OK, so I did run from my desktop this time not from Downloads:
Combofix.txt
ComboFix 14-08-17.01 - Lorenz 18.08.2014 23:41:03.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8169.4591 [GMT 2:00]
ausgeführt von:: c:\users\Lorenz\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\temp25.log
c:\users\Lorenz\AppData\Favorites\Ryu.cs
c:\users\Lorenz\AppData\Local\uninst.log
c:\users\Lorenz\AppData\Roaming\technic-launcher.jar
c:\users\Lorenz\AppData\Roaming\uninst.log
c:\windows\IsUn0407.exe
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-07-18 bis 2014-08-18 ))))))))))))))))))))))))))))))
.
.
2014-08-18 09:27 . 2014-08-18 09:27 -------- d-----w- c:\program files (x86)\FirstClass
2014-08-18 09:27 . 2014-08-18 09:27 -------- d-----w- c:\programdata\FirstClass
2014-08-18 08:04 . 2014-07-02 03:09 10924376 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C8370FC7-87B6-4B7F-9CC0-DA9996B3A6C3}\mpengine.dll
2014-08-17 12:47 . 2014-08-17 12:47 -------- d-----w- c:\program files (x86)\Autodesk
2014-08-17 12:46 . 2014-08-17 12:46 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2014-08-17 12:22 . 2014-08-17 12:22 -------- d-----w- c:\users\Lorenz\AppData\Local\Akamai
2014-08-17 09:39 . 2014-08-17 09:39 53248 ----a-w- c:\windows\SysWow64\zlib.dll
2014-08-17 09:39 . 2014-08-17 09:39 -------- d-----w- c:\programdata\Foolish IT
2014-08-17 09:39 . 2014-08-17 09:39 -------- d-----w- c:\program files (x86)\Foolish IT
2014-08-17 09:19 . 2014-08-18 22:00 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-17 09:18 . 2014-08-17 09:18 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-08-17 09:18 . 2014-08-17 09:18 -------- d-----w- c:\programdata\Malwarebytes
2014-08-17 09:18 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-17 09:18 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-17 09:18 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-17 08:49 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-08-17 08:49 . 2014-08-17 08:52 -------- d-----w- C:\AdwCleaner
2014-08-17 08:39 . 2014-08-18 19:33 -------- d-----w- c:\users\Lorenz\AppData\Local\CrashDumps
2014-08-17 08:27 . 2014-08-17 08:37 36456 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-08-17 08:27 . 2014-08-17 08:27 -------- d-----w- c:\programdata\RogueKiller
2014-08-17 07:49 . 2014-08-18 10:10 -------- d-----w- C:\FRST
2014-08-17 07:25 . 2014-05-02 00:00 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F90A133D-C6D0-4D8F-B6BF-E999DBB7A3FA}\gapaengine.dll
2014-08-17 07:15 . 2014-07-02 03:09 10924376 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-08-14 19:32 . 2014-08-14 19:32 -------- d-----w- c:\program files (x86)\Modern
2014-08-14 08:11 . 2014-08-14 08:12 -------- d-----w- c:\users\Lorenz\AppData\Roaming\faogen3
2014-08-13 22:04 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-13 22:04 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-08-13 22:04 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-13 22:04 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-08-13 22:04 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-08-13 22:04 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-08-13 22:04 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-13 22:04 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 10:45 . 2014-08-07 02:06 529920 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 10:45 . 2014-08-07 02:01 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-08-13 09:15 . 2014-08-13 09:15 -------- d-sh--w- c:\windows\ftpcache
2014-08-11 07:38 . 2014-08-11 07:38 -------- d-----w- c:\program files\Faogen 3
2014-08-10 14:50 . 2014-08-10 15:19 -------- d-----w- c:\programdata\Stardock
2014-08-10 14:50 . 2014-08-10 14:50 -------- d-----w- c:\users\Lorenz\AppData\Local\Stardock
2014-08-10 14:50 . 2014-08-10 14:50 -------- d-----w- c:\users\Lorenz\AppData\Roaming\Stardock
2014-08-10 14:49 . 2014-08-10 15:17 -------- d-----w- c:\program files (x86)\Stardock
2014-08-10 14:36 . 2014-08-10 14:36 -------- d-----w- c:\program files\Microsoft Network Monitor 3
2014-08-08 15:01 . 2014-08-18 10:27 122584 ----a-w- c:\windows\system32\drivers\48230029.sys
2014-08-07 17:31 . 2014-08-17 12:22 -------- d-----w- C:\Autodesk
2014-08-07 10:51 . 2014-08-07 10:51 -------- dc-h--w- c:\programdata\{629D8B17-22B3-46F8-A281-BD604EBA3ED7}
2014-08-05 12:38 . 2014-08-05 12:38 -------- d-----w- c:\users\Lorenz\AppData\Roaming\inkscape
2014-08-05 12:33 . 2014-08-05 12:37 -------- d-----w- c:\program files (x86)\Inkscape
2014-08-04 13:45 . 2014-08-04 13:45 -------- d-----w- c:\users\Lorenz\AppData\Local\Blizzard Entertainment
2014-08-04 13:45 . 2014-08-04 13:45 -------- d-----w- c:\users\Lorenz\AppData\Local\Battle.net
2014-08-04 13:45 . 2014-08-04 13:45 -------- d-----w- c:\users\Lorenz\AppData\Roaming\Battle.net
2014-08-04 13:44 . 2014-08-04 13:45 -------- d-----w- c:\programdata\Blizzard Entertainment
2014-08-04 13:44 . 2014-08-04 13:45 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2014-08-04 13:44 . 2014-08-04 13:45 -------- d-----w- c:\program files (x86)\Battle.net
2014-08-03 11:53 . 2014-08-03 11:53 -------- d-----w- c:\users\Lorenz\AppData\Local\IsolatedStorage
2014-08-03 11:40 . 2014-08-03 11:40 -------- d-----w- c:\users\Public\Quixel
2014-08-01 12:28 . 2014-05-14 16:23 44512 ----a-w- c:\windows\system32\wups2.dll
2014-08-01 12:28 . 2014-05-14 16:23 58336 ----a-w- c:\windows\system32\wuauclt.exe
2014-08-01 12:28 . 2014-05-14 16:23 2477536 ----a-w- c:\windows\system32\wuaueng.dll
2014-08-01 12:28 . 2014-05-14 16:21 2620928 ----a-w- c:\windows\system32\wucltux.dll
2014-08-01 12:27 . 2014-05-14 16:23 38880 ----a-w- c:\windows\system32\wups.dll
2014-08-01 12:27 . 2014-05-14 16:20 97792 ----a-w- c:\windows\system32\wudriver.dll
2014-08-01 12:27 . 2014-05-14 16:23 36320 ----a-w- c:\windows\SysWow64\wups.dll
2014-08-01 12:27 . 2014-05-14 16:23 700384 ----a-w- c:\windows\system32\wuapi.dll
2014-08-01 12:27 . 2014-05-14 16:23 581600 ----a-w- c:\windows\SysWow64\wuapi.dll
2014-08-01 12:27 . 2014-05-14 16:17 92672 ----a-w- c:\windows\SysWow64\wudriver.dll
2014-08-01 12:26 . 2014-05-14 07:23 179656 ----a-w- c:\windows\SysWow64\wuwebv.dll
2014-08-01 12:26 . 2014-05-14 07:23 198600 ----a-w- c:\windows\system32\wuwebv.dll
2014-08-01 12:26 . 2014-05-14 07:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2014-08-01 12:26 . 2014-05-14 07:17 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
2014-07-30 12:06 . 2014-07-30 12:06 -------- d-----w- c:\users\Lorenz\AppData\Local\LogMeIn
2014-07-30 12:06 . 2014-07-30 12:06 -------- d-----w- c:\programdata\LogMeIn
2014-07-30 09:50 . 2014-07-30 09:50 -------- d-----w- c:\users\Lorenz\AppData\Local\Quixel_AB
2014-07-30 09:47 . 2014-07-30 09:47 -------- d-----w- c:\users\Lorenz\AppData\Roaming\Quixel
2014-07-29 11:59 . 2014-07-29 14:19 -------- d-----w- c:\users\Lorenz\AppData\Roaming\TS3Client
2014-07-29 11:56 . 2014-07-29 11:56 -------- d-----w- c:\program files (x86)\TeamSpeak 3 Client
2014-07-27 09:22 . 2014-07-27 09:22 -------- d-----w- c:\users\Lorenz\AppData\Local\Allegorithmic
2014-07-27 09:21 . 2014-07-27 09:21 -------- d-----w- c:\program files\Allegorithmic
2014-07-20 09:45 . 2014-07-20 09:46 -------- d-----w- c:\program files\3D-Coat-V4
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-14 20:06 . 2012-06-10 16:03 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-08-13 22:08 . 2011-04-19 20:25 99218768 ----a-w- c:\windows\system32\MRT.exe
2014-07-06 07:25 . 2013-05-21 18:17 111016 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-07-06 07:25 . 2014-07-06 07:26 313256 ----a-w- c:\windows\system32\javaws.exe
2014-07-06 07:25 . 2013-05-21 18:17 191400 ----a-w- c:\windows\system32\javaw.exe
2014-07-06 07:25 . 2013-05-21 18:17 190888 ----a-w- c:\windows\system32\java.exe
2014-06-30 11:51 . 2014-06-30 11:51 61440 ----a-w- c:\windows\SysWow64\nvPhotoshopUtil.dll
2014-06-30 11:51 . 2014-06-30 11:51 40960 ----a-w- c:\windows\SysWow64\nvISWOW64.dll
2014-06-30 11:51 . 2011-11-12 07:32 151552 ----a-w- c:\windows\SysWow64\nvRegDev.dll
2014-06-25 23:17 . 2014-06-25 23:17 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2014-06-25 23:06 . 2014-06-25 23:06 2938 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
2014-06-23 22:04 . 2012-06-10 16:03 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-06-23 22:04 . 2012-06-10 15:39 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-06-23 14:39 . 2011-04-20 15:11 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-06-18 02:18 . 2014-07-10 07:19 692736 ----a-w- c:\windows\system32\osk.exe
2014-06-18 01:51 . 2014-07-10 07:19 646144 ----a-w- c:\windows\SysWow64\osk.exe
2014-06-07 20:22 . 2014-06-07 18:43 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-06-07 17:12 . 2011-06-24 12:28 386680 ----a-w- c:\windows\system32\drivers\sptd.sys
2014-06-06 10:10 . 2014-07-10 07:19 624128 ----a-w- c:\windows\system32\qedit.dll
2014-06-06 09:44 . 2014-07-10 07:19 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-06-05 14:45 . 2014-07-10 07:18 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-05 14:26 . 2014-07-10 07:18 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-06-05 14:25 . 2014-07-10 07:18 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-05-30 08:08 . 2014-07-10 07:19 210944 ----a-w- c:\windows\system32\wdigest.dll
2014-05-30 08:08 . 2014-07-10 07:19 86528 ----a-w- c:\windows\system32\TSpkg.dll
2014-05-30 08:08 . 2014-07-10 07:19 340992 ----a-w- c:\windows\system32\schannel.dll
2014-05-30 08:08 . 2014-07-10 07:19 314880 ----a-w- c:\windows\system32\msv1_0.dll
2014-05-30 08:08 . 2014-07-10 07:19 307200 ----a-w- c:\windows\system32\ncrypt.dll
2014-05-30 08:08 . 2014-07-10 07:19 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-05-30 08:08 . 2014-07-10 07:19 22016 ----a-w- c:\windows\system32\credssp.dll
2014-05-30 07:52 . 2014-07-10 07:19 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2014-05-30 07:52 . 2014-07-10 07:19 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-05-30 07:52 . 2014-07-10 07:19 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2014-05-30 07:52 . 2014-07-10 07:19 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
2014-05-30 07:52 . 2014-07-10 07:19 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-05-30 07:52 . 2014-07-10 07:19 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-05-30 07:52 . 2014-07-10 07:19 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-05-30 06:45 . 2014-07-10 07:19 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-29 23:00 . 2014-06-07 13:32 1291232 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2014-05-29 23:00 . 2014-06-07 13:32 1122312 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-05-29 22:59 . 2014-06-07 13:32 1715176 ----a-w- c:\windows\system32\nvspbridge64.dll
2014-05-29 22:59 . 2014-06-07 13:32 1279480 ----a-w- c:\windows\system32\nvspcap64.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"EsternTimesMouseExRun"="c:\program files (x86)\Anker Precision Laser Gaming Mouse\AnkerMonEx.exe" [2013-04-23 3351040]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-03-17 224128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 ALSysIO;ALSysIO;c:\users\Lorenz\AppData\Local\Temp\ALSysIO64.sys;c:\users\Lorenz\AppData\Local\Temp\ALSysIO64.sys [x]
R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R4 DAZContentManagementService;DAZ Content Management Service;c:\program files\DAZ 3D\Content Management Service\ContentManagementServer.exe ;c:\program files\DAZ 3D\Content Management Service\ContentManagementServer.exe [x]
R4 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 nm3;Microsoft Network Monitor 3 Driver;c:\windows\system32\DRIVERS\nm3.sys;c:\windows\SYSNATIVE\DRIVERS\nm3.sys [x]
S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 mi-raysat_3dsmax2014_64;mental ray Satellite for Autodesk 3ds Max 2014 64-bit;c:\program files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe;c:\program files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 RealtekCU;RealtekCU;c:\program files (x86)\Sitecom\WiFi USB adapter N300 Driver and Utility\RtlService.exe;c:\program files (x86)\Sitecom\WiFi USB adapter N300 Driver and Utility\RtlService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 WTabletServicePro;Wacom Professional Service;c:\program files\Tablet\Wacom\WTabletServicePro.exe;c:\program files\Tablet\Wacom\WTabletServicePro.exe [x]
S3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys;c:\windows\SYSNATIVE\DRIVERS\nvoclk64.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtwlanu.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlanu.sys [x]
S3 WacHidRouter;Wacom Hid Router;c:\windows\system32\DRIVERS\wachidrouter.sys;c:\windows\SYSNATIVE\DRIVERS\wachidrouter.sys [x]
S3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2014-08-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-20 19:41]
.
2014-08-18 c:\windows\Tasks\AdobeAAMUpdater-1.0-Computer-Lorenz.job
- c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2014-04-05 04:09]
.
2014-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-08 13:46]
.
2014-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-08 13:46]
.
2014-08-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-721527169-3598334179-861810665-1000Core.job
- c:\users\Lorenz\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-19 20:29]
.
2014-08-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-721527169-3598334179-861810665-1000UA.job
- c:\users\Lorenz\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-19 20:29]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-02-21 2991856]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-05-29 2350880]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-05-29 1279480]
"Fences"="c:\program files (x86)\Stardock\Fences\Fences.exe" [2014-05-22 3993744]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2014-05-22 521872]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube to MP3 Converter - c:\users\Lorenz\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.192.1
FF - ProfilePath - c:\users\Lorenz\AppData\Roaming\Mozilla\Firefox\Profiles\ddofuwyq.default\
FF - prefs.js: browser.startup.homepage - www.google.de
.
.
------- Dateityp-Verknüpfung -------
.
txtfile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
.scr=CryptoPreventSCR
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Arma 2 Army of The Czech Republic (LITE) - c:\program files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ACR_Lite_UnInstall.exe
AddRemove-BattlEye for OA - c:\program files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\BattlEye\UnInstallBE.exe
AddRemove-UnityWebPlayer - c:\users\Lorenz\AppData\Local\Unity\WebPlayer\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-721527169-3598334179-861810665-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:1e,43,f4,f8,d5,00,6e,85,9f,82,83,be,9d,d9,cd,5e,c3,c2,da,3c,ca,38,67,
42,d5,f5,10,c4,f6,5b,c7,d7,7e,c1,23,d5,1e,66,07,48,95,0c,fd,e5,e7,fb,6d,09,\
"??"=hex:5f,c1,36,f8,82,e2,79,84,23,72,b2,5c,4e,1d,6f,2c
.
[HKEY_USERS\S-1-5-21-721527169-3598334179-861810665-1000\Software\SecuROM\License information*]
"datasecu"=hex:a2,ea,34,eb,3c,53,82,20,91,a1,52,88,9f,81,9e,ef,97,1d,d1,52,1b,
47,a5,2b,55,75,2b,2a,10,61,ad,d2,ec,ed,8b,8e,93,fd,44,6b,7f,f5,e8,cb,3d,7b,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_USERS\S-1-5-21-721527169-3598334179-861810665-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\c:\Program Files (x86)\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"qgif4.dll"=multi:"2011-10-10T16:42\00gif\00\00"
"qico4.dll"=multi:"2011-10-10T16:42\00ico\00\00"
"qjpeg4.dll"=multi:"2011-10-10T16:42\00jpeg\00jpg\00\00"
.
[HKEY_USERS\S-1-5-21-721527169-3598334179-861810665-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\c:\program files (x86)\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"Microsoft.VC80.CRT.manifest"=multi:"0\001\00unknown\002011-10-10T16:42\00\00"
"msvcr80.dll"=multi:"0\001\00unknown\002011-10-10T16:42\00\00"
"qgif4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00"
"qico4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00"
"qjpeg4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Sitecom\WiFi USB adapter N300 Driver and Utility\RtWlan.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-08-19 00:07:18 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-08-18 22:07
.
Vor Suchlauf: 10 Verzeichnis(se), 415.141.552.128 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 415.947.403.264 Bytes frei
.
- - End Of File - - B1CB37D2F418070656FEDA01E71A9F36
A36C5E4F47E84449FF07ED3517B43A31
Looks like it automatically used my OS language. I can translate all of that if you need me to
