Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Hallo zusammen - bin neu hier - und noch völlig irritert

Obwohl auf dieser 500 GB-Platte ca. 130 MB belegt sind (was ich über Eigenschaften auch nach wie vor sehen kann), kann ich die Daten nicht mehr einsehen.
Auch nicht auf einem anderen PC ...

Nun suche ich und grüble nach möglichen Ursachen ...

Arbeite unter Win 7 (64 bit) und habe mir vor ein paar Tagen aus gegebenem Anlass eine "Schattenkopie (?)" auf diese Festplatte erstellt ...

Habe bisher mit chkdsk geprüft und aktuell läuft die Freeware-Version von GetDataBack drüber (seit mehr als 12 Stunden) ...

Würde gern 2 Screenshots hier reinstellen, weiß aber leider nicht wie das mit der URL geht ...

Der MSE-Bildschirm meldet im Verlauf vom 12./13.Juli den " exploit java/cve-2012-0507 " den ich mir wohl verg. Woche über ein Java-Update eingefangen habe ...

aber er meldet auch, dass er diesen unter Quarantäne gestellt und keine Schadsoftware auf meinem Rechner gefunden habe.

Kann dieser Virus etwas mit dem Problem auf meiner ext. Festplatte zu tun haben?

Was ist zu tun?

Ich wäre wirklich sehr dankbar für hilfreichen Hinweis ...

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-07-2013
Ran by Martina (administrator) on 20-07-2013 10:23:15
Running from C:\Users\Martina\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(iAnywhere Solutions, Inc.) C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
(SafeNet, Inc) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Secure Banking) C:\Program Files (x86)\Secure Banking\SecureBanking.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
(Dropbox, Inc.) C:\Users\Martina\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Secure Banking\sbservice.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files (x86)\Join Air\UIExec.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\bin\HPNetworkCommunicator.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Runtime Software) C:\Program Files (x86)\Runtime Software\GetDataBack\gdb.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\system32\taskmgr.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\NaturallySpeaking11\Program\natspeak.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking11\dgnuiasvr.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking11\dgnuiasvr_x64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [UpdatePRCShortCut] - C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-06-20] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [170496 2013-02-01] (Sun Microsystems, Inc.)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2013-07-12] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6199128 2013-07-12] (Lenovo(beijing) Limited)
HKCU\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe [11480920 2013-06-19] (NTeWORKS)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [HP Officejet Pro 8600 (NET)] - C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2676584 2011-09-09] (Hewlett-Packard Co.)
HKCU\...\Run: [SecureBanking] - C:\Program Files (x86)\Secure Banking\SecureBanking.exe [507904 2013-06-30] (Secure Banking)
HKCU\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe [1475584 2010-11-21] (Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart [507744 2011-12-20] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [331BigDog] - C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-11-24] (Vimicro)
HKLM-x32\...\Run: [UpdatePRCShortCut] - "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [] -  [x]
HKLM-x32\...\Run: [UIExec] - "C:\Program Files (x86)\Join Air\UIExec.exe" [132608 2009-08-31] ()
HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [DNS7reminder] - "C:\Program Files (x86)\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini" [328992 2010-10-27] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [PDF Converter Registry Controller] - "C:\Program Files (x86)\ScanSoft\PDF Converter\RegistryController.exe" [102400 2003-08-19] (ScanSoft, Inc.)
HKLM-x32\...\Run: [PDFConverterReminder] - "C:\PROGRA~2\ScanSoft\PDFCON~1\EReg\EReg.exe" -r "C:\PROGRA~2\ScanSoft\PDFCON~1\EReg\ereg.ini" [729088 2003-08-19] ()
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-05-30] (Geek Software GmbH)
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe /show [52584 2013-05-17] (Lenovo)
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe /show [52584 2013-05-17] (Lenovo)
HKU\Neipp BD\...\Run: [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19875432 2013-06-21] (Skype Technologies S.A.)
HKU\Neipp BD\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe /startup [11480920 2013-06-19] (NTeWORKS)
HKU\Neipp BD\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - "C:\Program Files (x86)\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe"  /PROMPT /CMPID=JUNE2013_TB [1266712 2013-06-03] (AVG Secure Search)
AppInit_DLLs:     C:\Windows\system32\nvinitx.dll [1266712 2013-06-03] ()
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll [215400 2012-06-22] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Martina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet Pro 8600\bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms}
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B2A2C0143DD1AD17&affID=120695&tt=250613_gr5&tsp=4928
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=0&systemid=413&apn_dtid=BND413&apn_ptnrs=AGA&o=APN10649&apn_uid=3145427514454419&q={searchTerms}
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: haufereader - No CLSID Value - 
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: haufereader - No CLSID Value - 
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default
FF user.js: detected! => C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\searchplugins\delta.xml
FF SearchPlugin: C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\searchplugins\webwebweb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
FF Extension: HTTPS-Everywhere - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\https-everywhere@eff.org
FF Extension: DownloadHelper - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: about-addons-memory - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\about-addons-memory@tn123.org.xpi
FF Extension: ffext_basicchromeext - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\ffext_basicchromeext@startpage24.xpi
FF Extension: suspendbackgroundtabs - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\suspendbackgroundtabs@adblockplus.org.xpi
FF Extension: tfdlookup - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\tfdlookup@nohup.in.xpi
FF Extension: No Name - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi
FF Extension: No Name - C:\Users\Martina\AppData\Roaming\Mozilla\Firefox\Profiles\l8g5kgzc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] C:\ProgramData\AVG Secure Search\FireFoxExt\

==================== Services (Whitelisted) =================

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 HRService; C:\Program Files (x86)\Haufe\iDesk\iDeskService\iDeskService.exe [71024 2010-10-25] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation)
R2 Lexware_Datenbank_Plus; C:\Program Files (x86)\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [83248 2010-11-05] (iAnywhere Solutions, Inc.)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-06-20] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-06-20] (Microsoft Corporation)
R2 SentinelKeysServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [374048 2010-10-20] (SafeNet, Inc.)
R2 SentinelProtectionServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1250592 2010-10-20] (SafeNet, Inc)
R2 SentinelSecurityRuntime; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [292128 2010-10-20] (SafeNet, Inc.)
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [241664 2009-08-31] ()
R2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [1598128 2013-06-27] (AVG Secure Search)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-06-27] (AVG Technologies)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [59048 2010-10-20] (SafeNet, Inc.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [952832 2011-12-06] (Vimicro Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-07-20 10:22 - 2013-07-20 10:22 - 00000000 ____D C:\FRST
2013-07-20 10:21 - 2013-07-20 10:21 - 01779345 _____ (Farbar) C:\Users\Martina\Downloads\FRST64.exe
2013-07-19 19:00 - 2013-07-19 19:00 - 00001988 _____ C:\Users\Public\Desktop\GetDataBack for FAT.lnk
2013-07-19 19:00 - 2013-07-19 19:00 - 00000000 ____D C:\Program Files (x86)\Runtime Software
2013-07-19 18:42 - 2013-07-19 18:42 - 03723592 _____ (Piriform Ltd) C:\Users\Martina\Downloads\rcsetup147.exe
2013-07-16 01:46 - 2013-07-20 09:53 - 00000654 _____ C:\Windows\setupact.log
2013-07-16 01:46 - 2013-07-16 01:46 - 00000000 _____ C:\Windows\setuperr.log
2013-07-16 01:44 - 2013-07-16 01:44 - 00010459 _____ C:\Users\Martina\Documents\Mappe1.xlsx
2013-07-15 15:43 - 2013-07-15 16:06 - 00000000 ____D C:\Users\Martina\Documents\01 B U S I N E S S
2013-07-15 12:39 - 2013-07-15 12:39 - 00001264 _____ C:\Users\Martina\Desktop\Revo Uninstaller.lnk
2013-07-15 12:39 - 2013-07-15 12:39 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-07-15 12:38 - 2013-07-15 12:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Martina\Downloads\revosetup95.exe
2013-07-15 11:31 - 2013-07-15 15:53 - 00000000 ____D C:\Users\Martina\Documents\Lenovo Notebook
2013-07-14 13:29 - 2013-07-14 13:29 - 00003110 _____ C:\Windows\System32\Tasks\{E645551B-CF7C-4A84-BA2A-BE7C4FDB61BD}
2013-07-14 11:17 - 2013-07-14 11:17 - 03357912 _____ (Piriform Ltd) C:\Users\Martina\Downloads\ccsetup403_slim.exe
2013-07-14 11:08 - 2013-07-14 11:08 - 00000000 ____D C:\Users\Martina\AppData\Local\PDF24
2013-07-14 10:28 - 2013-07-14 10:29 - 00000000 ____D C:\Users\Neipp BD\Bilder
2013-07-14 09:25 - 2013-07-14 09:27 - 00000000 ____D C:\Windows\system32\MRT
2013-07-13 15:21 - 2013-07-13 15:21 - 00013312 ___SH C:\Users\Martina\Desktop\Thumbs.db
2013-07-13 09:53 - 2013-07-19 13:49 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A5D247D3-B96E-4A7A-8CC3-F568284A7C55}
2013-07-12 13:12 - 2013-07-12 13:11 - 00039008 _____ (Lenovo.) C:\Windows\system32\Drivers\LhdX64.sys
2013-07-12 13:10 - 2013-07-12 13:11 - 22302856 _____ (Lenovo Group                                                ) C:\Users\Martina\Downloads\cagt26ww.exe
2013-07-12 13:06 - 2013-07-12 13:06 - 00000000 ____D C:\Program Files (x86)\Secure Banking
2013-07-12 13:03 - 2013-07-12 13:03 - 00441354 _____ (Hopfgartner Niklas                                          ) C:\Users\Martina\Downloads\setup152.exe
2013-07-12 09:38 - 2013-07-12 09:38 - 00000000 ____D C:\Users\Martina\AppData\Local\LSC
2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\LSC
2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Lenovo
2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Windows\Downloaded Installations
2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-07-12 09:34 - 2013-07-12 09:35 - 33963136 _____ (Lenovo Group Limited) C:\Users\Martina\Downloads\lscsetup_x64_21003.exe
2013-07-12 09:08 - 2013-07-12 09:08 - 03429528 _____ (Lenovo Group                                                ) C:\Users\Martina\Downloads\l1egc02us24.exe
2013-07-11 10:59 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 10:59 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 10:59 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 10:59 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 10:59 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 10:59 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 10:59 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 10:59 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 10:59 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 10:59 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 10:59 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 10:59 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-11 10:59 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 10:59 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 10:58 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 10:58 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-11 10:58 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 10:58 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 10:58 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-11 10:58 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 10:58 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 10:58 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 10:58 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 10:58 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 10:58 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 05:44 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 05:44 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 05:44 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 05:44 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 05:44 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 05:44 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 05:44 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-08 09:32 - 2013-07-08 09:34 - 51415040 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x64-de-de.exe
2013-07-08 08:57 - 2013-07-08 08:58 - 30091776 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe
2013-07-06 21:57 - 2013-07-06 21:57 - 00070581 _____ C:\Users\Martina\Desktop\Steuer 11.ESt2011
2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\Documents\Steuerfälle
2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\AppData\Local\AAV
2013-07-06 14:40 - 2013-07-12 12:54 - 00000000 ____D C:\Users\Martina\AppData\Roaming\BatteryBar
2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ___HD C:\Lenovo
2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ____D C:\ProgramData\CyberLink
2013-07-06 11:19 - 2013-07-06 11:19 - 00002299 _____ C:\Users\Public\Desktop\Steuer-Spar-Erklärung Selbstständige 2012.lnk
2013-07-06 11:04 - 2013-07-06 11:19 - 00000000 ____D C:\Program Files (x86)\Akademische Arbeitsgemeinschaft
2013-07-06 11:02 - 2013-07-06 11:17 - 00000000 ____D C:\ProgramData\AAV
2013-07-03 14:09 - 2013-07-03 14:09 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Morgen&Morgen
2013-07-03 06:53 - 2013-07-03 06:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-30 15:56 - 2013-06-30 15:56 - 00001710 _____ C:\Users\Public\Desktop\Kunden gewinnen am Telefon.lnk
2013-06-30 15:56 - 2013-06-30 15:56 - 00000000 ____D C:\Program Files\Haufe
2013-06-30 15:55 - 1998-11-17 14:44 - 00328704 _____ (InstallShield Software Corporation ) C:\Windows\IsUn0407.exe
2013-06-29 09:27 - 2013-06-29 09:27 - 02828552 _____ (AVAST Software) C:\Users\Martina\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Babylon
2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\ProgramData\Babylon
2013-06-27 00:25 - 2013-06-27 00:26 - 00003718 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml

==================== One Month Modified Files and Folders =======

2013-07-20 10:22 - 2013-07-20 10:22 - 00000000 ____D C:\FRST
2013-07-20 10:21 - 2013-07-20 10:21 - 01779345 _____ (Farbar) C:\Users\Martina\Downloads\FRST64.exe
2013-07-20 10:17 - 2013-01-06 17:51 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-20 09:54 - 2013-05-16 17:52 - 00001595 _____ C:\Users\Martina\AppData\Roaming\SAS7_000.DAT
2013-07-20 09:53 - 2013-07-16 01:46 - 00000654 _____ C:\Windows\setupact.log
2013-07-20 09:53 - 2012-12-21 22:41 - 01114481 _____ C:\Windows\WindowsUpdate.log
2013-07-20 09:28 - 2012-12-22 22:31 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-20 05:35 - 2013-01-06 17:51 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-20 05:24 - 2011-04-12 09:43 - 00654400 _____ C:\Windows\system32\perfh007.dat
2013-07-20 05:24 - 2011-04-12 09:43 - 00130240 _____ C:\Windows\system32\perfc007.dat
2013-07-20 05:24 - 2009-07-14 07:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-19 19:00 - 2013-07-19 19:00 - 00001988 _____ C:\Users\Public\Desktop\GetDataBack for FAT.lnk
2013-07-19 19:00 - 2013-07-19 19:00 - 00000000 ____D C:\Program Files (x86)\Runtime Software
2013-07-19 19:00 - 2012-12-30 13:43 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Skype
2013-07-19 18:42 - 2013-07-19 18:42 - 03723592 _____ (Piriform Ltd) C:\Users\Martina\Downloads\rcsetup147.exe
2013-07-19 18:38 - 2009-07-14 06:45 - 00026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-19 18:38 - 2009-07-14 06:45 - 00026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-19 18:32 - 2013-05-09 10:29 - 00000000 ___RD C:\Users\Martina\Dropbox
2013-07-19 18:32 - 2013-05-09 10:25 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Dropbox
2013-07-19 18:31 - 2013-06-03 13:48 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2013-07-19 18:31 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-19 13:51 - 2013-02-15 14:35 - 00000000 ____D C:\Users\Martina\Documents\02 My Privacy
2013-07-19 13:49 - 2013-07-13 09:53 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A5D247D3-B96E-4A7A-8CC3-F568284A7C55}
2013-07-16 09:12 - 2012-12-29 22:39 - 00000000 ____D C:\Users\Martina
2013-07-16 01:46 - 2013-07-16 01:46 - 00000000 _____ C:\Windows\setuperr.log
2013-07-16 01:44 - 2013-07-16 01:44 - 00010459 _____ C:\Users\Martina\Documents\Mappe1.xlsx
2013-07-15 16:06 - 2013-07-15 15:43 - 00000000 ____D C:\Users\Martina\Documents\01 B U S I N E S S
2013-07-15 16:04 - 2012-12-21 22:48 - 00000000 ____D C:\Users\Neipp BD
2013-07-15 15:53 - 2013-07-15 11:31 - 00000000 ____D C:\Users\Martina\Documents\Lenovo Notebook
2013-07-15 12:39 - 2013-07-15 12:39 - 00001264 _____ C:\Users\Martina\Desktop\Revo Uninstaller.lnk
2013-07-15 12:39 - 2013-07-15 12:39 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2013-07-15 12:39 - 2013-07-15 12:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Martina\Downloads\revosetup95.exe
2013-07-15 10:57 - 2012-12-26 21:37 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-15 10:57 - 2012-12-26 21:37 - 00000000 ____D C:\ProgramData\Skype
2013-07-14 13:29 - 2013-07-14 13:29 - 00003110 _____ C:\Windows\System32\Tasks\{E645551B-CF7C-4A84-BA2A-BE7C4FDB61BD}
2013-07-14 13:29 - 2013-05-25 13:59 - 00000000 ____D C:\Program Files (x86)\MahJongg Meister 3
2013-07-14 11:19 - 2013-06-19 10:00 - 00000000 ____D C:\Program Files\CCleaner
2013-07-14 11:17 - 2013-07-14 11:17 - 03357912 _____ (Piriform Ltd) C:\Users\Martina\Downloads\ccsetup403_slim.exe
2013-07-14 11:16 - 2012-12-21 22:37 - 00000000 ____D C:\Windows\Panther
2013-07-14 11:08 - 2013-07-14 11:08 - 00000000 ____D C:\Users\Martina\AppData\Local\PDF24
2013-07-14 10:29 - 2013-07-14 10:28 - 00000000 ____D C:\Users\Neipp BD\Bilder
2013-07-14 10:06 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-07-14 09:30 - 2012-12-30 10:03 - 00002155 _____ C:\Windows\epplauncher.mif
2013-07-14 09:29 - 2012-12-30 10:03 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-07-14 09:28 - 2012-12-30 10:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2013-07-14 09:27 - 2013-07-14 09:25 - 00000000 ____D C:\Windows\system32\MRT
2013-07-13 15:28 - 2013-01-03 18:49 - 00000000 ____D C:\Users\Martina\AppData\Roaming\vlc
2013-07-13 15:21 - 2013-07-13 15:21 - 00013312 ___SH C:\Users\Martina\Desktop\Thumbs.db
2013-07-12 13:12 - 2012-12-29 22:39 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2013-07-12 13:12 - 2012-12-21 22:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-12 13:12 - 2012-12-21 16:17 - 00000000 ____D C:\Program Files\Lenovo
2013-07-12 13:12 - 2012-12-21 16:11 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-07-12 13:11 - 2013-07-12 13:12 - 00039008 _____ (Lenovo.) C:\Windows\system32\Drivers\LhdX64.sys
2013-07-12 13:11 - 2013-07-12 13:10 - 22302856 _____ (Lenovo Group                                                ) C:\Users\Martina\Downloads\cagt26ww.exe
2013-07-12 13:11 - 2012-12-21 16:17 - 00019872 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoSDKEmSubSystem.dll
2013-07-12 13:11 - 2012-12-21 16:16 - 00000000 ____D C:\ProgramData\Downloaded Installations
2013-07-12 13:06 - 2013-07-12 13:06 - 00000000 ____D C:\Program Files (x86)\Secure Banking
2013-07-12 13:03 - 2013-07-12 13:03 - 00441354 _____ (Hopfgartner Niklas                                          ) C:\Users\Martina\Downloads\setup152.exe
2013-07-12 12:58 - 2013-02-28 17:03 - 00000000 ____D C:\ProgramData\Energy Management
2013-07-12 12:54 - 2013-07-06 14:40 - 00000000 ____D C:\Users\Martina\AppData\Roaming\BatteryBar
2013-07-12 09:38 - 2013-07-12 09:38 - 00000000 ____D C:\Users\Martina\AppData\Local\LSC
2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\LSC
2013-07-12 09:37 - 2013-07-12 09:37 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Lenovo
2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Windows\Downloaded Installations
2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-07-12 09:36 - 2013-07-12 09:36 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-07-12 09:36 - 2012-12-30 00:31 - 00000000 ____D C:\Users\Martina\AppData\Local\Adobe
2013-07-12 09:36 - 2012-12-30 00:24 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Adobe
2013-07-12 09:36 - 2012-12-22 12:23 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-07-12 09:36 - 2012-12-22 12:21 - 00000000 ____D C:\ProgramData\Adobe
2013-07-12 09:35 - 2013-07-12 09:34 - 33963136 _____ (Lenovo Group Limited) C:\Users\Martina\Downloads\lscsetup_x64_21003.exe
2013-07-12 09:08 - 2013-07-12 09:08 - 03429528 _____ (Lenovo Group                                                ) C:\Users\Martina\Downloads\l1egc02us24.exe
2013-07-12 04:12 - 2013-01-06 17:51 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-12 04:12 - 2013-01-06 17:51 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-11 11:10 - 2009-07-14 06:45 - 00337048 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-11 11:09 - 2013-03-14 04:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 11:09 - 2013-03-14 04:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 11:08 - 2011-04-12 09:55 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-11 11:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-11 11:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-11 10:59 - 2012-12-27 01:55 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-08 09:34 - 2013-07-08 09:32 - 51415040 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x64-de-de.exe
2013-07-08 08:58 - 2013-07-08 08:57 - 30091776 _____ (Microsoft Corporation) C:\Users\Martina\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe
2013-07-06 21:57 - 2013-07-06 21:57 - 00070581 _____ C:\Users\Martina\Desktop\Steuer 11.ESt2011
2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\Documents\Steuerfälle
2013-07-06 15:42 - 2013-07-06 15:42 - 00000000 ____D C:\Users\Martina\AppData\Local\AAV
2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ___HD C:\Lenovo
2013-07-06 14:31 - 2013-07-06 14:31 - 00000000 ____D C:\ProgramData\CyberLink
2013-07-06 14:23 - 2012-12-22 11:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-06 11:19 - 2013-07-06 11:19 - 00002299 _____ C:\Users\Public\Desktop\Steuer-Spar-Erklärung Selbstständige 2012.lnk
2013-07-06 11:19 - 2013-07-06 11:04 - 00000000 ____D C:\Program Files (x86)\Akademische Arbeitsgemeinschaft
2013-07-06 11:17 - 2013-07-06 11:02 - 00000000 ____D C:\ProgramData\AAV
2013-07-06 08:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-03 14:09 - 2013-07-03 14:09 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Morgen&Morgen
2013-07-03 06:53 - 2013-07-03 06:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 01:10 - 2013-02-01 10:43 - 00000000 ____D C:\ProgramData\lexware
2013-07-02 00:51 - 2013-02-01 10:44 - 00000000 ____D C:\ProgramData\BTrieve
2013-06-30 15:56 - 2013-06-30 15:56 - 00001710 _____ C:\Users\Public\Desktop\Kunden gewinnen am Telefon.lnk
2013-06-30 15:56 - 2013-06-30 15:56 - 00000000 ____D C:\Program Files\Haufe
2013-06-29 09:27 - 2013-06-29 09:27 - 02828552 _____ (AVAST Software) C:\Users\Martina\Downloads\avast-browser-cleanup_8.0.1484.29.exe
2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\Users\Martina\AppData\Roaming\Babylon
2013-06-29 09:19 - 2013-06-29 09:19 - 00000000 ____D C:\ProgramData\Babylon
2013-06-29 09:19 - 2012-12-27 02:25 - 00000000 ____D C:\Program Files (x86)\PicPick
2013-06-27 00:26 - 2013-06-27 00:25 - 00003718 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
2013-06-27 00:26 - 2012-12-27 02:25 - 00045856 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-06-27 00:26 - 2012-12-27 02:25 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search
2013-06-24 00:57 - 2012-12-21 17:10 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-07-13 00:18

==================== End Of Log ============================
Ist das so richtig?
Dann kommt jetzt der Addition.txt ...

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-07-2013
Ran by Martina at 2013-07-20 10:23:49
Running from C:\Users\Martina\Downloads
Boot Mode: Normal

==================== Installed Programs =======================

AAVUpdateManager (x32 Version: 18.00.0000)
Adobe AIR (x32 Version:
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Flash Player ActiveX (x32 Version:
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Amazon Kindle (HKCU)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version:
CCleaner (Version: 4.03)
Conexant HD Audio (Version:
ConvertHelper 2.2 (x32)
DirPrintOK (x32)
Dolby Advanced Audio v2 (x32 Version: 7.2.7000.11)
dows-Treiberpaket - Lenovo (ACPIVPC) System  (12/15/2011 (Version: 12/15/2011
Dragon NaturallySpeaking 11 (x32 Version: 11.50.100)
Dropbox (HKCU Version: 2.0.22)
Energy Management (x32 Version:
Evernote v. 4.6.6 (x32 Version:
FormatFactory 3.0.1 (x32 Version: 3.0.1)
Free FLV Converter V 7.5.0 (x32 Version:
GetDataBack for FAT (x32 Version: 4.33.000)
Google Earth Plug-in (x32 Version:
Google Update Helper (x32 Version:
Grewe Scanner-Interface 7 (x32 Version: 7)
Haufe iDesk-Browser (x32 Version:
Haufe iDesk-Service (x32 Version:
HP FWUpdateEDO2 (x32 Version:
HP Officejet Pro 8600 - Grundlegende Software für das Gerät (Version: 25.0.619.0)
HP Officejet Pro 8600 Hilfe (x32 Version:
HP Update (x32 Version:
HPDiagnosticAlert (x32 Version: 1.00.0000)
I.R.I.S. OCR (x32 Version:
Intel PROSet Wireless
Intel(R) Management Engine Components (x32 Version:
Intel(R) OpenCL CPU Runtime (x32)
Intel(R) Processor Graphics (x32 Version:
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version:
Intel(R) Rapid Storage Technology (x32 Version:
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version:
Intel® PROSet/Wireless WiFi-Software (Version: 15.00.0000.0642)
Intel® Trusted Connect Service Client (Version: 1.23.605.1)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version:
Java(TM) 6 Update 13 (64-bit) (Version: 6.0.130)
Java(TM) 6 Update 2 (x32 Version:
Join Air (x32 Version:
Klett Mathetrainer 10 (x32)
Kunden gewinnen am Telefon (x32)
KV-WIN (x32 Version: 7.113.6)
Lenovo EasyCamera (x32 Version: 13.11.1206.1)
Lenovo OneKey Recovery (Version:
Lenovo OneKey Recovery (x32 Version:
Lenovo pointing device (Version:
Lenovo Solution Center (Version:
Lenovo_Wireless_Driver (x32 Version: 1.02.01)
Lexware buchhalter 2011 (x32 Version:
Lexware Datenbank plus 2011 (x32 Version:
Lexware Elster (x32 Version:
Lexware Info Service (x32 Version:
Lexware online banking (x32 Version:
Lexware reisekosten 2009 (x32 Version:
Lexware reisekosten plus 2011 (x32 Version:
LV-WIN (x32 Version: 7.113.6)
McAfee Security Scan Plus (x32 Version: 3.0.318.3)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.3.0215.0)
Microsoft Security Essentials (Version:
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0)
NVIDIA Grafiktreiber 296.96 (Version: 296.96)
NVIDIA Install Application (Version: 2.1002.62.312)
NVIDIA Optimus 1.7.13 (Version: 1.7.13)
NVIDIA PhysX (x32 Version: 9.12.0613)
NVIDIA PhysX-Systemsoftware 9.12.0613 (Version: 9.12.0613)
NVIDIA Systemsteuerung 296.96 (Version: 296.96)
NVIDIA Update 1.7.13 (Version: 1.7.13)
NVIDIA Update Components (Version: 1.7.13)
PDF24 Creator 5.5.0 (x32)
PDFCreator (x32 Version: 1.7.0)
PicPick (x32 Version: 3.2.6)
QuickSteuer Deluxe 2010 (x32 Version:
QuickSteuer Deluxe 2011 (x32 Version:
QuickSteuer DELUXE Wissens-Center 2010 (x32 Version:
QuickSteuer DELUXE Wissens-Center 2011 (x32 Version:
Realtek USB 2.0 Reader Driver (x32 Version: 6.1.7601.39016)
RENESIS® Player Browser Plugins (x32 Version: 1.1.1)
Revo Uninstaller 1.95 (x32 Version: 1.95)
ScanSoft PDF Converter (x32 Version: 1.00.0000)
Secure Banking Version 1.5.2 (x32 Version: 1.5.2)
Sentinel Protection Installer 7.6.3 (x32 Version: 7.6.3)
Servicepack Datumsaktualisierung (x32 Version:
Skype Click to Call (x32 Version: 6.3.11079)
Skype™ 6.6 (x32 Version: 6.6.106)
Softwarenetz Haushaltsbuch4 (x32)
Steuer-Spar-Erklärung Selbstständige 2012 (x32 Version: 17.13)
Studie zur Verbesserung von HP Officejet Pro 8600 Produkten (Version: 25.0.619.0)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (Version: 11.0.200)
VLC media player 2.0.5 (Version: 2.0.5)

==================== Restore Points  =========================

12-07-2013 07:11:08 Installed EnergyCut
12-07-2013 07:36:48 Installed Lenovo Solution Center.
12-07-2013 10:57:58 Entfernt Energy Management
12-07-2013 10:59:47 Removed EnergyCut
12-07-2013 11:12:08 Installiert Energy Management
12-07-2013 14:59:45 Windows-Sicherung
12-07-2013 15:09:15 Windows-Sicherung
12-07-2013 15:13:16 Windows-Sicherung
13-07-2013 13:18:16 Windows-Sicherung
13-07-2013 13:41:37 Windows-Sicherung
13-07-2013 13:59:54 Windows-Sicherung
14-07-2013 07:25:26 Windows Update
14-07-2013 08:33:00 Removed PDF Architect
14-07-2013 08:54:15 Removed Adobe Flash Player 9 ActiveX.
17-07-2013 10:07:22 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {060FBA53-CAEA-4C06-BE03-6BB2C37CCE4A} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {0CDF6CEA-695C-4517-AD5E-A56543CB48FB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3436055512-94652675-3813047270-1000
Task: {121E87B3-8750-40E6-BCD3-598C7236A11E} - System32\Tasks\WPD\SqmUpload_S-1-5-21-3436055512-94652675-3813047270-1002 => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {3E9B42C4-E851-4FFF-92AE-BFA3AA18630A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {4616CD2E-1096-4017-BFB0-C9CE649ED1B9} - System32\Tasks\User_Feed_Synchronization-{A5D247D3-B96E-4A7A-8CC3-F568284A7C55} => C:\Windows\system32\msfeedssync.exe [2013-05-24] (Microsoft Corporation)
Task: {47DC3F0A-F9B0-4FA5-AD46-089CC8C6890A} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe [2013-06-20] (Microsoft Corporation)
Task: {4FCE486B-C487-49BA-8680-76547F961258} - System32\Tasks\User_Feed_Synchronization-{00E477AE-69B0-4A65-BD2E-2E3EA31B996C} => C:\Windows\system32\msfeedssync.exe [2013-05-24] (Microsoft Corporation)
Task: {52C546A2-267B-4511-90DB-5A034E94896B} - System32\Tasks\HPCustParticipation HP Officejet Pro 8600 => C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPCustPartic.exe [2011-09-09] (Hewlett-Packard Co.)
Task: {5FE5B722-CDDD-4D43-8A78-2AD0702A311E} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{A191360B-D6B0-468A-B911-60203C23C8A0}.exe No File
Task: {74DEF71A-3873-476E-AFBF-5E2AEE6DA062} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-05-17] (Lenovo)
Task: {75F96F2A-B5F6-462B-9EC3-E3DD4493CC10} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-06] (Google Inc.)
Task: {8482BDA2-0F9A-4C5A-B5F5-2B10C4D8AD00} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated)
Task: {8EA32C18-CE36-402A-BF33-EF08D31B69A7} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-05-17] (Lenovo)
Task: {9AE9F1CA-DFFB-406D-AC79-0A286BEA96EA} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation)
Task: {A45D167C-2F4D-481A-8493-B24AC85C30BD} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-05-17] ()
Task: {F67C7407-99E0-4B8E-B9D5-C003AD6609E0} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {F7354EC3-1571-43A0-ACC3-E5372D30C450} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-06] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{A191360B-D6B0-468A-B911-60203C23C8A0}.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (07/19/2013 06:37:47 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version:, Zeitstempel: 0x51c06b1b
Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x2b48fc58
ID des fehlerhaften Prozesses: 0x11c0
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3

Error: (07/19/2013 06:31:48 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/19/2013 04:02:45 PM) (Source: Microsoft-Windows-User Profiles Service) (User: ZIEGENER)
Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren.

Error: (07/19/2013 04:02:45 PM) (Source: Microsoft-Windows-User Profiles Service) (User: ZIEGENER)
Description: Dieses Benutzerprofil wurde gesichert. Bei der nächsten Anmeldung dieses Benutzers wird automatisch versucht, dieses gesicherte Profil zu verwenden.

Error: (07/19/2013 03:44:38 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/19/2013 03:33:54 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 12.0.6668.5000, Zeitstempel: 0x508314b2
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000ce6c3
ID des fehlerhaften Prozesses: 0x16e0
Startzeit der fehlerhaften Anwendung: 0xOUTLOOK.EXE0
Pfad der fehlerhaften Anwendung: OUTLOOK.EXE1
Pfad des fehlerhaften Moduls: OUTLOOK.EXE2
Berichtskennung: OUTLOOK.EXE3

Error: (07/19/2013 09:50:41 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WINWORD.EXE, Version: 12.0.6668.5000, Zeitstempel: 0x5083137f
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec49b8f
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000ce6c3
ID des fehlerhaften Prozesses: 0x1dc4
Startzeit der fehlerhaften Anwendung: 0xWINWORD.EXE0
Pfad der fehlerhaften Anwendung: WINWORD.EXE1
Pfad des fehlerhaften Moduls: WINWORD.EXE2
Berichtskennung: WINWORD.EXE3

Error: (07/19/2013 09:50:41 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: sidebar.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7a1c7
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c92c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000029fa9
ID des fehlerhaften Prozesses: 0xd7c
Startzeit der fehlerhaften Anwendung: 0xsidebar.exe0
Pfad der fehlerhaften Anwendung: sidebar.exe1
Pfad des fehlerhaften Moduls: sidebar.exe2
Berichtskennung: sidebar.exe3

Error: (07/19/2013 09:42:36 AM) (Source: Application Hang) (User: )
Description: Programm natspeak.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1a48

Startzeit: 01ce844d994eebf5

Endzeit: 10

Anwendungspfad: C:\Program Files (x86)\Nuance\NaturallySpeaking11\Program\natspeak.exe

Berichts-ID: b5f1c661-f046-11e2-9537-b888e38fdbd0

Error: (07/19/2013 08:57:53 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bca54
Name des fehlerhaften Moduls: igdumd64.dll, Version:, Zeitstempel: 0x4f3e8e4b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000030ed16
ID des fehlerhaften Prozesses: 0x1750
Startzeit der fehlerhaften Anwendung: 0xDllHost.exe0
Pfad der fehlerhaften Anwendung: DllHost.exe1
Pfad des fehlerhaften Moduls: DllHost.exe2
Berichtskennung: DllHost.exe3

System errors:
Error: (07/20/2013 10:09:05 AM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/20/2013 10:07:51 AM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/20/2013 10:06:23 AM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/19/2013 07:04:36 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/19/2013 03:36:06 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2.

Error: (07/19/2013 03:36:06 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2.

Error: (07/19/2013 03:36:05 PM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2.

Error: (07/17/2013 06:52:29 AM) (Source: Microsoft Antimalware) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.

	Neue Signaturversion: 

	Vorherige Signaturversion:

	Aktualisierungsquelle: %NT-AUTORITÄT59

	Aktualisierungsphase: 4.3.0215.00

	Quellpfad: 4.3.0215.01

	Signaturtyp: %NT-AUTORITÄT602

	Aktualisierungstyp: %NT-AUTORITÄT604


	Aktuelle Modulversion: %NT-AUTORITÄT605

	Vorherige Modulversion: %NT-AUTORITÄT606

	Fehlercode: %NT-AUTORITÄT607

	Fehlerbeschreibung: %NT-AUTORITÄT608

Error: (07/16/2013 01:11:03 AM) (Source: Disk) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/14/2013 10:34:51 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet: 

Microsoft Office Sessions:
Error: (07/13/2013 03:47:02 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1331 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (05/31/2013 10:03:05 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 121 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (01/04/2013 01:37:31 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 41323 seconds with 4140 seconds of active time.  This session ended with a crash.

==================== Memory info =========================== 

Percentage of memory in use: 65%
Total physical RAM: 3995.28 MB
Available physical RAM: 1372.35 MB
Total Pagefile: 7988.74 MB
Available Pagefile: 4845.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.54 GB) (Free:386.67 GB) NTFS (Disk=0 Partition=3)
Drive e: () (Fixed) (Total:465.65 GB) (Free:325.17 GB) FAT32 (Disk=1 Partition=1)

==================== MBR & Partition Table ==================

==================== End Of Log ============================
Hallo schrauber ... 1000 Dank schon jetzt ... ;-)

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Malware ist da keine.

Drive e: () (Fixed) (Total:465.65 GB) (Free:325.17 GB) FAT32 (Disk=1 Partition=1)
Du meinst diese Platte?

Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Ja genau diese Platte ...

hierhin habe ich ein Backup gemacht ...

und wenn ich jetzt sehe was GetDataBack a liefert, dann sind die Daten meiner Backups und der des Java-Downloads identisch ... 12./13.07. ...

Kann ich Dir denn hier i-wie Bilder reinstellen?

Alt 20.07.2013, 10:55   #6
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Ja, unten auf erweitert klicken, Anhänge verwalten, dort kannste sie anhängen.
--> Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Alt 20.07.2013, 10:59   #7
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

[IMG]C:\Users\Martina\Desktop\Bild 003.jpg[/IMG]

test ...

Alt 20.07.2013, 11:05   #8
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

C:\Users\Martina\Desktop\Bild 003.jpg
Miniaturansicht angehängter Grafiken
-bild-001.jpg   -bild-002.jpg   -bild-003.jpg  

Alt 20.07.2013, 11:09   #9
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

diese Screenshots habe ich heute im Laufe des Vormittags erstellt ...
Miniaturansicht angehängter Grafiken
-bild-004.jpg   -bild-005.jpg   -bild-006.jpg   -bild-007.jpg  

Alt 20.07.2013, 11:10   #10
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

darauf erkenne ich meine Daten auf der Festplatte wieder ...

aber ich komme nicht dran ...

Alt 20.07.2013, 11:15   #11
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

und hier sehe ich die Daten des Backups / der Backups ... auch 12./13.07. ...
Miniaturansicht angehängter Grafiken

Alt 20.07.2013, 11:42   #12
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

der PC meldet seit ein oder zwei Tagen immer wieder

COM SURROGATE reagiert nicht ...

(nur so als Hintergrundinfo)

Alt 20.07.2013, 15:55   #13
Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Ich habe jetzt mal Recuva (free-Version) drüberlaufen lassen ... wenn ich danach gehe, sind die meisten Daten scheinbar unwiederherstellbar ...
Miniaturansicht angehängter Grafiken

Alt 20.07.2013, 20:04   #14
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

in dem obigen Bild steht doch dass Du die Daten retten kannst wenn Du ne Lizenz kaufst oder?

Ich wüsste jetzt spontan auch nit wie Du da dran kommst. Sind die daten wichtig?
Warum ist die Platte in FAT32 formatiert?

Tina Zee
Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Externe Festplatte (FAT32) meldet: Dieser Ordner ist leer. Ursache womöglich der "exploit java/cve-2012-0507" ?

Hallo Schrauber,

die Lizenz soll um die 90 € kosten ...
meinst Du denn, dass ich da wirklich eine Chance habe?
Ich habe so gar keine Ahnung ... aber so unbekannt ist das Programm ja wohl nicht ...

Werd wohl mal drüber schlafen, ob diese Investition sinnvoll ist.

Ich habe die Platte so bekommen mit FAT formatiert ... worauf zielst Du mit Deiner Frage ab?




