FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 01
Ran by Ute (administrator) on UTE-PC on 14-09-2013 17:34:08
Running from C:\Users\Ute\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files\System Control Manager\MSIService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
( TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
(Mirco-Star International CO., LTD.) C:\Program Files\System Control Manager\MGSysCtrl.exe
(Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
(TOSHIBA CORPORATION.) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Google Inc.) C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\program files\avira\antivir desktop\avcenter.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) C:\Windows\system32\prevhost.exe
(Google Inc.) C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6265376 2008-08-21] (Realtek Semiconductor)
HKLM\...\Run: [ITSecMng] - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [75136 2007-09-29] ( TOSHIBA CORPORATION)
HKLM\...\Run: [MGSysCtrl] - C:\Program Files\System Control Manager\MGSysCtrl.exe [708608 2008-08-27] (Mirco-Star International CO., LTD.)
HKLM\...\Run: [SMSERIAL] - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1454080 2008-06-11] (Motorola Inc.)
HKLM\...\Run: [Windows Mobile-based device management] - C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [417792 2009-11-10] (Apple Inc.)
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [GoogleChromeAutoLaunch_C1425719F54350BB5DD043EF785D9D51] - C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe [829392 2013-09-02] (Google Inc.)
HKCU\...\Policies\Explorer: [NoDrives] 0
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
ShortcutTarget: Bluetooth Manager.lnk -> C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {18F87321-1CB7-476A-9AEC-37691523909B} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Ute\AppData\Local\Google\Chrome\Application\29.0.1547.66\gcswf32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Ute\AppData\Local\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Ute\AppData\Local\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (vShare.tv plug-in) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Veetle TV Player) - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
CHR Plugin: (Veetle TV Core) - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
CHR Plugin: (Unity Player) - C:\Users\Ute\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Google Update) - C:\Users\Ute\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (WOT) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.13_0
CHR Extension: (Adblock Plus) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_1
CHR Extension: (Chrome In-App Payments service) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Ute\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files\vShare.tv plugin\vshareplg.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Ute\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [159744 2008-08-27] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-27] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-21] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 RTL8187Se; C:\Windows\System32\DRIVERS\RTL8187Se.sys [333824 2008-08-23] (Realtek Semiconductor Corporation )
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1748352 2008-06-10] ()
S3 sscebus; C:\Windows\System32\DRIVERS\sscebus.sys [98560 2010-12-21] (MCCI Corporation)
S3 sscemdfl; C:\Windows\System32\DRIVERS\sscemdfl.sys [14848 2010-12-21] (MCCI Corporation)
S3 sscemdm; C:\Windows\System32\DRIVERS\sscemdm.sys [123648 2010-12-21] (MCCI Corporation)
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [100352 2010-12-21] (MCCI Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-10-09] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NVNET; system32\DRIVERS\nvmfdx32.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 SymIM; system32\DRIVERS\SymIM.sys [x]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-14 17:28 - 2013-09-14 17:28 - 00891144 _____ C:\Users\Ute\Desktop\SecurityCheck.exe
2013-09-14 16:47 - 2013-09-14 16:47 - 97581476 _____ C:\Windows\system32\彐†Ḭš
2013-09-14 14:50 - 2013-09-14 14:51 - 02347384 _____ (ESET) C:\Users\Ute\Desktop\esetsmartinstaller_enu.exe
2013-09-11 22:47 - 2013-09-11 22:47 - 00000000 ____D C:\Users\Ute\AppData\Local\FileTypeAssistant
2013-09-11 21:30 - 2013-09-11 21:30 - 01082195 _____ (Farbar) C:\Users\Ute\Desktop\FRST.exe
2013-09-11 21:21 - 2013-09-11 21:21 - 00001114 _____ C:\Users\Ute\Desktop\JRT.txt
2013-09-11 21:16 - 2013-09-11 21:16 - 01029490 _____ (Thisisu) C:\Users\Ute\Desktop\JRT.exe
2013-09-11 21:16 - 2013-09-11 21:16 - 00000000 ____D C:\Windows\ERUNT
2013-09-11 21:02 - 2013-09-11 21:11 - 00011553 _____ C:\Users\Ute\Desktop\AdwCleaner[S0].txt
2013-09-11 21:00 - 2013-09-11 21:00 - 00013042 _____ C:\Users\Ute\Desktop\AdwCleaner[R0].txt
2013-09-11 20:57 - 2013-09-11 21:13 - 00000000 ____D C:\AdwCleaner
2013-09-11 20:56 - 2013-09-11 20:57 - 01037278 _____ C:\Users\Ute\Desktop\adwcleaner.exe
2013-09-11 20:31 - 2013-09-11 20:31 - 00000916 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-11 20:31 - 2013-09-11 20:31 - 00000000 ____D C:\Users\Ute\AppData\Roaming\Malwarebytes
2013-09-11 20:31 - 2013-09-11 20:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-11 20:31 - 2013-09-11 20:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-11 20:31 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-09-11 20:30 - 2013-09-11 20:30 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ute\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-08 21:45 - 2013-09-08 21:45 - 96566691 _____ C:\Windows\system32\⻖촅Ḭ˜
2013-09-07 23:25 - 2013-09-07 23:20 - 00012567 _____ C:\Users\Ute\Desktop\ComboFix.txt
2013-09-07 23:20 - 2013-09-07 23:20 - 00012567 _____ C:\ComboFix.txt
2013-09-07 22:25 - 2013-09-07 23:20 - 00000000 ____D C:\Qoobox
2013-09-07 22:25 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-07 22:25 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-07 22:25 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-07 22:25 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-07 22:25 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-07 22:25 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-07 22:25 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-07 22:25 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-07 22:24 - 2013-09-07 23:18 - 00000000 ____D C:\Windows\erdnt
2013-09-07 22:22 - 2013-09-07 22:23 - 05120615 ____R (Swearware) C:\Users\Ute\Desktop\ComboFix.exe
2013-09-07 14:44 - 2013-09-07 14:44 - 00000562 _____ C:\Users\Ute\Desktop\defogger_disable - Verknüpfung.lnk
2013-09-07 14:43 - 2013-09-07 14:43 - 00000522 _____ C:\Users\Ute\Desktop\Addition - Verknüpfung.lnk
2013-09-07 13:52 - 2013-09-07 13:52 - 320101719 _____ C:\Windows\MEMORY.DMP
2013-09-07 13:52 - 2013-09-07 13:52 - 00139104 _____ C:\Windows\Minidump\Mini090713-01.dmp
2013-09-07 13:52 - 2013-09-07 13:52 - 00000000 ____D C:\Windows\Minidump
2013-09-07 13:14 - 2013-09-07 13:14 - 96511910 _____ C:\Windows\system32\斤ᴡḬ“
2013-09-07 12:40 - 2013-09-07 12:40 - 00377856 _____ C:\Users\Ute\Downloads\gmer_2.1.19163.exe
2013-09-07 12:38 - 2013-09-07 12:38 - 01948604 _____ (Farbar) C:\Users\Ute\Downloads\FRST64.exe
2013-09-07 12:33 - 2013-09-07 12:34 - 00030625 _____ C:\Users\Ute\Downloads\Addition.txt
2013-09-07 12:30 - 2013-09-07 12:30 - 00000000 ____D C:\FRST
2013-09-07 12:25 - 2013-09-07 12:26 - 00000468 _____ C:\Users\Ute\Downloads\defogger_disable.log
2013-09-07 12:25 - 2013-09-07 12:25 - 00000000 _____ C:\Users\Ute\defogger_reenable
2013-09-07 12:24 - 2013-09-07 12:24 - 00050477 _____ C:\Users\Ute\Downloads\Defogger.exe
2013-09-02 19:43 - 2013-09-02 19:43 - 95286781 _____ C:\Windows\system32\铕쵞Ḭ¨
==================== One Month Modified Files and Folders =======
2013-09-14 17:33 - 2013-09-14 17:33 - 00001208 _____ C:\Users\Ute\Desktop\checkup.txt
2013-09-14 17:28 - 2013-09-14 17:28 - 00891144 _____ C:\Users\Ute\Desktop\SecurityCheck.exe
2013-09-14 17:15 - 2010-10-31 21:51 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4008929132-1623217699-3924471616-1000UA.job
2013-09-14 16:47 - 2013-09-14 16:47 - 97581476 _____ C:\Windows\system32\彐†Ḭš
2013-09-14 16:44 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-14 16:44 - 2006-11-02 14:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-14 16:05 - 2008-10-07 13:32 - 00103069 _____ C:\ProgramData\nvModes.001
2013-09-14 14:58 - 2010-10-31 20:58 - 01360185 _____ C:\Windows\WindowsUpdate.log
2013-09-14 14:56 - 2008-10-07 14:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-14 14:51 - 2013-09-14 14:50 - 02347384 _____ (ESET) C:\Users\Ute\Desktop\esetsmartinstaller_enu.exe
2013-09-14 14:44 - 2011-03-16 22:05 - 00000382 _____ C:\Windows\Tasks\Final Media Player Update Checker.job
2013-09-14 14:44 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-13 18:27 - 2006-11-02 15:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-12 12:15 - 2010-10-31 21:51 - 00001060 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4008929132-1623217699-3924471616-1000Core.job
2013-09-11 22:47 - 2013-09-11 22:47 - 00000000 ____D C:\Users\Ute\AppData\Local\FileTypeAssistant
2013-09-11 21:30 - 2013-09-11 21:30 - 01082195 _____ (Farbar) C:\Users\Ute\Desktop\FRST.exe
2013-09-11 21:21 - 2013-09-11 21:21 - 00001114 _____ C:\Users\Ute\Desktop\JRT.txt
2013-09-11 21:16 - 2013-09-11 21:16 - 01029490 _____ (Thisisu) C:\Users\Ute\Desktop\JRT.exe
2013-09-11 21:16 - 2013-09-11 21:16 - 00000000 ____D C:\Windows\ERUNT
2013-09-11 21:13 - 2013-09-11 20:57 - 00000000 ____D C:\AdwCleaner
2013-09-11 21:11 - 2013-09-11 21:02 - 00011553 _____ C:\Users\Ute\Desktop\AdwCleaner[S0].txt
2013-09-11 21:03 - 2011-11-01 22:54 - 00000000 ____D C:\Users\Ute\AppData\Roaming\Uniblue
2013-09-11 21:03 - 2011-11-01 22:54 - 00000000 ____D C:\Program Files\Uniblue
2013-09-11 21:02 - 2011-11-01 22:54 - 00000000 ____D C:\ProgramData\Uniblue
2013-09-11 21:00 - 2013-09-11 21:00 - 00013042 _____ C:\Users\Ute\Desktop\AdwCleaner[R0].txt
2013-09-11 20:57 - 2013-09-11 20:56 - 01037278 _____ C:\Users\Ute\Desktop\adwcleaner.exe
2013-09-11 20:31 - 2013-09-11 20:31 - 00000916 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-11 20:31 - 2013-09-11 20:31 - 00000000 ____D C:\Users\Ute\AppData\Roaming\Malwarebytes
2013-09-11 20:31 - 2013-09-11 20:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-11 20:31 - 2013-09-11 20:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-11 20:30 - 2013-09-11 20:30 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ute\Desktop\mbam-setup-1.75.0.1300.exe
2013-09-08 21:45 - 2013-09-08 21:45 - 96566691 _____ C:\Windows\system32\⻖촅Ḭ˜
2013-09-07 23:20 - 2013-09-07 23:25 - 00012567 _____ C:\Users\Ute\Desktop\ComboFix.txt
2013-09-07 23:20 - 2013-09-07 23:20 - 00012567 _____ C:\ComboFix.txt
2013-09-07 23:20 - 2013-09-07 22:25 - 00000000 ____D C:\Qoobox
2013-09-07 23:20 - 2013-01-11 17:52 - 00000000 ____D C:\Users\Bernd
2013-09-07 23:20 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2013-09-07 23:20 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-09-07 23:18 - 2013-09-07 22:24 - 00000000 ____D C:\Windows\erdnt
2013-09-07 23:14 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2013-09-07 23:11 - 2012-10-09 09:05 - 00004604 _____ C:\Windows\PFRO.log
2013-09-07 22:39 - 2011-03-16 22:05 - 00000000 ____D C:\Program Files\File Type Assistant
2013-09-07 22:23 - 2013-09-07 22:22 - 05120615 ____R (Swearware) C:\Users\Ute\Desktop\ComboFix.exe
2013-09-07 14:44 - 2013-09-07 14:44 - 00000562 _____ C:\Users\Ute\Desktop\defogger_disable - Verknüpfung.lnk
2013-09-07 14:43 - 2013-09-07 14:43 - 00000522 _____ C:\Users\Ute\Desktop\Addition - Verknüpfung.lnk
2013-09-07 13:52 - 2013-09-07 13:52 - 320101719 _____ C:\Windows\MEMORY.DMP
2013-09-07 13:52 - 2013-09-07 13:52 - 00139104 _____ C:\Windows\Minidump\Mini090713-01.dmp
2013-09-07 13:52 - 2013-09-07 13:52 - 00000000 ____D C:\Windows\Minidump
2013-09-07 13:14 - 2013-09-07 13:14 - 96511910 _____ C:\Windows\system32\斤ᴡḬ“
2013-09-07 12:40 - 2013-09-07 12:40 - 00377856 _____ C:\Users\Ute\Downloads\gmer_2.1.19163.exe
2013-09-07 12:38 - 2013-09-07 12:38 - 01948604 _____ (Farbar) C:\Users\Ute\Downloads\FRST64.exe
2013-09-07 12:34 - 2013-09-07 12:33 - 00030625 _____ C:\Users\Ute\Downloads\Addition.txt
2013-09-07 12:30 - 2013-09-07 12:30 - 00000000 ____D C:\FRST
2013-09-07 12:26 - 2013-09-07 12:25 - 00000468 _____ C:\Users\Ute\Downloads\defogger_disable.log
2013-09-07 12:25 - 2013-09-07 12:25 - 00000000 _____ C:\Users\Ute\defogger_reenable
2013-09-07 12:25 - 2010-10-31 13:24 - 00000000 ____D C:\Users\Ute
2013-09-07 12:24 - 2013-09-07 12:24 - 00050477 _____ C:\Users\Ute\Downloads\Defogger.exe
2013-09-06 00:27 - 2008-10-07 10:51 - 01445298 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-02 19:43 - 2013-09-02 19:43 - 95286781 _____ C:\Windows\system32\铕쵞Ḭ¨
2013-09-02 15:42 - 2012-10-09 09:09 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-09-02 15:42 - 2012-10-09 09:09 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-15 10:56 - 2013-02-26 11:55 - 00000000 ____D C:\Users\Ute\AppData\Roaming\FreeBurner
Files to move or delete:
====================
C:\Users\Ute\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-14 15:00
==================== End Of Log ============================
--- --- ---
--- --- ---
Results of screen317's Security Check version 0.99.73
Windows Vista Service Pack 1 x86 (UAC is enabled)
Out of date service pack!!
Internet Explorer 7
Out of date! ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 13
Java version out of Date!
Adobe Flash Player 11.6.602.171
Adobe Reader 10.1.5
Adobe Reader out of Date!
Google Chrome 29.0.1547.62
Google Chrome 29.0.1547.66
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=8194f3142faded41b463a2082f498eaf
# engine=15126
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-09-14 02:59:25
# local_time=2013-09-14 04:59:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6001 NT Service Pack 1
# compatibility_mode=5892 16776638 100 100 117294 216703493 0 0
# scanned=148300
# found=0
# cleaned=0
# scan_time=7463