| derdommi |  25.04.2011 16:21 |        neuer Log   
Combofix Logfile:   Code:  
 ComboFix 11-04-24.06 - Emmi 25.04.2011  17:13:09.1.4 - x64 
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.49.1031.18.3959.2690 [GMT 2:00] 
ausgeführt von:: c:\users\Emmi\Desktop\cofi.exe 
AV: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} 
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} 
SP: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} 
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
 * Neuer Wiederherstellungspunkt wurde erstellt 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2011-03-25 bis 2011-04-25  )))))))))))))))))))))))))))))) 
. 
. 
2011-04-25 15:16 . 2011-04-25 15:16        --------        d-----w-        c:\users\MINI S\AppData\Local\temp 
2011-04-25 15:16 . 2011-04-25 15:16        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2011-04-25 15:05 . 2011-04-25 15:05        --------        d-----w-        c:\program files\CCleaner 
2011-04-25 13:27 . 2011-04-25 13:27        --------        d-----w-        c:\users\Emmi\AppData\Local\ElevatedDiagnostics 
2011-04-25 13:18 . 2011-04-25 13:18        --------        d-----w-        C:\_OTL 
2011-04-22 17:12 . 2011-04-25 14:36        --------        d-----w-        C:\Test 
2011-04-22 08:34 . 2011-04-22 08:34        --------        d-----w-        c:\users\Emmi\AppData\Roaming\Malwarebytes 
2011-04-22 08:34 . 2011-04-22 08:34        --------        d-----w-        c:\programdata\Malwarebytes 
2011-04-22 08:34 . 2010-12-20 16:09        38224        ----a-w-        c:\windows\SysWow64\drivers\mbamswissarmy.sys 
2011-04-22 08:34 . 2011-04-22 12:26        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware 
2011-04-22 08:34 . 2010-12-20 16:08        24152        ----a-w-        c:\windows\system32\drivers\mbam.sys 
2011-04-13 19:34 . 2011-03-03 06:17        182272        ----a-w-        c:\windows\system32\dnsrslvr.dll 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2011-02-19 06:37 . 2011-03-09 18:46        1135104        ----a-w-        c:\windows\system32\FntCache.dll 
2011-02-19 06:37 . 2011-03-09 18:46        1540608        ----a-w-        c:\windows\system32\DWrite.dll 
2011-02-19 06:36 . 2011-03-09 18:46        902656        ----a-w-        c:\windows\system32\d2d1.dll 
2011-02-19 05:32 . 2011-03-09 18:46        1074176        ----a-w-        c:\windows\SysWow64\DWrite.dll 
2011-02-19 05:32 . 2011-03-09 18:46        739840        ----a-w-        c:\windows\SysWow64\d2d1.dll 
2011-01-26 06:53 . 2011-02-10 20:00        982912        ----a-w-        c:\windows\system32\drivers\dxgkrnl.sys 
2011-01-26 06:53 . 2011-02-10 20:00        265088        ----a-w-        c:\windows\system32\drivers\dxgmms1.sys 
2011-01-26 06:31 . 2011-02-10 20:00        144384        ----a-w-        c:\windows\system32\cdd.dll 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-23 2454840] 
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1484856] 
"NBAgent"="c:\program files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" [2010-03-09 1086760] 
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088] 
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-15 98304] 
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] 
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-09-08 421888] 
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] 
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] 
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904] 
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-11-17 421160] 
. 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] 
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280] 
. 
c:\users\Emmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ 
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184] 
. 
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ 
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorAdmin"= 5 (0x5) 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableUIADesktopToggle"= 0 (0x0) 
"EnableLinkedConnections"= 1 (0x1) 
. 
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] 
Security Packages        REG_MULTI_SZ           kerberos msv1_0 schannel wdigest tspkg pku2u livessp 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] 
@="" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] 
@="" 
. 
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] 
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] 
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] 
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x] 
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368] 
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] 
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] 
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440] 
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] 
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] 
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] 
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] 
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200] 
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448] 
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440] 
S2 McMPFSvc;McAfee Personal Firewall-Dienst;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440] 
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440] 
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 245352] 
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-13 149032] 
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928] 
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] 
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920] 
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] 
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] 
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] 
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x] 
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] 
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] 
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] 
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] 
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] 
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] 
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] 
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] 
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560] 
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952] 
. 
. 
--- Andere Dienste/Treiber im Speicher --- 
. 
*NewlyCreated* - KLMD25 
*Deregistered* - klmd25 
*Deregistered* - mfeavfk01 
. 
. 
--------- x86-64 ----------- 
. 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976] 
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072] 
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] 
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-10 520760] 
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] 
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-02-12 136136] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 
"LoadAppInit_DLLs"=0x0 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uLocal Page = c:\windows\system32\blank.htm 
uStart Page = hxxp://de-de.facebook.com/ 
mLocal Page = c:\windows\SysWOW64\blank.htm 
uInternet Settings,ProxyOverride = *.local 
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
Toolbar-Locked - (no file) 
Toolbar-Locked - (no file) 
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 
HKLM-Run-SmartFaceVWatcher - %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe 
HKLM-Run-TosReelTimeMonitor - %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe 
HKLM-Run-TosNC - %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe 
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE 
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe 
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe 
HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe 
HKLM-Run-Teco - %ProgramFiles%\TOSHIBA\TECO\Teco.exe 
HKLM-Run-TosWaitSrv - %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe 
. 
. 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Shockwave Flash Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] 
@="0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] 
@="ShockwaveFlash.ShockwaveFlash.10" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="ShockwaveFlash.ShockwaveFlash" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Macromedia Flash Factory Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] 
@="FlashFactory.FlashFactory.1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="FlashFactory.FlashFactory" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker4" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] 
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
. 
Zeit der Fertigstellung: 2011-04-25  17:18:37 
ComboFix-quarantined-files.txt  2011-04-25 15:18 
. 
Vor Suchlauf: 14 Verzeichnis(se), 116.838.862.848 Bytes frei 
Nach Suchlauf: 15 Verzeichnis(se), 116.225.806.336 Bytes frei 
. 
- - End Of File - - 0A96493CAFF454F86214AB31EEB7EDA5   --- --- ---   
Aktuell bekomm ich bei Start von Windows Live folgenen Fehler.  
" Fehler bei Initialisierung von RSS-Feedunterstützung. Die RSS Feeds konnten nicht aktualisiert werden "  
Weiß nicht ob das jetzt mit den durchgeführten Aktionen zusammen hängt.  
Gruß    |