Schweizerische Eidgenossenschaft
Forts.
========== Files - Modified Within 30 Days ==========
[2012.11.19 18:37:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.19 17:50:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.19 17:27:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Walter\Desktop\OTL (1).exe
[2012.11.19 16:52:05 | 000,002,712 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.11.19 16:27:23 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.19 16:27:23 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.19 16:24:41 | 001,500,254 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.19 16:24:41 | 000,654,594 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.11.19 16:24:41 | 000,616,476 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.19 16:24:41 | 000,130,208 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.11.19 16:24:41 | 000,106,598 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.19 16:22:13 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.19 16:19:42 | 000,505,536 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.11.19 16:19:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.19 16:19:09 | 2812,383,232 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.18 19:46:06 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.15 22:16:18 | 000,016,200 | ---- | M] (McAfee, Inc.) -- C:\Windows\stinger.sys
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Walter\Documents\*.tmp files -> C:\Users\Walter\Documents\*.tmp -> ]
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.18 19:46:06 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.18 18:29:53 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012.11.18 18:21:33 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012.09.09 20:38:22 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012.06.14 08:15:39 | 000,003,654 | ---- | C] () -- C:\Windows\SysWow64\drivers\Sonyhcp.dll
[2012.02.14 19:48:27 | 001,526,060 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.07.08 07:37:28 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011.06.28 19:26:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.06.27 22:01:38 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.08.26 12:12:53 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Garmin
[2012.04.10 18:20:17 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Information Factory
[2012.11.16 06:19:26 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Sammsoft
[2012.11.18 21:35:57 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\SoftGrid Client
[2012.07.01 12:18:39 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\TomTom
[2012.02.14 19:49:21 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\TP
[2012.04.01 15:17:22 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2012.02.03 20:33:48 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2012.10.27 08:08:31 | 000,000,000 | ---D | M] -- C:\CHFahrschule
[2012.11.19 16:19:07 | 000,000,000 | -HSD | M] -- C:\Config.Msi
[2012.02.03 20:23:05 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2012.06.14 08:15:39 | 000,000,000 | ---D | M] -- C:\Drivers
[2012.09.09 20:28:59 | 000,000,000 | ---D | M] -- C:\hp_CLJ_CP1215_Full_Solution
[2012.11.18 17:18:43 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2012.04.11 20:07:29 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.11.18 18:39:24 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012.11.18 17:26:08 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2012.02.03 20:23:05 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.11.19 18:42:37 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.09.09 18:30:12 | 000,000,000 | R--D | M] -- C:\Users
[2012.11.18 16:27:50 | 000,000,000 | ---D | M] -- C:\Windows
Forts. folgt
Forts.
========== Files - Modified Within 30 Days ==========
[2012.11.19 18:37:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.11.19 17:50:00 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.19 17:27:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Walter\Desktop\OTL (1).exe
[2012.11.19 16:52:05 | 000,002,712 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012.11.19 16:27:23 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.19 16:27:23 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.19 16:24:41 | 001,500,254 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.19 16:24:41 | 000,654,594 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.11.19 16:24:41 | 000,616,476 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.19 16:24:41 | 000,130,208 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.11.19 16:24:41 | 000,106,598 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.19 16:22:13 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.19 16:19:42 | 000,505,536 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.11.19 16:19:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.19 16:19:09 | 2812,383,232 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.18 19:46:06 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.15 22:16:18 | 000,016,200 | ---- | M] (McAfee, Inc.) -- C:\Windows\stinger.sys
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Walter\Documents\*.tmp files -> C:\Users\Walter\Documents\*.tmp -> ]
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.11.18 19:46:06 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.11.18 18:29:53 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012.11.18 18:21:33 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012.09.09 20:38:22 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012.06.14 08:15:39 | 000,003,654 | ---- | C] () -- C:\Windows\SysWow64\drivers\Sonyhcp.dll
[2012.02.14 19:48:27 | 001,526,060 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.07.08 07:37:28 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011.06.28 19:26:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.06.27 22:01:38 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012.08.26 12:12:53 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Garmin
[2012.04.10 18:20:17 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Information Factory
[2012.11.16 06:19:26 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Sammsoft
[2012.11.18 21:35:57 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\SoftGrid Client
[2012.07.01 12:18:39 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\TomTom
[2012.02.14 19:49:21 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\TP
[2012.04.01 15:17:22 | 000,000,000 | ---D | M] -- C:\Users\Walter\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2012.02.03 20:33:48 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN
[2012.10.27 08:08:31 | 000,000,000 | ---D | M] -- C:\CHFahrschule
[2012.11.19 16:19:07 | 000,000,000 | -HSD | M] -- C:\Config.Msi
[2012.02.03 20:23:05 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2012.06.14 08:15:39 | 000,000,000 | ---D | M] -- C:\Drivers
[2012.09.09 20:28:59 | 000,000,000 | ---D | M] -- C:\hp_CLJ_CP1215_Full_Solution
[2012.11.18 17:18:43 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2012.04.11 20:07:29 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.11.18 18:39:24 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012.11.18 17:26:08 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2012.02.03 20:23:05 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.11.19 18:42:37 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.09.09 18:30:12 | 000,000,000 | R--D | M] -- C:\Users
[2012.11.18 16:27:50 | 000,000,000 | ---D | M] -- C:\Windows
Forts. folgt