ok, dann versuche ich das mal. hier loggfile von mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Skannedato: 19.03.2016
Skannetid: 03:36
Loggfil:
Administrator: Ja
Versjon: 2.2.0.1024
Malwaredatabase: v2016.03.18.06
Rootkitdatabase: v2016.03.12.01
Lisens: Prøveversjon
Malwarebeskyttelse: Aktivert
Ondsinnet Nettsidebeskyttelse: Aktivert
Selvbeskyttelse: Deaktivert
OS: Windows 8.1
CPU: x64
Filsystem: NTFS
Bruker: Hein
Skannetype: Trusselskann
Resultat: Fullført
Objekter skannet: 387636
Tid brukt: 6 min, 25 sek
Minne: Aktivert
Oppstart: Aktivert
Filsystem: Aktivert
Arkiv: Aktivert
Rootkits: Deaktivert
Heuristikk: Aktivert
PUP: Aktivert
PUM: Aktivert
Prosesser: 0
(Ingen ondsinnede elementer funnet)
Moduler: 0
(Ingen ondsinnede elementer funnet)
Registernøkler: 0
(Ingen ondsinnede elementer funnet)
Registerverdier: 0
(Ingen ondsinnede elementer funnet)
Registerdata: 0
(Ingen ondsinnede elementer funnet)
Mapper: 0
(Ingen ondsinnede elementer funnet)
Filer: 0
(Ingen ondsinnede elementer funnet)
Fysiske sektorer: 0
(Ingen ondsinnede elementer funnet)
(end) und dieses hier Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Scheduler, Malware Database, 2016.3.18.4, 2016.3.18.6,
Protection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Starting,
Protection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopping,
Protection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopped,
Protection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Success,
Protection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Starting,
Protection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Started,
Detection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50343, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50343, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50344, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:28, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50357, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:29, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50374, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:29, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50375, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:56, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50651, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 00:59, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50672, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 01:18, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50862, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 01:18, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50863, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 01:18, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50864, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 01:19, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 50972, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 01:19, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 51011, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 01:19, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 51045, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52016, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52017, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52018, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:08, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52049, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:08, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52050, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:08, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52051, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:08, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52053, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:08, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52054, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:08, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52055, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52875, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52893, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52971, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52972, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52973, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52974, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52975, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52979, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52980, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52984, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52985, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 52986, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53184, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53185, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53190, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53191, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53192, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 02:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53310, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 03:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 53986, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Scan, 19.03.2016 03:42, SYSTEM, RECHENSCHLAMPE, Context, Start: 19.03.2016 03:36, Varighet: 6 min 25 sek, Trusselskann, Fullført, 0 Malwareidentifiseringer, 0 PUP/PUM-identifiseringer,
Detection, 19.03.2016 03:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54295, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 03:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54295, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 03:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54296, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 03:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54297, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 03:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54300, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 03:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54420, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:27, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 54743, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Update, 19.03.2016 04:53, SYSTEM, RECHENSCHLAMPE, Scheduler, Malware Database, 2016.3.18.6, 2016.3.19.1,
Protection, 19.03.2016 04:53, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Starting,
Protection, 19.03.2016 04:53, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopping,
Protection, 19.03.2016 04:53, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopped,
Protection, 19.03.2016 04:54, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Success,
Protection, 19.03.2016 04:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Starting,
Protection, 19.03.2016 04:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Started,
Detection, 19.03.2016 04:56, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55130, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:56, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55130, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:56, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55131, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:56, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55132, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:56, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55134, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55190, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:59, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55208, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 04:59, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55209, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Update, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Scheduler, Malware Database, 2016.3.19.1, 2016.3.19.2,
Protection, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Starting,
Protection, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopping,
Protection, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopped,
Protection, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Success,
Protection, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Starting,
Protection, 19.03.2016 09:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Started,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55354, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55354, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55355, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55359, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55360, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55361, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55372, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55373, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 09:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55374, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:30, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55576, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:30, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55577, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:30, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55617, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:30, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55618, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:50, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55827, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:50, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55840, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 12:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 55971, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:06, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56147, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Update, 19.03.2016 14:06, SYSTEM, RECHENSCHLAMPE, Scheduler, Malware Database, 2016.3.19.2, 2016.3.19.3,
Protection, 19.03.2016 14:06, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Starting,
Protection, 19.03.2016 14:06, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopping,
Protection, 19.03.2016 14:06, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopped,
Protection, 19.03.2016 14:07, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Success,
Protection, 19.03.2016 14:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Starting,
Protection, 19.03.2016 14:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Started,
Detection, 19.03.2016 14:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56373, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56374, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:36, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56373, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:41, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56430, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:41, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56431, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:41, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56432, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56438, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56439, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56443, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56444, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56445, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56454, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56462, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56463, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56497, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56501, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56502, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56503, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56504, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56505, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56517, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:42, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56532, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:43, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56559, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:43, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56570, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56575, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56576, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56577, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56578, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56590, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56602, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56603, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56604, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:44, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56620, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:45, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56631, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:46, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56654, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:47, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56659, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:47, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56665, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:47, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56671, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56675, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56683, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56684, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56688, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56689, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56690, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56710, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56711, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56720, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56721, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 14:49, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56722, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Update, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Scheduler, Domain Database, 2016.3.18.2, 2016.3.19.1,
Protection, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Starting,
Protection, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopping,
Protection, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopped,
Protection, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Success,
Protection, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Starting,
Protection, 19.03.2016 14:54, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Started,
Detection, 19.03.2016 15:06, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56904, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:06, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56904, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:06, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 56905, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:34, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57214, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57390, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57402, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57403, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57408, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57409, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57410, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:39, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57425, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:39, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57426, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:39, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57430, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:39, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57431, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:39, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57432, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57462, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57463, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57466, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57467, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57468, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57473, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 15:40, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 57474, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 16:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 58279, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 16:37, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 58462, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 16:47, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 58737, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 16:48, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 58798, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 17:07, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 59041, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 17:22, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60102, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 17:51, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60418, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 17:51, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60436, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 17:52, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60482, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Update, 19.03.2016 17:57, SYSTEM, RECHENSCHLAMPE, Scheduler, Malware Database, 2016.3.19.3, 2016.3.19.4,
Protection, 19.03.2016 17:57, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Starting,
Protection, 19.03.2016 17:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopping,
Protection, 19.03.2016 17:57, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Stopped,
Protection, 19.03.2016 17:58, SYSTEM, RECHENSCHLAMPE, Protection, Refresh, Success,
Protection, 19.03.2016 17:58, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Starting,
Protection, 19.03.2016 17:58, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Started,
Detection, 19.03.2016 18:00, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60603, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 18:00, SYSTEM, RECHENSCHLAME, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60603, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 18:00, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60604, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 18:00, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60614, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 19.03.2016 18:00, SYSTEM, RECHENSCHLAMPE, Protection, Malicious Website Protection, Domain, 82.163.143.92, m55.dnsqa.me, 60622, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
(end) was ADW angeht, so konnte ich kein loggfile von gestern aufrufen. Hängt vieleicht damit zusammen, dass mir aufgrund der popup und reimage probleme gestern abend es nicht møglich war irgendwelche Seiten zu øffnen, geschweige denn irgendwelche tools runterzuladen. deswegen hab ich ADW über einen zweiten laptop runtergeladen und auf disc gebrannt und von der disc gestartet. Als ich ADW eben geøffnet habe, war kein loggfile augeführt. Deswegen hab ich einen neuscan gemacht, der aber so wie es aussieht ergebnislos war
AdwCleaner Logfile: Code:
# AdwCleaner v5.102 - Logfile created 19/03/2016 at 18:08:00
# Updated 13/03/2016 by Xplode
# Database : 2016-03-19.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Hein - RECHENSCHLAMPE
# Running from : D:\AdwCleaner_5.102.exe
# Option : Scan
# Support : hxxp://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLL ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
*************************
C:\Program Files (x86)\AdwCleaner\AdwCleaner[C1].txt - [4038 bytes] - [18/03/2016 17:57:12]
C:\Program Files (x86)\AdwCleaner\AdwCleaner[C2].txt - [1273 bytes] - [18/03/2016 18:50:21]
C:\Program Files (x86)\AdwCleaner\AdwCleaner[S1].txt - [4136 bytes] - [18/03/2016 17:55:01]
C:\Program Files (x86)\AdwCleaner\AdwCleaner[S2].txt - [1101 bytes] - [18/03/2016 18:48:56]
C:\Program Files (x86)\AdwCleaner\AdwCleaner[S3].txt - [951 bytes] - [19/03/2016 18:08:00]
########## EOF - C:\Program Files (x86)\AdwCleaner\AdwCleaner[S3].txt - [1043 bytes] ########## --- --- ---
jetzt funktioniert der laptop zumindestens wieder so weit, das ich seiten øffnen und sachen downloaden kann, aber ich bekomme halt ständig wie schon gestern geschrieben die warnfenster vom MBAM.
Werde mich jetzt an FRST TDSS machen und das dann hier gleich posten.
Vielen Dank schon mal für Eure Hilfe!
die loggfiles von FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Hein (administrator) on RECHENSCHLAMPE (19-03-2016 18:26:44)
Running from C:\Users\Hein\Desktop
Loaded Profiles: Hein (Available Profiles: Hein & Administrator)
Platform: Windows 8.1 (X64) Language: Norsk, bokmål (Norge)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\avfaudiosw.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Synaptics Incorporated) C:\Windows\System32\valWbioSyncSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics Incorporated\SynFP\Shared\SensorDBSynch.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\QuickControl\QuickControl.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
() C:\Program Files (x86)\Lenovo\OneLink Dock\onelinkpromgn.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Peer Connect\LenovoDiscoverySvc.exe
() C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
() C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LenovoOptMouseUpdate] => C:\Program Files\Lenovo\HOTKEY\extapsup.exe [255480 2013-06-20] (Lenovo Group Limited)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [TpShocks] => C:\WINDOWS\system32\TpShocks.exe [384344 2014-02-18] (Lenovo.)
HKLM\...\Run: [LnvMobHotspotClient] => C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [938032 2014-03-06] (Lenovo)
HKLM\...\Run: [LMCSSTART1] => C:\WINDOWS\SysWOW64\lmcfrundll.exe C:\Program Files\Lenovo\Communications Utility\libmcsrdllb.dll,InitSubsystemProcesses
HKLM\...\Run: [LMCSSTART2] => C:\WINDOWS\SysWOW64\lmcfrundll.exe C:\Program Files\Lenovo\Communications Utility\libstartstub2.dll,ProxyStart
HKLM\...\Run: [LMCSSTART3] => C:\WINDOWS\SysWOW64\lmcfrundll.exe C:\Program Files\Lenovo\Communications Utility\libmcsrdllb.dll,SetupCamplusDrop
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-11-12] (IvoSoft)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-09-16] (Intel Corporation)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [552960 2013-05-14] (Vimicro)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-03-18]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ThinkPad OneLink Dock Management.lnk [2014-12-20]
ShortcutTarget: ThinkPad OneLink Dock Management.lnk -> C:\Program Files (x86)\Lenovo\OneLink Dock\onelinkpromgn.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{013EA3FE-019E-4995-B068-4399A10F735A}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{013EA3FE-019E-4995-B068-4399A10F735A}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{2F0BE758-366B-4C4D-83DD-22E4910B970E}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{2F0BE758-366B-4C4D-83DD-22E4910B970E}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{475A88DF-E6F3-43DC-A187-E822B6F2884F}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{822EC8C9-51FF-4F99-9A55-6DB6B298CE91}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{DA56E7A7-3C80-4F6B-841E-41C7392344DB}: [DhcpNameServer] 82.163.143.171
Internet Explorer:
==================
HKU\S-1-5-21-331516496-3851143654-2456111117-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-331516496-3851143654-2456111117-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13-comm.msn.com/?pc=LNJB
HKU\S-1-5-21-331516496-3851143654-2456111117-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://home.lenovo.com
HKU\S-1-5-21-331516496-3851143654-2456111117-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://home.lenovo.com
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-331516496-3851143654-2456111117-1001 -> DefaultScope {E62BFBAE-43EE-4CF5-BD6E-423F055F1485} URL =
SearchScopes: HKU\S-1-5-21-331516496-3851143654-2456111117-1001 -> {E62BFBAE-43EE-4CF5-BD6E-423F055F1485} URL =
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-11-12] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-11-12] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-11-12] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-11-12] (IvoSoft)
FireFox:
========
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-02-26] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Präsentationen) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-30]
CHR Extension: (Google Docs) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-30]
CHR Extension: (Google Drive) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-30]
CHR Extension: (YouTube) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-30]
CHR Extension: (Adblock Plus) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-18]
CHR Extension: (Google-Suche) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-30]
CHR Extension: (Google Tabellen) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-30]
CHR Extension: (Google Docs Offline) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-30]
CHR Extension: (Google Mail) - C:\Users\Hein\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-30]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [560584 2015-01-21] (Lenovo Corporation)
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [9954096 2014-04-01] (DisplayLink Corp.)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S3 intelsba; C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [54976 2013-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2016472 2015-01-23] (Lenovo Group Limited)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
S3 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [626120 2015-01-21] (Lenovo Corporation)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [115184 2014-07-09] (Lenovo Group Limited)
R2 lnvDiscoveryWinSvc; C:\Program Files\Lenovo\Lenovo Peer Connect\LenovoDiscoverySvc.exe [22576 2014-02-22] (Lenovo)
S3 LnvHotSpotSvc; C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [474160 2014-03-06] (Lenovo)
R2 LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [469720 2015-01-09] ()
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272864 2015-12-10] (Lenovo)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [293128 2016-02-05] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-18] ()
S2 QuickControlMasterSvc; C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe [61936 2014-06-12] (Lenovo Group Limited)
R3 QuickControlService; C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe [327152 2014-06-12] (Lenovo Group Limited)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [24560 2014-06-18] ()
R2 valWBFPolicyService; C:\Windows\System32\valWBFPolicyService.exe [47504 2014-06-13] (Synaptics Incorporated)
R2 valWbioSyncSvc; C:\windows\system32\valWbioSyncSvc.exe [32256 2014-06-25] (Synaptics Incorporated) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-18] (Intel® Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2014-03-26] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1424184 2014-04-22] (Motorola Solutions, Inc.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [192456 2014-05-30] (Intel Corporation)
R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [77456 2013-08-19] (Intel Corporation)
R3 LnvHIDHW; C:\Windows\System32\drivers\LnvHIDHW.sys [29496 2014-04-08] (Lenovo)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-03-19] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3440096 2014-04-16] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [418008 2013-06-24] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2014-04-07] (Synaptics Incorporated)
R1 SMIDriver; C:\Windows\System32\drivers\smi.sys [19760 2014-06-13] (Windows (R) Win 7 DDK provider)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [1065344 2013-09-11] (Vimicro Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-19 18:26 - 2016-03-19 18:26 - 00021081 _____ C:\Users\Hein\Desktop\FRST.txt
2016-03-19 18:26 - 2016-03-19 18:26 - 00000000 ____D C:\FRST
2016-03-19 18:25 - 2016-03-19 18:25 - 02374144 _____ (Farbar) C:\Users\Hein\Desktop\FRST64.exe
2016-03-19 12:28 - 2016-03-19 12:28 - 00000000 ____D C:\Users\Hein\AppData\Local\CEF
2016-03-18 18:00 - 2016-03-18 18:00 - 00001291 _____ C:\Users\Hein\Desktop\Revo Uninstaller.lnk
2016-03-18 18:00 - 2016-03-18 18:00 - 00000000 ____D C:\Users\Hein\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-03-18 18:00 - 2016-03-18 18:00 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2016-03-18 17:54 - 2016-03-19 18:08 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
2016-03-18 17:14 - 2016-03-18 17:15 - 00772016 _____ (Reimage®) C:\Users\Hein\Downloads\ReimageRepair.exe
2016-03-18 17:04 - 2016-03-18 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-03-18 17:04 - 2016-03-18 17:04 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-03-18 16:34 - 2016-03-18 17:04 - 00001991 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-03-18 16:34 - 2016-03-18 16:42 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-03-18 16:34 - 2016-03-18 16:42 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-18 16:34 - 2016-03-18 16:34 - 00002078 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-03-18 16:34 - 2016-03-18 16:34 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2016-03-18 16:34 - 2016-03-18 16:34 - 00000000 ____D C:\ProgramData\McAfee
2016-03-15 18:24 - 2016-03-15 18:24 - 00000000 ____D C:\Users\Hein\AppData\LocalLow\Temp
2016-03-11 09:35 - 2016-03-11 09:35 - 00000000 _____ C:\Users\Hein\Downloads\Download (1)
2016-03-11 09:35 - 2016-03-11 09:35 - 00000000 _____ C:\Users\Hein\Downloads\Download
2016-03-07 22:35 - 2016-03-18 13:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFill
2016-03-07 22:35 - 2016-03-07 22:35 - 00000000 ____D C:\Users\Hein\Documents\My PDFill
2016-03-07 22:35 - 2016-03-07 22:35 - 00000000 ____D C:\ProgramData\PlotSoft
2016-03-07 22:35 - 2016-03-07 22:35 - 00000000 ____D C:\Program Files (x86)\PlotSoft
2016-03-07 22:05 - 2016-03-07 22:05 - 00970154 _____ C:\Users\Hein\Downloads\membercard_48970.pdf
2016-03-07 22:04 - 2016-03-07 22:04 - 00016985 _____ C:\Users\Hein\Downloads\faktura41614.pdf
2016-03-03 18:34 - 2016-03-03 18:34 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2016-02-29 21:12 - 2016-03-17 21:04 - 00000000 ____D C:\Users\Hein\AppData\Local\CrashDumps
2016-02-25 21:55 - 2016-02-25 21:55 - 00115402 _____ C:\Users\Hein\Downloads\tickets_19535452.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-19 18:23 - 2015-12-25 16:56 - 00000000 ____D C:\Users\Hein\AppData\Local\ClassicShell
2016-03-19 18:04 - 2015-12-25 16:49 - 00001030 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-19 17:57 - 2015-12-26 00:49 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-19 02:43 - 2015-11-26 19:19 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-331516496-3851143654-2456111117-1001
2016-03-19 01:43 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-19 01:43 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-19 01:05 - 2015-12-25 16:50 - 00002220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-19 01:05 - 2015-12-25 16:50 - 00002208 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-18 18:56 - 2014-12-20 00:28 - 00449910 _____ C:\WINDOWS\system32\perfh014.dat
2016-03-18 18:56 - 2014-12-20 00:28 - 00077052 _____ C:\WINDOWS\system32\perfc014.dat
2016-03-18 18:56 - 2014-03-18 10:53 - 01377824 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-18 18:56 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2016-03-18 18:55 - 2014-12-20 00:24 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-03-18 18:52 - 2015-12-30 09:32 - 00000322 _____ C:\WINDOWS\Tasks\Start WinZip Driver Updater( SR ) for RECHENSCHLAMPE@Hein at logon.job
2016-03-18 18:52 - 2015-12-30 09:32 - 00000296 _____ C:\WINDOWS\Tasks\Start WinZip Driver Updater for RECHENSCHLAMPE@Hein(logon).job
2016-03-18 18:52 - 2015-12-25 16:49 - 00001026 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-18 18:51 - 2015-04-29 15:09 - 00000000 ___DO C:\Users\Hein\OneDrive
2016-03-18 18:51 - 2014-12-20 00:27 - 00000000 ____D C:\ProgramData\Validity
2016-03-18 18:51 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-18 18:16 - 2014-12-20 00:22 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2016-03-18 18:16 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-18 18:06 - 2015-11-26 19:25 - 00000000 ____D C:\Users\Hein\AppData\Local\Adobe
2016-03-18 16:39 - 2014-12-20 00:24 - 00000000 ____D C:\ProgramData\Adobe
2016-03-18 16:38 - 2015-11-26 19:13 - 00000000 ____D C:\Users\Hein\AppData\Roaming\Adobe
2016-03-18 16:34 - 2014-12-20 00:24 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-03-18 13:38 - 2015-11-26 19:06 - 00000000 ____D C:\Users\Hein
2016-03-18 13:37 - 2015-12-25 16:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-18 13:37 - 2015-12-25 16:56 - 00000000 ____D C:\ProgramData\ClassicShell
2016-03-18 13:37 - 2014-12-20 00:14 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2016-03-18 13:37 - 2014-12-19 08:08 - 00000000 ____D C:\ProgramData\Lenovo
2016-03-18 13:37 - 2014-04-03 19:18 - 00000000 ____D C:\Users\Administrator
2016-03-18 13:35 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\registration
2016-02-25 20:52 - 2016-01-08 07:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-02-25 19:53 - 2014-12-20 00:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-02-25 19:50 - 2014-12-20 00:04 - 00000000 ____D C:\Program Files\Lenovo
2016-02-25 19:48 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2016-02-25 19:47 - 2014-12-20 00:03 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-02-25 19:26 - 2015-11-26 19:13 - 00000000 ____D C:\Users\Hein\AppData\Local\Lenovo
==================== Files in the root of some directories =======
2014-12-20 00:07 - 2014-12-20 00:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-12-20 00:29 - 2014-12-20 00:29 - 0000107 _____ () C:\ProgramData\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}.log
2014-12-20 00:27 - 2014-12-20 00:28 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2014-12-20 00:28 - 2014-12-20 00:28 - 0000110 _____ () C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log
2014-12-20 00:28 - 2014-12-20 00:29 - 0000115 _____ () C:\ProgramData\{D6E853EC-8960-4D44-AF03-7361BB93227C}.log
Some files in TEMP:
====================
C:\Users\Hein\AppData\Local\Temp\LenovoExperienceImprovement.exe
C:\Users\Hein\AppData\Local\Temp\octB126.tmp.exe
C:\Users\Hein\AppData\Local\Temp\octE37B.tmp.exe
C:\Users\Hein\AppData\Local\Temp\tu17p84.exe
Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\dlumd10.dll
C:\Windows\SysWOW64\dlumd11.dll
C:\Windows\SysWOW64\dlumd9.dll
C:\Windows\System32\dlumd10.dll
C:\Windows\System32\dlumd11.dll
C:\Windows\System32\dlumd9.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-17 06:10
==================== End of FRST.txt ============================ --- --- ---
--- --- ---
[CODE]Additional
FRST Logfile:
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Hein (2016-03-19 18:27:12)
Running from C:\Users\Hein\Desktop
Windows 8.1 (X64) (2015-11-26 18:07:41)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-331516496-3851143654-2456111117-500 - Administrator - Disabled) => C:\Users\Administrator
Gjest (S-1-5-21-331516496-3851143654-2456111117-501 - Limited - Disabled)
Hein (S-1-5-21-331516496-3851143654-2456111117-1001 - Administrator - Enabled) => C:\Users\Hein
HomeGroupUser$ (S-1-5-21-331516496-3851143654-2456111117-1003 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC - Norsk (HKLM-x32\...\{AC76BA86-7AD7-1044-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Classic Shell (HKLM\...\{D4B3454F-7529-4F5F-851D-2C36933F7D64}) (Version: 4.2.5 - IvoSoft)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.17.50 - Conexant)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.3604 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.3604 - CyberLink Corp.) Hidden
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Dependency Package Update (Version: 1.6.26.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.38.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (x32 Version: 1.6.38.00 - Lenovo Group Limited) Hidden
DisplayLink Core Software (HKLM\...\{58F4C39B-D946-4A45-A314-DEFC2AFDF397}) (Version: 7.5.54609.0 - DisplayLink Corp.)
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Integrated Camera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 5.13.911.3 - Vimicro)
Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: 1.0.0.1014 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3379 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1419.2) (HKLM\...\{302600C1-6BDF-4FD1-1405-148929CC1385}) (Version: 17.0.1405.0464 - Intel Corporation)
Intel(R) Update Manager (x32 Version: 1.0.0.36888 - Intel Corporation) Hidden
Intel® PROSet/Wireless Software (HKLM-x32\...\{75895d95-3e4b-42b6-8440-97a0e234aeb3}) (Version: 17.0.2 - Intel Corporation)
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.12 - )
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.38.00 - Lenovo Group Limited)
Lenovo HID HW Radio Driver 1.0.0.58 (HKLM\...\{E5325F32-D15A-4131-B029-4A5B7609E532}_is1) (Version: 1.0.0.58 - Lenovo)
Lenovo Multimedia and Communications Core Runtime (HKLM\...\{033DC0E0-DA89-4C33-B66C-89B64D312CD1}_is1) (Version: 5.0.13.94 - Lenovo Corporation)
Lenovo Patch Utility (x32 Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Patch Utility 64 bit (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Peer Connect SDK (HKLM\...\{75C87855-9CBB-4892-B1A9-74C73A19CACA}_is1) (Version: 1.0.0.7 - Lenovo)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.05 - )
Lenovo QuickControl (HKLM-x32\...\{4855C42F-5197-4AAD-A50D-5066D2CC4647}) (Version: 2.20 - Lenovo Group Limited)
Lenovo Settings - Camera Audio (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 4.3.19.209 - Lenovo Corporation)
Lenovo Settings - Location Awareness (HKLM-x32\...\{C79D4402-E622-4922-9C02-89F9080BF081}_is1) (Version: 1.4.0.5 - Lenovo Group Limited)
Lenovo Settings - Power (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}) (Version: 7.49.4 - Lenovo Group Limited)
Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 2.3.3.33 - Lenovo Group Limited)
Lenovo Settings Mobile Hotspot (HKLM\...\{42603F7D-B08D-436B-B0D8-3E2DEF1AFD41}_is1) (Version: 2.3.0.84 - Lenovo)
Lenovo Settings Service (HKLM\...\{8C6F1EBA-17F1-4481-B688-9777E63E985F}_is1) (Version: 2.3.3.7 - Lenovo Group Limited)
Lenovo Settings UMDF driver (HKLM\...\{2BDC7413-65EA-4B99-8C4B-02F11075BE6D}_is1) (Version: 1.2.0.7 - Lenovo Group Limited)
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.4.0 - Lenovo Group Limited)
Lenovo Solution Center (HKLM\...\{4386A5EF-BD23-49F4-9DAD-CD76B4F6A8BF}) (Version: 2.8.006.00 - Lenovo Group Limited)
Lenovo Solutions for Small Business (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 2.2.42.8185 - Intel(R) Corporation)
Lenovo Solutions for Small Business Customizations (HKLM-x32\...\{AFD7B869-3B70-40C7-8983-769256BA3BD2}) (Version: 2.2.0003.00 - Lenovo Group Limited)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.06.0016 - Lenovo)
Lenovo USB Graphics (HKLM\...\{E6B1FE9A-CB1E-4096-A0AF-163419CB971C}) (Version: 7.5.54614.0 - Lenovo)
Lenovo USB3.0 to DVI VGA Monitor Adapter (HKLM-x32\...\{454D32AD-C149-49BE-9F2E-8C089C3D6620}) (Version: 1.07.17 - Lenovo)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
Malwarebytes Anti-Malware versjon 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.292.3 - McAfee, Inc.)
Metric Collection SDK (x32 Version: 1.1.0005.00 - Lenovo Group Limited) Hidden
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.5.0 - Mozilla)
Mozilla Thunderbird 38.6.0 (x86 nb-NO) (HKLM-x32\...\Mozilla Thunderbird 38.6.0 (x86 nb-NO)) (Version: 38.6.0 - Mozilla)
On Screen Display (HKLM\...\OnScreenDisplay) (Version: 8.33.00 - )
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
PowerDVD Create (HKLM-x32\...\InstallShield_{DE485075-8CD3-4A1E-9ABC-6412EBA44872}) (Version: 10.0 - CyberLink Corp.)
PowerDVD Create 10 (x32 Version: 10.0.1.2704 - CyberLink Corp.) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.21234 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Synaptics WBF DDK 5011 (HKLM\...\{491728AE-BFF0-44F2-A9F1-9AE218E36E2D}) (Version: 4.5.263.0 - Synaptics)
Synaptics WBF DDK 5011 (HKLM\...\{4D70781C-36A9-4335-9568-565C6F61B5EB}) (Version: 4.5.263.0 - )
ThinkPad OneLink Dock (HKLM-x32\...\{8E1CACF5-2493-4950-9AD5-189903FE57E7}) (Version: 1.08.25 - Lenovo)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 18.0.7.40 - Synaptics Incorporated)
Thinkpad USB 3.0 Ethernet Adapter Driver (HKLM-x32\...\{D8102684-7BA1-4948-88B9-535F84E6E588}) (Version: 8.8.911.2013 - Lenovo)
ThinkVantage Active Protection System (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.79.00.03 - Lenovo)
WaveEditor (x32 Version: 1.0.1.4514 - CyberLink Corp.) Hidden
Windows Driver Package - Intel Corporation (iaStorA) HDC (08/01/2013 12.8.0.1016) (HKLM\...\C8A921233C0C441A4E4EAABC2AB08C872FD77A6E) (Version: 08/01/2013 12.8.0.1016 - Intel Corporation)
Windows Driver Package - Lenovo 1.67.04.05 (12/17/2013 1.67.04.05) (HKLM\...\68ECF461D6E85BB67AFC110D2FEBF1955C9F26B5) (Version: 12/17/2013 1.67.04.05 - Lenovo)
WinZip Driver Updater (HKLM\...\WinZip Driver Updater) (Version: 5.3.2.54 - VAPC (Lux) S.a.r.L)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0E27045A-699B-48F5-A9AE-FE2565F1FFCB} - System32\Tasks\Lenovo\Lenovo Settings Power => Rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
Task: {1A007918-0FAD-420F-9A27-6809D63F5A1E} - System32\Tasks\TVT\LenovoWERMonitor => C:\Program Files (x86)\Common Files\lenovo\SUP\sup_wermonitor.exe [2014-05-27] (Lenovo)
Task: {258786F3-6780-4510-84F4-F4DC0C1225CA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-25] (Google Inc.)
Task: {31841FC0-9CDB-44F0-9F5F-448017D45E05} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-12-14] ()
Task: {42C14980-900E-4EFA-BAAE-A86F8409251D} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {49101344-6C76-46D5-A5F2-776A4831F494} - System32\Tasks\Diner Browser => Rundll32.exe "C:\Users\Hein\AppData\Local\Diner Browser\{7420D55C-28E9-72F7-ABB0-767FACF2478B}\DinerBrowser.dll",#1 <==== ATTENTION
Task: {501FE315-3E58-4A4A-988F-85F98192C12A} - System32\Tasks\Start WinZip Driver Updater Update => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
Task: {513819BA-6109-4CF9-B53B-81A9330851A2} - System32\Tasks\Diner Browser2 => Rundll32.exe "C:\Users\Hein\AppData\Local\Diner Browser\{7420D55C-28E9-72F7-ABB0-767FACF2478B}\vqelekf.dll",#1 <==== ATTENTION
Task: {52340366-8AB4-4507-98B5-C83E40EB0036} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-25] (Google Inc.)
Task: {56AF9621-5123-45F2-852D-62BF905F958A} - System32\Tasks\Start WinZip Driver Updater( SR ) for RECHENSCHLAMPE@Hein => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
Task: {60BEB501-9AD5-45CF-A44B-DFFD735C1704} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2015-12-10] (Lenovo)
Task: {62B8B0BC-78EF-4257-84F6-24819EE57AE0} - System32\Tasks\CLMLSvc => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2013-03-07] (CyberLink)
Task: {6F01A077-D156-493B-92CA-82C3EE8D6A55} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-04-07] (Synaptics Incorporated)
Task: {7A2EAC43-1D01-458A-B3AE-9DF7389FEB31} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2015-12-10] (Lenovo)
Task: {85944945-8F16-4432-9CD4-77F84C066944} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {922C9785-042D-4A1C-B98E-A4FFDFA0B32E} - System32\Tasks\Start WinZip Driver Updater Schedule => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
Task: {A42755FE-7E6E-44B0-9546-B19C5B0F91AB} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2015-12-10] (Lenovo)
Task: {AE685F9E-9C02-4D89-97B8-A376389BFF53} - System32\Tasks\StartPowerDVDService => C:\PROGRAM FILES (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe [2013-06-29] (CyberLink Corp.)
Task: {B36A6187-A80F-4959-A41B-FD222C61CB8A} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2015-12-10] (Lenovo)
Task: {C0F659EF-7BCF-4649-975C-432E4FA4CF4D} - System32\Tasks\Start WinZip Driver Updater( SR ) for RECHENSCHLAMPE@Hein at logon => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
Task: {D722B938-2AA9-403D-B597-F224DC56F6DA} - System32\Tasks\Start WinZip Driver Updater for RECHENSCHLAMPE@Hein(logon) => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
Task: {ED246180-ED51-4764-80A2-FD6F062EF138} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2015-12-10] (Lenovo)
Task: {F9514689-9757-4AA4-90F4-CB90AB92EEB4} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2014-06-18] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Start WinZip Driver Updater for RECHENSCHLAMPE@Hein(logon).job => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe
Task: C:\WINDOWS\Tasks\Start WinZip Driver Updater( SR ) for RECHENSCHLAMPE@Hein at logon.job => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe-runExecutable SRTray.exe
Task: C:\WINDOWS\Tasks\Start WinZip Driver Updater( SR ) for RECHENSCHLAMPE@Hein.job => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe-runExecutable SRTray.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-12-20 00:33 - 2015-01-16 07:49 - 00105472 ____N () C:\Program Files (x86)\ThinkPad\Utilities\NO\PWMRT64V.dll
2014-12-20 00:26 - 2012-04-24 11:43 - 00390632 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-12-20 00:07 - 2010-10-26 05:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-02-18 03:38 - 2014-02-18 03:38 - 00246104 _____ () C:\Program Files\ThinkPad\TpShocks\MUI\0414\TpShocks.dll
2014-12-20 00:03 - 2013-10-29 01:48 - 00915968 _____ () C:\Program Files (x86)\Lenovo\OneLink Dock\onelinkpromgn.exe
2014-12-20 00:33 - 2015-01-16 07:49 - 00105472 ____N () C:\Program Files (x86)\ThinkPad\Utilities\NO\PWMRT64V.DLL
2014-12-20 00:33 - 2015-01-09 15:40 - 00469720 _____ () C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
2014-12-20 00:33 - 2015-01-09 15:40 - 00013528 _____ () C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
2016-01-29 19:42 - 2016-01-29 19:42 - 00797696 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Networking\e1a2f3f274995f1f847c00f962657943\Windows.Networking.ni.dll
2015-12-25 15:07 - 2015-12-25 15:07 - 01282048 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Devices\bf5509cf3a0d2e3afbd0c33e9153ecbd\Windows.Devices.ni.dll
2016-01-31 05:34 - 2016-01-31 05:34 - 00228864 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Foundation\f7e726805e56676bd7b8662a3d842b0e\Windows.Foundation.ni.dll
2013-03-07 06:49 - 2013-03-07 06:49 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2013-03-07 06:52 - 2013-03-07 06:52 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-12-20 00:01 - 2013-09-16 04:19 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-02-20 12:05 - 2016-02-18 05:14 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll
2016-02-20 12:05 - 2016-02-18 05:14 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll
2016-01-08 07:44 - 2016-02-25 20:51 - 00153032 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2016-01-08 07:44 - 2016-02-25 20:51 - 00022472 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2016-02-20 12:05 - 2016-02-18 05:15 - 16808600 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Hein\Downloads\Classic Shell - CHIP-Installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Hein\Downloads\FreeCAD - CHIP-Installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Hein\Downloads\Microsoft Rechner Plus - CHIP-Installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Hein\Downloads\OpenOffice - CHIP-Installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Hein\Downloads\Setup.X86.nb-NO_HomeStudentRetail_18f91a2b-0c0f-4b6e-b2b2-db75bb097d82_TX_DB_.exe:BDU [0]
AlternateDataStreams: C:\Users\Hein\Downloads\Support-LogMeInRescue (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Hein\Downloads\Support-LogMeInRescue.exe:BDU [0]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2016-03-18 17:04 - 00000854 ____A C:\WINDOWS\system32\Drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-331516496-3851143654-2456111117-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Hein\Desktop\Pictures\Pictures\bilder für email\10350632_10152164393638002_5661559173947843649_n.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{53150976-E673-43CD-96E1-8EAED71603DB}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{1A71CB6B-B0CD-4EB6-A482-CDE9BEFF72FB}] => (Allow) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe
FirewallRules: [{F5817868-B22F-45D0-BA41-2753D601F50E}] => (Allow) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe
FirewallRules: [{42175962-ED99-4625-93A7-9E0ABA3F0612}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
FirewallRules: [{06D2607C-A9FA-401E-8EFE-D689547E5C2C}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
FirewallRules: [{1316B1EA-4B06-41E5-8D3E-39C8F18EB6D3}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D9C34587-731C-4E37-9789-C4DAD83C8557}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{3609141A-55E3-4FEB-9ABA-3664D5910F6D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{C0CBF5E6-D70F-4351-86B5-9F3CFF0262B0}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{7BFEA752-06F5-4F90-9FDD-5C5DDE9CFE4A}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{30320B62-554D-4CAE-BB91-B64B9C096E7B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{6F90D5DD-098E-4A47-9A7E-7A1134B76698}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{9FA48342-C48C-4042-BC2D-8006A6F8E7D5}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{BF11FF53-1ABF-4EB1-BC0F-F5D7527BEBF9}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{08B22EA0-8B70-40B2-8D8D-60CFDA0EB406}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
07-03-2016 08:26:40 Planlagt kontrollpunkt
18-03-2016 13:34:43 Gjenopprettingsoperasjon
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/18/2016 04:41:43 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description:
Error: (03/18/2016 04:30:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RECHENSCHLAMPE)
Description: Aktiveringen av appen Microsoft.Reader_8wekyb3d8bbwe!Microsoft.Reader mislyktes med feilen: -2147009284 Se loggen for Microsoft-Windows-TWinUI/Operational hvis du vil ha mer informasjon.
Error: (03/18/2016 04:29:23 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RECHENSCHLAMPE)
Description: Aktiveringen av appen Microsoft.Reader_8wekyb3d8bbwe!Microsoft.Reader mislyktes med feilen: -2147009284 Se loggen for Microsoft-Windows-TWinUI/Operational hvis du vil ha mer informasjon.
Error: (03/18/2016 04:28:55 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1652) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\WINDOWS\system32\SRU\SRU000B0.log.
Error: (03/17/2016 08:44:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Programnavn med feil: chrome.exe, versjon: 48.0.2564.116, tidsangivelse: 0x56c52f1d
Modulnavn med feil: chrome.dll, versjon: 48.0.2564.116, tidsangivelse: 0x56c52969
Unntakskode: 0x80000003
Feilforskyvning: 0x00548ec4
Feil prosess-ID: 0x4d0
Feil starttid for program: 0xchrome.exe0
Feil programbane: chrome.exe1
Feil modulbane: chrome.exe2
Rapport-ID: chrome.exe3
Fullstendig navn på feilpakke: chrome.exe4
Relativ program-ID for feilpakke: chrome.exe5
Error: (03/17/2016 08:04:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programmet LiveComm.exe versjon 17.5.9600.20911 sluttet å samhandle med Windows og ble lukket. Hvis du vil se om det finnes mer informasjon tilgjengelig om problemet, åpner du problemloggen i kontrollpanelet for Handlingssenter.
Prosess-ID: 1950
Starttidspunkt: 01d1807fb592649f
Avslutningstidspunkt: 4294967295
Programbane: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe
Rapport-ID: 03af8b7b-ec73-11e5-8272-801934d39d0b
Fullstendig navn på feilpakke: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe
Relativ program-ID for feilpakke: ppleae38af2e007f4358a809ac99a64a67c1
Error: (03/15/2016 08:11:58 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Volumet WINRE_DRV ble ikke optimalisert fordi det oppstod en feil: Feil parameter. (0x80070057)
Error: (03/09/2016 08:00:42 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Volumet WINRE_DRV ble ikke optimalisert fordi det oppstod en feil: Feil parameter. (0x80070057)
Error: (03/07/2016 08:17:04 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Volumet WINRE_DRV ble ikke optimalisert fordi det oppstod en feil: Feil parameter. (0x80070057)
Error: (03/07/2016 06:37:26 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Volumet WINRE_DRV ble ikke optimalisert fordi det oppstod en feil: Feil parameter. (0x80070057)
System errors:
=============
Error: (03/18/2016 06:51:08 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-MYNDIGHET)
Description: Modulen for WLAN-utvidelse er stoppet uventet.
Modulbane: C:\WINDOWS\System32\IWMSSvc.dll
Error: (03/18/2016 06:51:08 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-MYNDIGHET)
Description: Modulen for WLAN-utvidelse er stoppet uventet.
Modulbane: C:\WINDOWS\System32\IWMSSvc.dll
Error: (03/18/2016 06:51:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten Lenovo PM Service avsluttet uventet. Det har den gjort 1 gang(er).
Error: (03/18/2016 06:51:03 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-MYNDIGHET)
Description: Modulen for WLAN-utvidelse er stoppet uventet.
Modulbane: C:\WINDOWS\System32\IWMSSvc.dll
Error: (03/18/2016 06:50:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten Lenovo Settings Power Service avsluttet uventet. Det har den gjort 1 gang(er).
Error: (03/18/2016 06:50:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten LocationTaskManager avsluttet uventet. Det har den gjort 1 gang(er).
Error: (03/18/2016 06:50:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten lnvDiscoveryWinSvc avsluttet uventet. Det har den gjort 1 gang(er).
Error: (03/18/2016 06:50:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten Intel(R) Dynamic Application Loader Host Interface Service avsluttet uventet. Det har den gjort 1 gang(er).
Error: (03/18/2016 06:50:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten Lenovo Hotkey Client Loader avsluttet uventet. Det har den gjort 1 gang(er).
Error: (03/18/2016 06:50:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Tjenesten Cyberlink RichVideo64 Service(CRVS) avsluttet uventet. Det har den gjort 1 gang(er).
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-4100M CPU @ 2.50GHz
Percentage of memory in use: 66%
Total physical RAM: 3986.58 MB
Available physical RAM: 1317.82 MB
Total Virtual: 6290.58 MB
Available Virtual: 2791.83 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:97.94 GB) (Free:41.2 GB) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 7BA096CD)
Partition: GPT.
==================== End of Addition.txt ============================ --- --- ---
--- --- --- |