|   | kevinanthony | 17.12.2014 01:16 |  
 moin, anbei einmal die Log vom Combofix :   Code: 
 ComboFix 14-12-14.01 - Siddiq 17.12.2014   0:46.1.4 - x64Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.5119.2305 [GMT 1:00]
 ausgeführt von:: c:\users\Siddiq\Desktop\ComboFix.exe
 AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
 SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
 SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
 SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 .
 .
 ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 c:\programdata\6577510721512629562
 c:\programdata\6577510721512629562\cd5b15e575e1c3d0cb41a56236abc36b.ini
 c:\windows\msdownld.tmp
 c:\windows\SysWow64\Packet.dll
 c:\windows\SysWow64\pthreadVC.dll
 c:\windows\SysWow64\SET4D53.tmp
 c:\windows\SysWow64\SET5B7B.tmp
 c:\windows\SysWow64\SET705A.tmp
 c:\windows\SysWow64\wpcap.dll
 .
 .
 (((((((((((((((((((((((((((((((((((((((   Treiber/Dienste   )))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 -------\Legacy_NPF
 -------\Service_npf
 .
 .
 (((((((((((((((((((((((   Dateien erstellt von 2014-11-17 bis 2014-12-17  ))))))))))))))))))))))))))))))
 .
 .
 2014-12-16 23:57 . 2014-12-16 23:57        --------        d-----w-        c:\users\Kevo\AppData\Local\temp
 2014-12-16 23:57 . 2014-12-16 23:57        --------        d-----w-        c:\users\Default\AppData\Local\temp
 2014-12-16 15:31 . 2014-12-16 15:31        --------        d-----w-        c:\program files (x86)\BuuyNsAVe
 2014-12-16 15:30 . 2014-12-16 15:30        --------        d-----w-        c:\programdata\nlcgledcgbnjgnhikehaekocgppemfni
 2014-12-16 15:29 . 2014-12-16 16:08        --------        d-----w-        c:\users\Siddiq\AppData\Roaming\DMCache
 2014-12-16 14:51 . 2014-12-02 10:26        11870360        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B545F141-9BE2-4DCE-B496-2A5CCFC7CC3D}\mpengine.dll
 2014-12-16 14:38 . 2014-12-16 23:38        --------        d-----w-        c:\programdata\Spybot - Search & Destroy
 2014-12-16 14:38 . 2014-12-16 23:59        --------        d-----w-        c:\program files (x86)\Spybot - Search & Destroy 2
 2014-12-16 13:10 . 2014-12-17 00:03        129752        ----a-w-        c:\windows\system32\drivers\MBAMSwissArmy.sys
 2014-12-16 13:09 . 2014-12-16 13:09        --------        d-----w-        c:\program files (x86)\Malwarebytes Anti-Malware
 2014-12-16 13:09 . 2014-11-21 05:14        63704        ----a-w-        c:\windows\system32\drivers\mwac.sys
 2014-12-16 13:09 . 2014-11-21 05:14        93400        ----a-w-        c:\windows\system32\drivers\mbamchameleon.sys
 2014-12-16 13:09 . 2014-11-21 05:14        25816        ----a-w-        c:\windows\system32\drivers\mbam.sys
 2014-12-15 14:38 . 2014-11-02 04:20        11632448        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
 2014-12-11 05:47 . 2014-09-21 15:28        1188440        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F3563E0C-1A8F-43D1-A396-89895392982D}\gapaengine.dll
 2014-12-10 17:54 . 2014-12-10 17:54        3981488        ----a-w-        c:\windows\SysWow64\FlashPlayerInstaller.exe
 2014-12-07 16:04 . 2014-12-07 16:04        --------        d-----w-        c:\users\Siddiq\AppData\Roaming\Unity
 2014-12-07 15:56 . 2014-12-07 15:56        --------        d-----w-        c:\users\Siddiq\AppData\Roaming\.mono
 2014-12-07 14:02 . 2014-12-07 14:02        --------        d-----w-        c:\program files\Unity
 2014-11-30 18:57 . 2014-11-30 18:57        --------        d-----w-        c:\users\Siddiq\AppData\Local\Apps
 2014-11-30 18:57 . 2014-11-30 18:59        --------        d-----w-        c:\users\Siddiq\AppData\Local\Deployment
 .
 .
 .
 ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2014-12-16 14:55 . 2013-10-01 15:17        348928        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
 2014-12-16 14:55 . 2013-10-01 10:17        348928        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
 2014-12-16 14:55 . 2013-10-01 10:17        290184        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
 2014-12-10 17:54 . 2013-10-02 16:56        71344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
 2014-12-10 17:54 . 2013-10-02 16:56        701104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
 2014-10-30 11:25 . 2013-08-21 23:08        275080        ------w-        c:\windows\system32\MpSigStub.exe
 2014-10-17 15:23 . 2014-10-17 15:23        14544        ----a-w-        c:\windows\SysWow64\drivers\hmonitor45.sys
 2014-09-21 15:28 . 2013-10-18 13:53        1188440        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
 .
 .
 ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
 REGEDIT4
 .
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "GoogleChromeAutoLaunch_DCDE99E772EF02AB63A59D2B2790539C"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-12-10 898376]
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
 "Module Loader"="c:\program files (x86)\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
 "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-11-20 1021128]
 .
 c:\users\Kevo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
 PdaNet Desktop.lnk - c:\program files (x86)\PdaNet for Android\PdaNetPC.exe [2014-10-17 1054432]
 .
 c:\users\Siddiq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
 Dropbox.lnk - c:\users\Siddiq\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-11-13 35419192]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
 "ConsentPromptBehaviorAdmin"= 5 (0x5)
 "ConsentPromptBehaviorUser"= 3 (0x3)
 "EnableUIADesktopToggle"= 0 (0x0)
 "PromptOnSecureDesktop"= 0 (0x0)
 .
 [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
 "LoadAppInit_DLLs"=1 (0x1)
 .
 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
 BootExecute        REG_MULTI_SZ           autocheck autochk *\0\0sdnclean64.exe
 .
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
 @="Service"
 .
 R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
 R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
 R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
 R3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys;c:\windows\SYSNATIVE\Drivers\HDJBulk.sys [x]
 R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
 R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
 R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
 R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x]
 R3 HDJMidi;DJ Control MP3 e2 MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys;c:\windows\SYSNATIVE\DRIVERS\HDJMidi.sys [x]
 R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
 R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
 R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
 R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
 R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
 R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
 R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
 R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
 R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
 R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
 R3 SafeIPS;SafeIPS;c:\program files (x86)\SafeIP\SafeIPs.exe;c:\program files (x86)\SafeIP\SafeIPs.exe [x]
 R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
 R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
 R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
 R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x]
 R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
 R3 usbrndis6;USB-RNDIS6-Adapter;c:\windows\system32\DRIVERS\usb80236.sys;c:\windows\SYSNATIVE\DRIVERS\usb80236.sys [x]
 S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
 S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
 S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
 S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
 S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
 S2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE;c:\program files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [x]
 S2 HTCMonitorService;HTCMonitorService;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [x]
 S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
 S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
 S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
 S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
 S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
 S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
 S3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys;c:\windows\SYSNATIVE\Drivers\androidusb.sys [x]
 S3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys;c:\windows\SYSNATIVE\DRIVERS\easytthr.sys [x]
 S3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17b64.sys;c:\windows\SYSNATIVE\drivers\hcw17b64.sys [x]
 S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys;c:\windows\SYSNATIVE\drivers\ksaud.sys [x]
 S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
 S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
 S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
 S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
 S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
 S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
 S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x]
 S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
 .
 .
 --- Andere Dienste/Treiber im Speicher ---
 .
 *NewlyCreated* - MBAMSWISSARMY
 .
 Inhalt des "geplante Tasks" Ordners
 .
 2014-12-16 c:\windows\Tasks\Adobe Flash Player Updater.job
 - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-02 17:54]
 .
 2014-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
 - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-30 19:01]
 .
 2014-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
 - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-30 19:01]
 .
 .
 --------- X64 Entries -----------
 .
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
 @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
 @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
 @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
 @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
 @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
 @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
 @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
 @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
 2014-08-17 04:10        164760        ----a-w-        c:\users\Siddiq\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 1331288]
 "Creative SB Monitoring Utility"="sbavmon.dll" [2009-12-16 109056]
 .
 ------- Zusätzlicher Suchlauf -------
 .
 uLocal Page = c:\windows\system32\blank.htm
 mLocal Page = c:\windows\SysWOW64\blank.htm
 TCP: DhcpNameServer = 192.168.42.129
 DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
 .
 - - - - Entfernte verwaiste Registrierungseinträge - - - -
 .
 ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
 ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
 ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
 HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
 HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\40.0.2182.3\Installer\chrmstp.exe
 ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
 ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
 ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
 AddRemove-SAFEIP_is1 - c:\program files (x86)\SafeIP\unins000.exe
 .
 .
 .
 --------------------- Gesperrte Registrierungsschluessel ---------------------
 .
 [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
 @Denied: (2) (LocalSystem)
 .
 [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
 @Denied: (2) (LocalSystem)
 "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
 d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a2,89,7d,6c,df,07,af,4c,87,77,9b,\
 "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
 d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a2,89,7d,6c,df,07,af,4c,87,77,9b,\
 .
 [HKEY_LOCAL_MACHINE\software\BlueStacks]
 "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
 @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_246_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker6"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Shockwave Flash Object"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
 @="0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
 @="ShockwaveFlash.ShockwaveFlash.15"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="ShockwaveFlash.ShockwaveFlash"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Macromedia Flash Factory Object"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
 @="FlashFactory.FlashFactory.1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_246.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="FlashFactory.FlashFactory"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker6"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
 @Denied: (A) (Users)
 @Denied: (A) (Everyone)
 @Allowed: (B 1 2 3 4 5) (S-1-5-20)
 "BlindDial"=dword:00000000
 .
 [HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
 @Denied: (Full) (Everyone)
 .
 ------------------------ Weitere laufende Prozesse ------------------------
 .
 c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
 c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
 c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 c:\windows\SysWOW64\PnkBstrA.exe
 c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
 c:\program files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
 .
 **************************************************************************
 .
 Zeit der Fertigstellung: 2014-12-17  01:10:00 - PC wurde neu gestartet
 ComboFix-quarantined-files.txt  2014-12-17 00:09
 ComboFix2.txt  2013-07-05 11:40
 .
 Vor Suchlauf: 49 Verzeichnis(se), 166.814.765.056 Bytes frei
 Nach Suchlauf: 51 Verzeichnis(se), 168.791.334.912 Bytes frei
 .
 - - End Of File - - 66DC0F097042791EC9754C60CB769230
 A36C5E4F47E84449FF07ED3517B43A31
 mfg Kevin. |