - 03357912 _____ (Piriform Ltd) C:\Users\Martina\Downloads\ccsetup403_slim.exe 2013-07-14 11:16 - 2012-12-21 22:37 - 00000000 ____D C:\Windows\Panther 2013-07-14 11:08 - 2013-07-14 11:08 - 00000000 ____D C:\Users\Martina\AppData\Local\PDF24 2013-07-14 10:29 - 2013-07-14 10:28 - 00000000 ____D C:\Users\Neipp BD\Bilder 2013-07-14 10:06 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-07-14 09:30 - 2012-12-30 10:03 - 00002155 _____ C:\Windows\epplauncher.mif 2013-07-14 09:29 - 2012-12-30 10:03 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-07-14 09:28 - 2012-12-30 10:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-07-14 09:27 - 2013-07-14 09:25 - 00000000 ____D C:\Windows\system32\MRT 2013-07-13 15:28 - 2013-01-03 18:49 - 00000000 ____D C:\Users\Martina\AppData\Roaming\vlc 2013-07-13 15:21 - 2013-07-13 15:21 - 00013312 ___SH C:\Users\Martina\Desktop\Thumbs.db 2013-07-12 13:12 - 2012-12-29 22:39 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2013-07-12 13:12 - 2012-12-21 22:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-12 13:12 - 2012-12-21 16:17 - 00000000 ____D C:\Program Files\Lenovo 2013-07-12 13:12 - 2012-12-21 16:11 - 00000000 ____D C:\Program Files (x86)\Lenovo 2013-07-12 13:11 - 2013-07-12 13:12 - 00039008 _____ (Lenovo.) C:\Windows\system32\Drivers\LhdX64.sys 2013-07-12 13:11 - 2013-07-12 13:10 - 22302856 _____ (Lenovo Group ) C:\Users\Martina\Downloads\cagt26ww.exe 2013-07-12 13:11 - 2012-12-21 16:17 - 00019872 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoSDKEmSubSystem.dll 2013-07-12 13:11 - 2012-12-21 16:16 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-12 13:06 - 2013-07-12 13:06 - 00000000 ____D C:\Program Files (x86)\Secure Banking 2013-07-12 13:03 - 2013-07-12 13:03 - 00441354 _____ (Hopfgartner Niklas ) C:\Users\Martina\Downloads\setup152.exe 2013-07-12 12:58 - 2013-02-28 17:03 - 00000000 ____D C:\ProgramData\Energy Management 2013-07-12 12:54 - 2013-07-06 14:40 - 00000000 ____D C:\Users\Martina\AppData\Roaming\BatteryBar 2013-07-12 09:38 - 2013-07-12 09:38 - 00000000 ____D C:\Users\Martina\AppData\Local\LSC 2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo 2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\LSC 2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Lenovo 2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Windows\Downloaded Installations 2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-07-12 09:36 - 2012-12-30 00:31 - 00000000 ____D C:\Users\Martina\AppData\Local\Adobe 2013-07-12 09:36 - 2012-12-30 00:24 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Adobe 2013-07-12 09:36 - 2012-12-22 12:23 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-12 09:36 - 2012-12-22 12:21 - 00000000 ____D C:\ProgramData\Adobe 2013-07-12 09:35 - 2013-07-12 09:34 - 33963136 _____ (Lenovo Group Limited) C:\Users\Martina\Downloads\lscsetup_x64_21003.exe 2013-07-12 09:08 - 2013-07-12 09:08 - 03429528 _____ (Lenovo Group ) C:\Users\Martina\Downloads\l1egc02us24.exe 2013-07-12 04:12 - 2013-01-06 17:51 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-12 04:12 - 2013-01-06 17:51 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-11 11:10 - 2009-07-14 06:45 - 00337048 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-11 11:09 - 2013-03-14 04:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-11 11:09 - 2013-03-14 04:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-11 11:08 - 2011-04-12 09:55 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 11:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-11 11:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-11 10:59 - 2012-12-27 01:55 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-08 09:34 - 2013-07-08 09:32 - 51415040 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x64-de-de.exe 2013-07-08 08:58 - 2013-07-08 08:57 - 30091776 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-07-06 21:57 - 2013-07-06 21:57 - 00070581 _____ C:\Users\Martina\Desktop\Steuer 11.ESt2011 2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\Documents\Steuerfälle 2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\AppData\Local\AAV 2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ___HD C:\Lenovo 2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ____D C:\ProgramData\CyberLink 2013-07-06 14:23 - 2012-12-22 11:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-06 11:19 - 2013-07-06 11:19 - 00002299 _____ C:\Users\Public\Desktop\Steuer-Spar-Erklärung Selbstständige 2012.lnk 2013-07-06 11:19 - 2013-07-06 11:04 - 00000000 ____D C:\Program Files (x86)\Akademische Arbeitsgemeinschaft 2013-07-06 11:17 - 2013-07-06 11:02 - 00000000 ____D C:\ProgramData\AAV 2013-07-06 08:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-03 14:09 - 2013-07-03 14:09 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Morgen&Morgen 2013-07-03 06:53 - 2013-07-03 06:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 01:10 - 2013-02-01 10:43 - 00000000 ____D C:\ProgramData\lexware 2013-07-02 00:51 - 2013-02-01 10:44 - 00000000 ____D C:\ProgramData\BTrieve 2013-06-30 15:56 - 2013-06-30 15:56 - 00001710 _____ C:\Users\Public\Desktop\Kunden gewinnen am Telefon.lnk 2013-06-30 15:56 - 2013-06-30 15:56 - 00000000 ____D C:\Program Files\Haufe 2013-06-29 09:27 - 2013-06-29 09:27 - 02828552 _____ (AVAST Software) C:\Users\Martina\Downloads\avast-browser-cleanup_8.0.1484.29.exe 2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick 2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Babylon 2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\ProgramData\Babylon 2013-06-29 09:19 - 2012-12-27 02:25 - 00000000 ____D C:\Program Files (x86)\PicPick 2013-06-27 00:26 - 2013-06-27 00:25 - 00003718 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2013-06-27 00:26 - 2012-12-27 02:25 - 00045856 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2013-06-27 00:26 - 2012-12-27 02:25 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2013-06-24 00:57 - 2012-12-21 17:10 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-13 00:18 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- Ist das so richtig? Dann kommt jetzt der Addition.txt ... Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-07-2013 Ran by Martina at 2013-07-20 10:23:49 Running from C:\Users\Martina\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= AAVUpdateManager (x32 Version: 18.00.0000) Adobe AIR (x32 Version: 3.7.0.2090) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Flash Player ActiveX (x32 Version: 9.0.124.0) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Amazon Kindle (HKCU) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.0.14.15) CCleaner (Version: 4.03) Conexant HD Audio (Version: 8.54.32.50) ConvertHelper 2.2 (x32) DirPrintOK (x32) Dolby Advanced Audio v2 (x32 Version: 7.2.7000.11) dows-Treiberpaket - Lenovo (ACPIVPC) System (12/15/2011 7.1.0.1) (Version: 12/15/2011 7.1.0.1) Dragon NaturallySpeaking 11 (x32 Version: 11.50.100) Dropbox (HKCU Version: 2.0.22) Energy Management (x32 Version: 7.0.3.4) Evernote v. 4.6.6 (x32 Version: 4.6.6.8360) FormatFactory 3.0.1 (x32 Version: 3.0.1) Free FLV Converter V 7.5.0 (x32 Version: 7.5.0.0) GetDataBack for FAT (x32 Version: 4.33.000) Google Earth Plug-in (x32 Version: 7.0.3.8542) Google Update Helper (x32 Version: 1.3.21.153) Grewe Scanner-Interface 7 (x32 Version: 7) Haufe iDesk-Browser (x32 Version: 10.10.14.0000) Haufe iDesk-Service (x32 Version: 10.10.25.7810) HP FWUpdateEDO2 (x32 Version: 1.2.0.0) HP Officejet Pro 8600 - Grundlegende Software für das Gerät (Version: 25.0.619.0) HP Officejet Pro 8600 Hilfe (x32 Version: 140.0.2.2) HP Update (x32 Version: 5.003.000.004) HPDiagnosticAlert (x32 Version: 1.00.0000) I.R.I.S. OCR (x32 Version: 12.3.4.0) Intel PROSet Wireless Intel(R) Management Engine Components (x32 Version: 8.0.3.1427) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2656) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: 15.0.0.0059) Intel(R) Rapid Storage Technology (x32 Version: 11.0.0.1032) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.5.235) Intel® PROSet/Wireless WiFi-Software (Version: 15.00.0000.0642) Intel® Trusted Connect Service Client (Version: 1.23.605.1) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Java(TM) 6 Update 13 (64-bit) (Version: 6.0.130) Java(TM) 6 Update 2 (x32 Version: 1.6.0.20) Join Air (x32 Version: 1.0.0.1) Klett Mathetrainer 10 (x32) Kunden gewinnen am Telefon (x32) KV-WIN (x32 Version: 7.113.6) Lenovo EasyCamera (x32 Version: 13.11.1206.1) Lenovo OneKey Recovery (Version: 7.0.0.3712) Lenovo OneKey Recovery (x32 Version: 7.0.0.3712) Lenovo pointing device (Version: 11.4.3.3) Lenovo Solution Center (Version: 2.1.003.00) Lenovo_Wireless_Driver (x32 Version: 1.02.01) Lexware buchhalter 2011 (x32 Version: 16.00.00.0070) Lexware Datenbank plus 2011 (x32 Version: 11.00.00.0061) Lexware Elster (x32 Version: 9.10.00.0041) Lexware Info Service (x32 Version: 2.70.00.0081) Lexware online banking (x32 Version: 11.00.00.0039) Lexware reisekosten 2009 (x32 Version: 16.00.00.0054) Lexware reisekosten plus 2011 (x32 Version: 11.00.00.0076) LV-WIN (x32 Version: 7.113.6) McAfee Security Scan Plus (x32 Version: 3.0.318.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Security Client (Version: 4.3.0215.0) Microsoft Security Essentials (Version: 4.3.215.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0) NVIDIA Grafiktreiber 296.96 (Version: 296.96) NVIDIA Install Application (Version: 2.1002.62.312) NVIDIA Optimus 1.7.13 (Version: 1.7.13) NVIDIA PhysX (x32 Version: 9.12.0613) NVIDIA PhysX-Systemsoftware 9.12.0613 (Version: 9.12.0613) NVIDIA Systemsteuerung 296.96 (Version: 296.96) NVIDIA Update 1.7.13 (Version: 1.7.13) NVIDIA Update Components (Version: 1.7.13) PDF24 Creator 5.5.0 (x32) PDFCreator (x32 Version: 1.7.0) PicPick (x32 Version: 3.2.6) QuickSteuer Deluxe 2010 (x32 Version: 16.14.00.0002) QuickSteuer Deluxe 2011 (x32 Version: 17.00.00.0065) QuickSteuer DELUXE Wissens-Center 2010 (x32 Version: 16.0.2.0) QuickSteuer DELUXE Wissens-Center 2011 (x32 Version: 17.0.0.0) Realtek USB 2.0 Reader Driver (x32 Version: 6.1.7601.39016) RENESIS® Player Browser Plugins (x32 Version: 1.1.1) Revo Uninstaller 1.95 (x32 Version: 1.95) ScanSoft PDF Converter (x32 Version: 1.00.0000) Secure Banking Version 1.5.2 (x32 Version: 1.5.2) Sentinel Protection Installer 7.6.3 (x32 Version: 7.6.3) Servicepack Datumsaktualisierung (x32 Version: 1.00.00.0005) Skype Click to Call (x32 Version: 6.3.11079) Skype™ 6.6 (x32 Version: 6.6.106) Softwarenetz Haushaltsbuch4 (x32) Steuer-Spar-Erklärung Selbstständige 2012 (x32 Version: 17.13) Studie zur Verbesserung von HP Officejet Pro 8600 Produkten (Version: 25.0.619.0) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (Version: 11.0.200) VLC media player 2.0.5 (Version: 2.0.5) ==================== Restore Points ========================= 12-07-2013 07:11:08 Installed EnergyCut 12-07-2013 07:36:48 Installed Lenovo Solution Center. 12-07-2013 10:57:58 Entfernt Energy Management 12-07-2013 10:59:47 Removed EnergyCut 12-07-2013 11:12:08 Installiert Energy Management 12-07-2013 14:59:45 Windows-Sicherung 12-07-2013 15:09:15 Windows-Sicherung 12-07-2013 15:13:16 Windows-Sicherung 13-07-2013 13:18:16 Windows-Sicherung 13-07-2013 13:41:37 Windows-Sicherung 13-07-2013 13:59:54 Windows-Sicherung 14-07-2013 07:25:26 Windows Update 14-07-2013 08:33:00 Removed PDF Architect 14-07-2013 08:54:15 Removed Adobe Flash Player 9 ActiveX. 17-07-2013 10:07:22 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {060FBA53-CAEA-4C06-BE03-6BB2C37CCE4A} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {0CDF6CEA-695C-4517-AD5E-A56543CB48FB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3436055512-94652675-3813047270-1000 Task: {121E87B3-8750-40E6-BCD3-598C7236A11E} - System32\Tasks\WPD\SqmUpload_S-1-5-21-3436055512-94652675-3813047270-1002 => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {3E9B42C4-E851-4FFF-92AE-BFA3AA18630A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {4616CD2E-1096-4017-BFB0-C9CE649ED1B9} - System32\Tasks\User_Feed_Synchronization-{A5D247D3-B96E-4A7A-8CC3-F568284A7C55} => C:\Windows\system32\msfeedssync.exe [2013-05-24] (Microsoft Corporation) Task: {47DC3F0A-F9B0-4FA5-AD46-089CC8C6890A} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-06-20] (Microsoft Corporation) Task: {4FCE486B-C487-49BA-8680-76547F961258} - System32\Tasks\User_Feed_Synchronization-{00E477AE-69B0-4A65-BD2E-2E3EA31B996C} => C:\Windows\system32\msfeedssync.exe [2013-05-24] (Microsoft Corporation) Task: {52C546A2-267B-4511-90DB-5A034E94896B} - System32\Tasks\HPCustParticipation HP Officejet Pro 8600 => C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPCustPartic.exe [2011-09-09] (Hewlett-Packard Co.) Task: {5FE5B722-CDDD-4D43-8A78-2AD0702A311E} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{A191360B-D6B0-468A-B911-60203C23C8A0}.exe No File Task: {74DEF71A-3873-476E-AFBF-5E2AEE6DA062} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-05-17] (Lenovo) Task: {75F96F2A-B5F6-462B-9EC3-E3DD4493CC10} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-06] (Google Inc.) Task: {8482BDA2-0F9A-4C5A-B5F5-2B10C4D8AD00} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated) Task: {8EA32C18-CE36-402A-BF33-EF08D31B69A7} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-05-17] (Lenovo) Task: {9AE9F1CA-DFFB-406D-AC79-0A286BEA96EA} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation) Task: {A45D167C-2F4D-481A-8493-B24AC85C30BD} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-05-17] () Task: {F67C7407-99E0-4B8E-B9D5-C003AD6609E0} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {F7354EC3-1571-43A0-ACC3-E5372D30C450} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-06] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{A191360B-D6B0-468A-B911-60203C23C8A0}.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/19/2013 06:37:47 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 22.0.0.4917, Zeitstempel: 0x51c06b1b Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x2b48fc58 ID des fehlerhaften Prozesses: 0x11c0 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (07/19/2013 06:31:48 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/19/2013 04:02:45 PM) (Source: Microsoft-Windows-User Profiles Service) (User: ZIEGENER) Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren. Error: (07/19/2013 04:02:45 PM) (Source: Microsoft-Windows-User Profiles Service) (User: ZIEGENER) Description: Dieses Benutzerprofil wurde gesichert. Bei der nächsten Anmeldung dieses Benutzers wird automatisch versucht, dieses gesicherte Profil zu verwenden. Error: (07/19/2013 03:44:38 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/19/2013 03:33:54 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 12.0.6668.5000, Zeitstempel: 0x508314b2 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000374 Fehleroffset: 0x000ce6c3 ID des fehlerhaften Prozesses: 0x16e0 Startzeit der fehlerhaften Anwendung: 0xOUTLOOK.EXE0 Pfad der fehlerhaften Anwendung: OUTLOOK.EXE1 Pfad des fehlerhaften Moduls: OUTLOOK.EXE2 Berichtskennung: OUTLOOK.EXE3 Error: (07/19/2013 09:50:41 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: WINWORD.EXE, Version: 12.0.6668.5000, Zeitstempel: 0x5083137f Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f Ausnahmecode: 0xc0000374 Fehleroffset: 0x000ce6c3 ID des fehlerhaften Prozesses: 0x1dc4 Startzeit der fehlerhaften Anwendung: 0xWINWORD.EXE0 Pfad der fehlerhaften Anwendung: WINWORD.EXE1 Pfad des fehlerhaften Moduls: WINWORD.EXE2 Berichtskennung: WINWORD.EXE3 Error: (07/19/2013 09:50:41 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: sidebar.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7a1c7 Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c92c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000029fa9 ID des fehlerhaften Prozesses: 0xd7c Startzeit der fehlerhaften Anwendung: 0xsidebar.exe0 Pfad der fehlerhaften Anwendung: sidebar.exe1 Pfad des fehlerhaften Moduls: sidebar.exe2 Berichtskennung: sidebar.exe3 Error: (07/19/2013 09:42:36 AM) (Source: Application Hang) (User: ) Description: Programm natspeak.exe, Version 11.50.100.40 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1a48 Startzeit: 01ce844d994eebf5 Endzeit: 10 Anwendungspfad: C:\Program Files (x86)\Nuance\NaturallySpeaking11\Program\natspeak.exe Berichts-ID: b5f1c661-f046-11e2-9537-b888e38fdbd0 Error: (07/19/2013 08:57:53 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bca54 Name des fehlerhaften Moduls: igdumd64.dll, Version: 8.15.10.2656, Zeitstempel: 0x4f3e8e4b Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000030ed16 ID des fehlerhaften Prozesses: 0x1750 Startzeit der fehlerhaften Anwendung: 0xDllHost.exe0 Pfad der fehlerhaften Anwendung: DllHost.exe1 Pfad des fehlerhaften Moduls: DllHost.exe2 Berichtskennung: DllHost.exe3 System errors: ============= Error: (07/20/2013 10:09:05 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/20/2013 10:07:51 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/20/2013 10:06:23 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/19/2013 07:04:36 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/19/2013 03:36:06 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (07/19/2013 03:36:06 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (07/19/2013 03:36:05 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2. Error: (07/17/2013 06:52:29 AM) (Source: Microsoft Antimalware) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.155.29.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.3.0215.00 Quellpfad: 4.3.0215.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (07/16/2013 01:11:03 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/14/2013 10:34:51 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet: %%-2147467259 Microsoft Office Sessions: ========================= Error: (07/13/2013 03:47:02 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1331 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/31/2013 10:03:05 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 121 seconds with 60 seconds of active time. This session ended with a crash. Error: (01/04/2013 01:37:31 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 41323 seconds with 4140 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 65% Total physical RAM: 3995.28 MB Available physical RAM: 1372.35 MB Total Pagefile: 7988.74 MB Available Pagefile: 4845.13 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.54 GB) (Free:386.67 GB) NTFS (Disk=0 Partition=3) Drive e: () (Fixed) (Total:465.65 GB) (Free:325.17 GB) FAT32 (Disk=1 Partition=1) ==================== MBR & Partition Table ================== ==================== End Of Log ============================ |
20.07.2013, 10:46 | #4 | |
/// the machine /// TB-Ausbilder | Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Malware ist da keine. Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.07.2013, 10:51 | #5 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Ja genau diese Platte ... hierhin habe ich ein Backup gemacht ... und wenn ich jetzt sehe was GetDataBack a liefert, dann sind die Daten meiner Backups und der des Java-Downloads identisch ... 12./13.07. ... Kann ich Dir denn hier i-wie Bilder reinstellen? |
20.07.2013, 10:55 | #6 |
/// the machine /// TB-Ausbilder | Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Ja, unten auf erweitert klicken, Anhänge verwalten, dort kannste sie anhängen.
__________________ --> Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? |
20.07.2013, 10:59 | #7 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? [IMG]C:\Users\Martina\Desktop\Bild 003.jpg[/IMG] test ... |
20.07.2013, 11:05 | #8 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? C:\Users\Martina\Desktop\Bild 003.jpg |
20.07.2013, 11:09 | #9 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? diese Screenshots habe ich heute im Laufe des Vormittags erstellt ... |
20.07.2013, 11:10 | #10 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? darauf erkenne ich meine Daten auf der Festplatte wieder ... aber ich komme nicht dran ... |
20.07.2013, 11:15 | #11 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? und hier sehe ich die Daten des Backups / der Backups ... auch 12./13.07. ... |
20.07.2013, 11:42 | #12 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? der PC meldet seit ein oder zwei Tagen immer wieder COM SURROGATE reagiert nicht ... (nur so als Hintergrundinfo) |
20.07.2013, 15:55 | #13 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Ich habe jetzt mal Recuva (free-Version) drüberlaufen lassen ... wenn ich danach gehe, sind die meisten Daten scheinbar unwiederherstellbar ... |
20.07.2013, 20:04 | #14 |
/// the machine /// TB-Ausbilder | Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? in dem obigen Bild steht doch dass Du die Daten retten kannst wenn Du ne Lizenz kaufst oder? Ich wüsste jetzt spontan auch nit wie Du da dran kommst. Sind die daten wichtig? Warum ist die Platte in FAT32 formatiert?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.07.2013, 20:29 | #15 |
| Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? Hallo Schrauber, die Lizenz soll um die 90 € kosten ... meinst Du denn, dass ich da wirklich eine Chance habe? Ich habe so gar keine Ahnung ... aber so unbekannt ist das Programm ja wohl nicht ... Werd wohl mal drüber schlafen, ob diese Investition sinnvoll ist. Ich habe die Platte so bekommen mit FAT formatiert ... worauf zielst Du mit Deiner Frage ab? Gruß Tina |
Themen zu Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ? |
anderen, chkdsk, daten, eingefangen, erstellt, exploit, externe festplatte, festplatte, hallo zusammen, hilfreiche, hinweis, java-update, meldet, neu, nicht mehr, ordner, platte, problem, quarantäne, rechner, suche, verlauf, virus, win, wirklich, woche |