[B][color=#0000FF]
start
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [amttgm] => rundll32.exe "C:\Users\Laurens\AppData\Local\amttgm.dll",amttgm <===== AANDACHT
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [EMU5OXGGMW] => "C:\Program Files\PYZR20D82S\PYZR20D82.exe"
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [D3O3BHEPME] => "C:\Users\Laurens\AppData\Local\Temp\2OWGKYFD52.exe" <===== AANDACHT
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [GBRYECYXKH] => "C:\Program Files\86D24A6AMP\86D24A6AM.exe"
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [LS1VTWXGSV] => "C:\Program Files (x86)\DPower\CLECARAJ9J.exe" <===== AANDACHT
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [NPFHKOI0V8] => "C:\Program Files\C9WKJ7NLAI\C9WKJ7NLA.exe"
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [YDT60WIQCB] => "C:\Program Files\AB90HR2BZT\AB90HR2BZ.exe"
C:\Users\Laurens\AppData\Local\amttgm.dll
C:\Program Files\PYZR20D82S\PYZR20D82.exe
C:\Users\Laurens\AppData\Local\Temp\2OWGKYFD52.exe
C:\Program Files\86D24A6AMP
C:\Program Files (x86)\DPower
C:\Program Files\C9WKJ7NLAI
C:\Program Files\AB90HR2BZT
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [VLEMTA4X1U] => "C:\Program Files\10K1LK8BS4\10K1LK8BS.exe"
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [2P28TE0HVA] => "C:\Program Files\7JCCY950IP\7JCCY950I.exe"
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\Run: [GSQ5QDO16E] => "C:\Users\Laurens\AppData\Local\Temp\GLERAQIXR6.exe" <===== AANDACHT
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\MountPoints2: {144c3eac-1d7e-11e6-998e-0015833d0a57} - "F:\setup.exe"
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\MountPoints2: {492ac149-4909-11e2-aa97-dc85de088292} - G:\Setup.exe
HKU\S-1-5-21-4090984413-3736412349-222151437-1000\...\MountPoints2: {5c70e5c2-3869-11e6-a7a3-dc85de088292} - F:\Startme.exe
ShellExecuteHooks: Geen Naam - {77C40B00-DE3D-11E6-A6A5-64006A5CFC23} - C:\Users\Laurens\AppData\Roaming\Ponophulatain\Reernesplocily.dll -> Geen bestand
ProxyEnable: [.DEFAULT] => Proxy is ingeschakeld.
ProxyServer: [.DEFAULT] => http=127.0.0.1:52527;https=127.0.0.1:52527
Winsock: Catalog9-x64 01 C:\Windows\system32\zdengine64.dll Geen bestand
Winsock: Catalog9-x64 02 C:\Windows\system32\zdengine64.dll Geen bestand
Winsock: Catalog9-x64 03 C:\Windows\system32\zdengine64.dll Geen bestand
Winsock: Catalog9-x64 04 C:\Windows\system32\zdengine64.dll Geen bestand
Winsock: Catalog9-x64 16 C:\Windows\system32\zdengine64.dll Geen bestand
FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-13] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-13] (Oracle Corporation)
CHR HKLM-x32\...\Chrome\Extension: [cfclhhllineonleiepjgghajakndbhcp] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1431\ch\MediaViewerV1alpha1431.crx <niet gevonden>
CHR HKLM-x32\...\Chrome\Extension: [idnijejmfnihcodhholpepafheamcbnn] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3654\ch\MediaViewV1alpha3654.crx <niet gevonden>
CHR HKLM-x32\...\Chrome\Extension: [jjgfnhbjhabihfaceanpoefmjakocpdf] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha488\ch\WebexpEnhancedV1alpha488.crx <niet gevonden>
CHR HKLM-x32\...\Chrome\Extension: [lmoikiehbkipeldbdcelljicenmeflfa] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha5308\ch\MediaViewV1alpha5308.crx <niet gevonden>
CHR HKLM-x32\...\Chrome\Extension: [oelcddbiapokjdknhmhndjfmhkppemlg] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta198\ch\VideoPlayerV3beta198.crx <niet gevonden>
CHR HKLM-x32\...\Chrome\Extension: [okjlcfaamohlinobingnfkhbmobialpm] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home2034\ch\MediaWatchV1home2034.crx <niet gevonden>
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
C:\Program Files (x86)\GTFAVENUE Updater
C:\Program Files\Common Files\Noobzo
C:\Users\Laurens\AppData\Local\Temp\WS
C:\Windows\system32\drivers\EagleX64.sys
C:\Program Files (x86)\GUMCD8C.tmp
C:\Program Files (x86)\GUTCDAC.tmp
C:\Users\Laurens\AppData\Local\BrowserAir
C:\Windows\System32\Tasks\{72334C87-DDB8-467B-9EB7-8159D3582F97}
C:\Windows\System32\Tasks\{65710494-353D-479A-AE12-AE6C6F61D9FF}
C:\Windows\System32\Tasks\{033E54F4-4619-41F5-B2C2-F8DACBF5E8BA}
C:\Users\Laurens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
C:\Windows\System32\Tasks\Stoboght System
C:\Windows\System32\Tasks\Traffic Exchange Guardian
C:\Windows\System32\Tasks\Traffic Exchange Guard
C:\Windows\System32\Tasks\Traffic Exchange
C:\Windows\System32\Tasks\Traffic Exchange Debug
C:\Windows\System32\Tasks\Traffic Exchange Updater
C:\Windows\System32\Tasks\Traffic Exchange v2 Guardian
C:\Windows\System32\Tasks\Traffic Exchange v2 Guard
C:\Windows\System32\Tasks\Traffic Exchange v2
C:\Windows\Tasks\Traffic Exchange Updater.job
C:\Windows\Tasks\Traffic Exchange v2.job
C:\Windows\Tasks\Traffic Exchange v2 Guardian.job
C:\Windows\Tasks\Traffic Exchange v2 Guard.job
C:\ProgramData\Avira
C:\ProgramData\Avg
C:\ProgramData\AVAST Software
C:\Windows\SysWOW64\zdengineOff.ini
C:\Windows\system32\zdengineOff.ini
C:\Users\Default\AppData\Local\AdvinstAnalytics
C:\Users\Default User\AppData\Local\AdvinstAnalytics
C:\Windows\System32\Tasks\GTFAVENUE
Task: {3D1D6BB3-6ABD-4855-96EB-0575213A9426} - System32\Tasks\SMW_P => C:\ProgramData\smp2.exe <==== AANDACHT
C:\ProgramData\smp2.exe
Task: {3E63FC14-6BFB-4A8E-A656-7E8FC167977A} - System32\Tasks\Traffic Exchange v2 Guardian => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.exe <==== AANDACHT
Task: {46582820-3B4A-4BAA-B682-BF05EA5B7504} - System32\Tasks\Traffic Exchange Guardian => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe <==== AANDACHT
Task: {4B501039-368D-4DFE-BEA6-5CF32D149FDB} - System32\Tasks\DistromaticSearchProtect-hourly => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-04-13] (Distromatic) <==== AANDACHT
C:\Program Files (x86)\Microleaves
C:\Program Files (x86)\Amazon Browser Settings
Task: {62B16A08-2D40-40FC-BAED-D8FCC91AA42B} - System32\Tasks\snf => C:\ProgramData\Zaamla\Zaamla.exe <==== AANDACHT
C:\ProgramData\Zaamla
Task: {9D62975E-7DF0-4FC6-8D51-EF7585809095} - System32\Tasks\{9018B07B-8A58-4E5F-B220-D128FBDCBA7E} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {9E00C75A-E174-44E1-8C17-1E7B5C0FB609} - System32\Tasks\schedule!3036567561 => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe <==== AANDACHT
C:\ProgramData\BetterSoft
Task: {A19A465E-3EB0-47E0-9197-C00A60058FD8} - System32\Tasks\updengine => C:\Program Files (x86)\OtherSearch\updengine.exe <==== AANDACHT
Task: {A3D40B0E-780E-46A0-8A11-599FB56345C6} - System32\Tasks\DistromaticUpdater-periodic => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-04-13] (Distromatic) <==== AANDACHT
C:\Program Files (x86)\OtherSearch
C:\Program Files (x86)\Amazon Browser Settings
Task: {AD96B9EC-B151-4566-A0DA-C80D8871D54E} - System32\Tasks\SMW_UpdateTask_Time_333035383839363639332d505b2d34454137455a5a786c => Wscript.exe //B "C:\ProgramData\SearchModule\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== AANDACHT
C:\ProgramData\SearchModule
Task: {B70A0AC4-ACF6-405F-9516-1293C527710C} - System32\Tasks\Traffic Exchange Guard => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe <==== AANDACHT
Task: {B79E31CD-074A-4A3A-A7EB-888C0752DA57} - System32\Tasks\Traffic Exchange Debug => C:\Program Files (x86)\Microleaves\Traffic Exchange\nc.exe <==== AANDACHT
Task: {B9405429-B63B-4E1E-B463-C39F8135F93D} - System32\Tasks\SecureUpdater => C:\Program Files (x86)\UCBrowser\Security\uclauncher.exe <==== AANDACHT
Task: {C1D4D6B7-B848-40EA-9111-14F619FBA63E} - System32\Tasks\Traffic Exchange => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe <==== AANDACHT
Task: {CFD9978E-6EFF-4E43-AC44-0EB463C7D9D1} - System32\Tasks\DistromaticUpdater-logon => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-04-13] (Distromatic) <==== AANDACHT
Task: {D0461C38-CB15-415B-8ABE-BFB021CF723F} - System32\Tasks\DistromaticSearchProtect-logon => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-04-13] (Distromatic) <==== AANDACHT
Task: {D6A3728F-D23E-4CD3-A0D7-1CE5DA32699C} - System32\Tasks\Traffic Exchange v2 Guard => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.exe <==== AANDACHT
Task: {DC096143-C468-4C3F-B21E-DA233D9FD43E} - System32\Tasks\Traffic Exchange Updater => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== AANDACHT
Task: {E65280E3-55AE-4D96-8DE3-5A119F5D7430} - System32\Tasks\Traffic Exchange v2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.exe <==== AANDACHT
Task: {EF62E507-DFB4-4637-8BD9-DD9673565144} - System32\Tasks\snp => C:\ProgramData\Zaamla\Zaamla.exe <==== AANDACHT
Task: {F7656B57-09E7-4CE9-86D3-90E84DF2C8BC} - System32\Tasks\UCBrowserUpdaterCore => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== AANDACHT
c:\programdata\bettersoft\optimizerpro\3036567561.ini <==== AANDACHT
Task: C:\Windows\Tasks\Traffic Exchange Updater.job => <==== AANDACHT
Task: C:\Windows\Tasks\Traffic Exchange v2 Guard.job => <==== AANDACHT
Task: C:\Windows\Tasks\Traffic Exchange v2 Guardian.job => <==== AANDACHT
Task: C:\Windows\Tasks\Traffic Exchange v2.job => <==== AANDACHT
ShortcutWithArgument: C:\Users\Laurens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epc&s=h1ozftptn095001au,86edefa3-5600-4ff3-a7ad-8b6bba1eb8af,
ShortcutWithArgument: C:\Users\Laurens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epc&s=h1ozftptn095001au,86edefa3-5600-4ff3-a7ad-8b6bba1eb8af,
ShortcutWithArgument: C:\Users\Laurens\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epc&s=h1ozftptn095001au,86edefa3-5600-4ff3-a7ad-8b6bba1eb8af
cmd: ipconfig /flushdns
cmd: netsh winsock reset
[/COLOR][/B]