# AdwCleaner v6.030 - Logbestand aangemaakt 01/11/2016 op 17:30:02 # *Updated on 19/10/2016 by Malwarebytes # Gebruik lokale database : 2016-11-01.2 [*Server] # Besturingssysteem : Windows 10 Home (X64) # Gebruikersnaam : Ewoud - KUILMAN # Gestart vanuit : C:\Users\Ewoud\Downloads\AdwCleaner.exe # Verwijderen # Ondersteuning : hxxps://www.malwarebytes.com/support ***** [ *Services ] ***** [-] IE policies verwijderdWtuSystemSupport [-] IE policies verwijderdLavasoftTcpService [-] IE policies verwijderdSearchProtectionService [-] IE policies verwijderdUpdate service ***** [ Mappen ] ***** [-] hersteldC:\ProgramData\Avg_Update_1015av [-] hersteldC:\ProgramData\Avg_Update_1215avz [-] hersteldC:\Users\Ewoud\AppData\Local\Essentware [-] hersteldC:\Users\Ewoud\AppData\Local\Hola [-] hersteldC:\Users\Ewoud\AppData\Local\Mail.Ru [-] hersteldC:\Users\Ewoud\AppData\Local\pokki [-] hersteldC:\Users\Ewoud\AppData\Local\avg web tuneup [#] *Folder deleted on reboot: C:\Users\Ewoud\AppData\Local\Pokki [-] hersteldC:\Users\Ewoud\AppData\Roaming\Hola [-] hersteldC:\Users\Ewoud\AppData\Roaming\RHEng [-] hersteldC:\Users\Ewoud\AppData\Roaming\MailProducts [-] hersteldC:\Users\Ewoud\AppData\Roaming\lavasoft\web companion [-] hersteldC:\Program Files\Hola [-] hersteldC:\Program Files\avg web tuneup [-] hersteldC:\Program Files\Booking.com [-] hersteldC:\Program Files\Common Files\AVG Secure Search [-] hersteldC:\ProgramData\AVG Secure Search [-] hersteldC:\ProgramData\AVG Security Toolbar [-] hersteldC:\ProgramData\Essentware [-] hersteldC:\ProgramData\Mail.Ru [-] hersteldC:\ProgramData\avg web tuneup [-] hersteldC:\ProgramData\lavasoft\web companion [-] hersteldC:\ProgramData\BSD\DriverHive [#] *Folder deleted on reboot: C:\ProgramData\Application Data\AVG Secure Search [#] *Folder deleted on reboot: C:\ProgramData\Application Data\AVG Security Toolbar [#] *Folder deleted on reboot: C:\ProgramData\Application Data\Essentware [#] *Folder deleted on reboot: C:\ProgramData\Application Data\Mail.Ru [#] *Folder deleted on reboot: C:\ProgramData\Application Data\avg web tuneup [#] *Folder deleted on reboot: C:\ProgramData\Application Data\lavasoft\web companion [#] *Folder deleted on reboot: C:\ProgramData\Application Data\BSD\DriverHive [-] hersteldC:\Program Files (x86)\Mail.Ru [-] hersteldC:\Program Files (x86)\avg web tuneup [-] hersteldC:\Program Files (x86)\lavasoft\web companion [-] hersteldC:\Program Files (x86)\SPnP6 [-] hersteldC:\Program Files (x86)\Common Files\AVG Secure Search [-] hersteldC:\Users\Default User\AppData\Local\Pokki [#] *Folder deleted on reboot: C:\Users\Default\AppData\Local\Pokki [-] hersteldC:\Users\Ewoud\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj [-] hersteldC:\Users\Ewoud\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd [-] hersteldC:\Users\Ewoud\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof ***** [ Bestanden ] ***** [-] hersteldC:\Users\Ewoud\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk [-] hersteldC:\Users\Ewoud\Favorites\Mail.Ru.url [-] hersteldC:\Users\Ewoud\Favorites\Mail.Ru Агент - используй для общения!.url [#] hersteldC:\WINDOWS\SysNative\LavasoftTcpService64.dll [-] hersteldC:\WINDOWS\SysNative\LavasoftTcpServiceOff.ini [-] hersteldC:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat [#] hersteldC:\ProgramData\Application Data\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat [-] hersteldC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk [-] hersteldC:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk [-] hersteldC:\WINDOWS\SysWoW64\lavasofttcpservice.dll [-] hersteldC:\WINDOWS\SysWoW64\LavasoftTcpServiceOff.ini ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Snelkoppelingen ] ***** ***** [ Geplande taken ] ***** ***** [ Register ] ***** [-] hersteldHKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_f356775052cadffd19a420ccdfaa87ea13120bef [-] hersteldHKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu [-] hersteldHKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdMan [#] *Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdMan [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Classes\pokki [#] *Key deleted on reboot: HKCU\Software\Classes\pokki [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1 [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController [-] hersteldHKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1 [-] hersteldHKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd [-] hersteldHKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1 [-] hersteldHKLM\SOFTWARE\Classes\ScriptHelper.NativeApi [-] hersteldHKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1 [-] hersteldHKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi [-] hersteldHKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\pokki [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1 [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi [#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 [-] hersteldHKLM\SOFTWARE\Classes\AppID\{56AD7EEE-D6C0-410E-8A7B-811DEA764554} [-] hersteldHKLM\SOFTWARE\Classes\AppID\{E8EB2F1F-661E-4A7F-8F9A-77DEB757A906} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{CB31FF8F-BF80-4D2B-ADBE-12C6F5347890} [-] hersteldHKLM\SOFTWARE\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105} [-] hersteldHKLM\SOFTWARE\Classes\Interface\{7BCA6879-A9F8-47DE-AE05-F5CE7EA3A474} [-] hersteldHKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7} [-] hersteldHKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057} [-] hersteldHKLM\SOFTWARE\Classes\TypeLib\{ADF1FA2A-6EAA-4A97-A55F-3C8B92843EF5} [-] hersteldHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [-] hersteldHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [-] hersteldHKU\.DEFAULT\Software\Hola [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Essentware [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Microsoft\Tinstalls [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Reg\Clean [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Mail.Ru [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\COMMONMSG [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\AppDataLow\Software\Mail.Ru [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki [#] *Key deleted on reboot: HKU\S-1-5-18\Software\Hola [#] *Key deleted on reboot: HKCU\Software\Essentware [#] *Key deleted on reboot: HKCU\Software\Microsoft\Tinstalls [#] *Key deleted on reboot: HKCU\Software\Reg\Clean [#] *Key deleted on reboot: HKCU\Software\Mail.Ru [#] *Key deleted on reboot: HKCU\Software\COMMONMSG [#] *Key deleted on reboot: HKCU\Software\AppDataLow\Software\Mail.Ru [-] hersteldHKLM\SOFTWARE\Reg\Clean [-] hersteldHKLM\SOFTWARE\AVG Tuneup [-] hersteldHKLM\SOFTWARE\Mail.Ru [-] hersteldHKLM\SOFTWARE\Lavasoft\Web Companion [-] hersteldHKLM\SOFTWARE\TWEAKBIT [#] *Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki [#] *Key deleted on reboot: [x64] HKCU\Software\Essentware [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Tinstalls [#] *Key deleted on reboot: [x64] HKCU\Software\Reg\Clean [#] *Key deleted on reboot: [x64] HKCU\Software\Mail.Ru [#] *Key deleted on reboot: [x64] HKCU\Software\COMMONMSG [#] *Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Mail.Ru [-] hersteld[x64] HKLM\SOFTWARE\Essentware [-] hersteld[x64] HKLM\SOFTWARE\Hola [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [-] hersteldHKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [-] hersteld[x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} [-] hersteldHKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [-] hersteldHKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com [-] hersteldHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\qq.com [-] hersteldHKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.qq.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\bestpriceninja.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\foxi69.tlscdn.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pstatic.bestpriceninja.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\re-markable.net [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.re-markable00.re-markable.net [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\tlscdn.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\bestpriceninja.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\foxi69.tlscdn.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\re-markable.net [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.re-markable00.re-markable.net [-] hersteldHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\tlscdn.com [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\qq.com [#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.qq.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\bestpriceninja.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\foxi69.tlscdn.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pstatic.bestpriceninja.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\re-markable.net [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.re-markable00.re-markable.net [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\tlscdn.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\bestpriceninja.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\foxi69.tlscdn.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\re-markable.net [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.re-markable00.re-markable.net [#] *Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\tlscdn.com [-] hersteld[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [hola] [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [PCKeeperLive] [-] hersteldHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] [-] hersteld[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [vProt] [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion] [-] hersteldHKU\S-1-5-21-1854223093-3483252176-3228169965-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Web Companion] [#] *Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion] [#] *Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion] [-] hersteldHKCU\Software\MozillaPlugins\@hola.org/FlashPlayer [-] hersteldHKCU\Software\MozillaPlugins\@hola.org/vlc [-] hersteldHKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh [-] hersteldHKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin [-] hersteldHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com [-] hersteldHKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com [-] hersteldHKLM\SOFTWARE\Classes\AppID\OverlayIcon.DLL [-] hersteldHKLM\SOFTWARE\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj [-] hersteldHKLM\SOFTWARE\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd [-] hersteldHKLM\SOFTWARE\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof ***** [ Internetbrowser scannen ... ] ***** [-] [C:\Users\Ewoud\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [extension] verwijderdccfifbojenkenpkmnbnndeadpfdiffof [-] [C:\Users\Ewoud\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [extension] verwijderdoelpkepjlgmehajehfeicfbjdiobdkfj [-] [C:\Users\Ewoud\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [extension] verwijderdojlcebdkbpjdpiligkdbbkdkfjmchbfd ************************* :: Proxy instellingen gereset :: *Hosts file cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [20612 bytes] - [01/11/2016 17:30:02] C:\AdwCleaner\AdwCleaner[S0].txt - [19179 bytes] - [01/11/2016 17:22:56] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [20760 bytes] ##########