Hallo, das ist der LOG :    Code:  
 ComboFix 13-08-29.02 - Timo Tischler 29.08.2013  22:58:05.1.2 - x86 
ausgeführt von:: c:\users\Timo Tischler\Desktop\ComboFix.exe 
 * Neuer Wiederherstellungspunkt wurde erstellt 
. 
. 
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
c:\program files\Hyperionics DB Toolbar\tbHElper.dll 
c:\programdata\3D3 
c:\programdata\3D3\mm.db 
c:\programdata\3D3\thumbnail.db 
c:\users\Timo Tischler\AppData\Local\Minibar 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\background.html 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\cached_http_request.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\extension_info.json 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\icons\icon128.png 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\icons\icon19.png 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\icons\icon32.png 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\icons\icon48.png 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\includes\content.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\includes\content_kango.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\includes\content_messaging.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\includes\content_userscript.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango-ui\button.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango-ui\ui.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\browser.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\console.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\event_listener.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\initialize.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\io.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\jsonstorage.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\kango.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\lang.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\messaging.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\userscript_engine.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\kango\xhr.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\main.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\manifest.json 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\minibar\actions.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\minibar\cachedxhr.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\minibar\config.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\minibar\macros.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\minibar\minibar.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\popup.html 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\popup.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\tab.html 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome\tab.js 
c:\users\Timo Tischler\AppData\Local\Minibar\chrome_installer.js 
c:\users\Timo Tischler\AppData\Local\Minibar\common.js 
c:\users\Timo Tischler\AppData\Local\Minibar\install.json 
c:\users\Timo Tischler\AppData\Local\Minibar\minibar.crx 
c:\users\Timo Tischler\AppData\Local\Minibar\sqlite3.exe 
c:\users\Timo Tischler\AppData\Local\Minibar\Uninstall.exe 
c:\windows\Installer\{FD76A02F-9E81-A3A9-D53C-2A4DB5201B24}\syshost.exe 
c:\windows\IsUn0407.exe 
c:\windows\system32\drivers\10CF_FUJITSU_FTS_AMILO Xi 3650_FUJITSU SIEMENS_XY680 _Version 1.0_FSC - 6040000_1.0E-1646-0021_Mobile Intel(R) 4 Series Express Chipset Family_NVIDIA GeForce 9600M GT .MRK 
c:\windows\system32\tempdir 
c:\windows\system32\tempdir\tinypdf.chm 
c:\windows\system32\tempdir\tinypdf.dll 
c:\windows\system32\tempdir\tinypdf1.dll 
c:\windows\system32\tempdir\tinypdf2.dll 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2013-07-28 bis 2013-08-29  )))))))))))))))))))))))))))))) 
. 
. 
2013-08-30 04:10 . 2013-08-30 04:10        --------        d-----w-        C:\FRST 
2013-08-29 20:41 . 2013-08-29 20:41        --------        d-----w-        C:\found.004 
2013-08-29 16:25 . 2013-08-29 16:37        30976        ----a-w-        c:\windows\system32\drivers\hitmanpro37.sys 
2013-08-29 16:24 . 2013-08-29 16:31        --------        d-----w-        c:\programdata\HitmanPro 
2013-08-25 11:12 . 2013-08-25 11:12        --------        d-----w-        c:\users\Timo Tischler\AppData\Roaming\Okidata 
2013-08-02 16:41 . 2011-05-10 07:26        9216        ----a-w-        c:\windows\system32\drivers\massfilter.sys 
2013-08-02 16:41 . 2011-05-10 07:26        116736        ----a-w-        c:\windows\system32\drivers\ZTEusbnet.sys 
2013-08-02 16:41 . 2011-05-10 07:26        107776        ----a-w-        c:\windows\system32\drivers\ZTEusbser6k.sys 
2013-08-02 16:41 . 2011-05-10 07:26        107776        ----a-w-        c:\windows\system32\drivers\ZTEusbnmea.sys 
2013-08-02 16:41 . 2011-05-10 07:26        107776        ----a-w-        c:\windows\system32\drivers\ZTEusbmdm6k.sys 
2013-08-02 16:40 . 2013-08-02 16:41        --------        d-----w-        c:\program files\SupportAppCB 
2013-08-02 16:40 . 2013-08-02 16:40        --------        d-----w-        c:\program files\MF60 Mobile Hotspot 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] 
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\prxtbWin0.dll" [2011-05-09 176936] 
. 
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}] 
2011-05-09 09:49        176936        ----a-w-        c:\program files\Winload\prxtbWin0.dll 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] 
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\prxtbWin0.dll" [2011-05-09 176936] 
. 
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}] 
. 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384] 
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] 
"GoogleChromeAutoLaunch_02FD4696E8D584CA28380A4E066BEED4"="c:\program files\Google\Chrome\Application\chrome.exe" [2013-08-16 829392] 
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-04-19 18678376] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-17 13531680] 
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-17 92704] 
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-12 150040] 
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-12 170520] 
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-12 145944] 
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-08 6139904] 
"FIC HotKey"="c:\program files\Hotkey Utility\tray.exe" [2008-06-05 520192] 
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] 
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-20 178712] 
"PowerManager"="c:\program files\Power Manager\PM.exe" [2008-05-22 1675264] 
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2007-04-11 26704] 
"lxdomon.exe"="c:\program files\Lexmark 9500 Series\lxdomon.exe" [2007-09-06 450560] 
"lxdoamon"="c:\program files\Lexmark 9500 Series\lxdoamon.exe" [2007-08-10 20480] 
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-02-18 202256] 
"TrayServer"="c:\program files\MAGIX\Video_deluxe_17_Plus_Sonderedition_Download-Version\TrayServer.exe" [2008-08-07 90112] 
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] 
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280] 
"IndexSearch"="c:\program files\Nuance\PaperPort\IndexSearch.exe" [2010-03-08 46368] 
"PaperPort PTD"="c:\program files\Nuance\PaperPort\pptd40nt.exe" [2010-03-08 29984] 
"PPort12reminder"="c:\program files\Nuance\PaperPort\Ereg\Ereg.exe" [2010-02-09 328992] 
"PDFHook"="c:\program files\Nuance\PDF Viewer Plus\pdfpro5hook.exe" [2010-03-05 636192] 
"PDF5 Registry Controller"="c:\program files\Nuance\PDF Viewer Plus\RegistryController.exe" [2010-03-05 62752] 
"ControlCenter4"="c:\program files\ControlCenter4\BrCcBoot.exe" [2011-04-20 139264] 
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2011-05-19 2629632] 
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2012-09-09 421776] 
. 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] 
"DeleteEngineAfterUpdate"="reg DELETE HKCU\Software\AppDataLow\Software\ConduitEngine" [X] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorAdmin"= 0 (0x0) 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableLUA"= 0 (0x0) 
"EnableUIADesktopToggle"= 0 (0x0) 
"PromptOnSecureDesktop"= 0 (0x0) 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] 
"aux"=wdmaud.drv 
. 
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] 
BootExecute        REG_MULTI_SZ           autocheck autochk *\0auto_reactivate \\?\Volume{8b33aa80-978c-11de-a815-806e6f6e6963}\bootwiz\asrm.bin 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] 
@="" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] 
@="" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] 
@="" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] 
@="" 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0] 
2007-05-10 20:46        624248        ----a-w-        c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service] 
2009-11-12 04:42        362032        ----a-w-        c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 
2008-06-12 00:38        34672        ----a-w-        c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] 
2008-01-25 05:22        159744        ----a-w-        c:\program files\Apoint2K\Apoint.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] 
2010-02-17 18:37        177472        ----a-w-        c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FSCRecovery] 
2008-06-18 12:25        268096        ----a-w-        c:\program files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ITSecMng] 
2007-09-28 14:03        75136        ----a-w-        c:\program files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 9500 Series Fax Server] 
2007-09-18 10:28        307200        ----a-w-        c:\program files\Lexmark 9500 Series\fm3032.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 
2010-03-17 19:53        421888        ----a-w-        c:\program files\QuickTime\QTTask.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 
2010-02-18 15:52        202256        ----a-w-        c:\program files\Common Files\Real\Update_OB\realsched.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe] 
2009-11-12 04:42        5140960        ----a-w-        d:\program files\Acronis Trueimage\TrueImageMonitor.exe 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys] 
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" /hide 
. 
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-04-19 161384] 
R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-02-09 160288] 
R3 dc3d;MS Hardware Device Detection Driver (HID);c:\windows\system32\DRIVERS\dc3d.sys [2009-11-04 17408] 
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-05-06 13904] 
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800] 
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2013-08-29 30976] 
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2011-05-10 9216] 
R3 Tdsshbecr;Handelsbanken card reader;c:\windows\system32\DRIVERS\shbecr.sys [2008-09-28 42368] 
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-16 1343400] 
R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2011-05-10 116736] 
R4 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-02-09 2480048] 
R4 FSCLBaseUpdaterService;FSCLBaseUpdaterService;c:\program files\Fujitsu Siemens Computers\FSCLounge\FSCWBaseUpdaterService\2\FSCWBaseUpdaterService.exe [2007-06-04 65536] 
R4 O&O DriveLED;O&O DriveLED Service;c:\program files\OO Software\DriveLED\oodlag.exe [2009-09-28 529664] 
S0 OODrvled;OODrvled;c:\windows\system32\DRIVERS\OODrvled.sys [2009-09-28 25608] 
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-02-09 911680] 
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376] 
S2 lxdo_device;lxdo_device;c:\windows\system32\lxdocoms.exe [2007-09-20 589824] 
S2 lxdoCATSCustConnectService;lxdoCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdoserv.exe [2007-07-17 94208] 
S2 OpLclSrv;OKI Local Port Manager;c:\program files\Okidata\Common\Extend3\portmgrsrv.exe [2011-04-11 139264] 
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-08 144672] 
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2011-03-18 5120] 
S3 BrYNSvc;BrYNSvc;c:\program files\Browny02\BrYNSvc.exe [2010-01-25 245760] 
S3 e1yexpress;Intel(R) Gigabit-Netzwerkverbindungstreiber;c:\windows\system32\DRIVERS\e1y6032.sys [2009-07-13 214016] 
S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] 
. 
. 
--- Andere Dienste/Treiber im Speicher --- 
. 
*NewlyCreated* - AVGNTFLT 
*NewlyCreated* - IPNAT 
*Deregistered* - avfwot 
*Deregistered* - avgntflt 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 
2013-08-22 14:42        1177552        ----a-w-        c:\program files\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2013-08-29 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 17:09] 
. 
2013-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-06 13:45] 
. 
2013-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-06 13:45] 
. 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uStart Page = hxxp://www.google.de/ 
mStart Page = hxxp://www.bigseekpro.com/hypercam/{C6C86047-3328-46DE-BDF4-E5145B5BA962} 
uInternet Settings,ProxyOverride = *.local 
IE: An vorhandenes PDF anfügen - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html 
IE: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html 
IE: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html 
IE: Auswahl in Adobe PDF konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html 
IE: Auswahl in vorhandene PDF-Datei konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html 
IE: Free YouTube to MP3 Converter - c:\users\Timo Tischler\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm 
IE: In Adobe PDF konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html 
IE: Verknüpfungsziel in Adobe PDF konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html 
IE: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html 
TCP: DhcpNameServer = 192.168.174.1 
TCP: Interfaces\{FF75917C-E18C-4378-809D-BBE54B81C17C}: NameServer = 192.168.174.254 
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://82.99.75.137/activex/AMC.cab 
FF - ProfilePath - c:\users\Timo Tischler\AppData\Roaming\Mozilla\Firefox\Profiles\0q1up566.default\ 
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms} 
FF - prefs.js: browser.search.selectedEngine - Winload Customized Web Search 
FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/hypercam/{4597E343-791B-48A7-AF44-F05300000950} 
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/hypercam/{4597E343-791B-48A7-AF44-F05300000950}?q= 
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} 
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} 
FF - Ext: Winload Community Toolbar: {40c3cc16-7269-4b32-9531-17f2950fb06f} - %profile%\extensions\{40c3cc16-7269-4b32-9531-17f2950fb06f} 
FF - Ext: HyperionicsDB Toolbar: {75656794-AB59-4712-BFBC-5D816D56F3BC} - %profile%\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC} 
FF - Ext: Free YouTube Download (Free Studio) Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} 
FF - user.js: network.cookie.cookieBehavior - 0 
FF - user.js: privacy.clearOnShutdown.cookies - false 
FF - user.js: security.warn_viewing_mixed - false 
FF - user.js: security.warn_viewing_mixed.show_once - false 
FF - user.js: security.warn_submit_insecure - false 
FF - user.js: security.warn_submit_insecure.show_once - false 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
AddRemove-WAV To MP3_is1 - d:\wav to mp3\unins000.exe 
AddRemove-web2date - c:\windows\IsUn0407.exe 
AddRemove-{13153F10-CAE7-4C15-A0B0-C51B9BA3CAAA}_is1 - d:\jagderleben\unins000.exe 
. 
. 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] 
@Denied: (2) (LocalSystem) 
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90, 
   43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87 
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"=hex:51,66,7a,6c,4c,1d,38,12,8d,ec,f8, 
   7b,2b,25,27,06,e7,c4,bc,f0,98,15,0d,de 
"{338B4DFE-2E2C-4338-9E41-E176D497299E}"=hex:51,66,7a,6c,4c,1d,38,12,90,4e,98, 
   37,1e,60,56,06,e1,57,a2,36,d1,c9,6d,8a 
"{40C3CC16-7269-4B32-9531-17F2950FB06F}"=hex:51,66,7a,6c,4c,1d,38,12,78,cf,d0, 
   44,5b,3c,5c,0e,ea,27,54,b2,90,51,f4,7b 
"{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea, 
   34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89 
"{182EC0BE-5110-49C8-A062-BEB1D02A220B}"=hex:51,66,7a,6c,4c,1d,38,12,d0,c3,3d, 
   1c,22,1f,a6,0c,df,74,fd,f1,d5,74,66,1f 
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 
   2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, 
   fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 
"{10945114-B19F-4614-8450-B25E444A1020}"=hex:51,66,7a,6c,4c,1d,38,12,7a,52,87, 
   14,ad,ff,7a,03,fb,46,f1,1e,41,14,54,34 
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 
"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a, 
   34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de 
"{551A852F-39A6-44A7-9C13-AFBEC9185A9D}"=hex:51,66,7a,6c,4c,1d,38,12,41,86,09, 
   51,94,77,c9,01,e3,05,ec,fe,cc,46,1e,89 
"{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}"=hex:51,66,7a,6c,4c,1d,38,12,60,d8,39, 
   64,cd,04,79,07,f5,b7,d6,9a,c1,81,e0,1c 
"{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40, 
   69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18 
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 
   76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a 
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23, 
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2 
"{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f, 
   aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04 
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, 
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd 
"{FCBCCB87-9224-4B8D-B117-F56D924BEB18}"=hex:51,66,7a,6c,4c,1d,38,12,e9,c8,af, 
   f8,16,dc,e3,0e,ce,01,b6,2d,97,15,af,0c 
. 
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] 
@Denied: (2) (LocalSystem) 
"Timestamp"=hex:09,a8,28,19,ff,a2,cd,01 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] 
@Denied: (A) (Users) 
@Denied: (A) (Everyone) 
@Allowed: (B 1 2 3 4 5) (S-1-5-20) 
"BlindDial"=dword:00000000 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
. 
--------------------- Durch laufende Prozesse gestartete DLLs --------------------- 
. 
- - - - - - - > 'Explorer.exe'(4048) 
c:\windows\system32\MSVCR71.dll 
c:\windows\system32\NVSVC.DLL 
c:\program files\WinSCP\DragExt.dll 
. 
------------------------ Weitere laufende Prozesse ------------------------ 
. 
c:\windows\system32\nvvsvc.exe 
c:\windows\system32\rundll32.exe 
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe 
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 
c:\program files\Bonjour\mDNSResponder.exe 
c:\windows\system32\LMabcoms.exe 
c:\windows\system32\spool\DRIVERS\W32X86\3\lxdoserv.exe 
d:\programme\CDBurnerXP\NMSAccessU.exe 
c:\windows\servicing\TrustedInstaller.exe 
c:\windows\system32\taskhost.exe 
c:\windows\system32\conhost.exe 
c:\windows\System32\rundll32.exe 
c:\windows\RtHDVCpl.exe 
c:\program files\ControlCenter4\BrCtrlCntr.exe 
c:\program files\ControlCenter4\BrCcUxSys.exe 
c:\program files\iPod\bin\iPodService.exe 
c:\windows\System32\spool\drivers\w32x86\3\WrtProc.exe 
c:\program files\Windows Media Player\wmpnetwk.exe 
c:\windows\system32\sppsvc.exe 
c:\program files\Common Files\Java\Java Update\jucheck.exe 
. 
************************************************************************** 
. 
Zeit der Fertigstellung: 2013-08-29  23:15:40 - PC wurde neu gestartet 
ComboFix-quarantined-files.txt  2013-08-29 21:15 
. 
Vor Suchlauf: 30 Verzeichnis(se), 18.596.855.808 Bytes frei 
Nach Suchlauf: 42 Verzeichnis(se), 19.585.310.720 Bytes frei 
. 
- - End Of File - - BD64D7F318A3406D87F85A5C31D481D5 
CA5D868F04144D0BC30199794ADB1DEC      |