start CreateRestorePoint: CloseProcesses: Task: {040A1CAD-B34B-4397-9D26-E3E7E13F32AD} - System32\Tasks\{867BA8B7-9AD5-42D2-B0EC-D1B074D938A7} => pcalua.exe -a "C:\Program Files (x86)\BestCleaner\uninstaller.exe" Task: {0F463FF3-2EA3-4F1B-B1DA-CBACE028D5A8} - System32\Tasks\UCBrowserUpdaterCore => C:\Program Files (x86)\UCBrowser\Application\update_task.exe [2016-12-27] (UCWeb Inc) <==== AANDACHT Task: {23CB2559-F0C7-4A9C-84AD-DB48D3420D3D} - System32\Tasks\Driver Booster SkipUAC (Fenny Beernink) => C:\Program Files (x86)\IObit\Driver Booster\4.1.0\DriverBooster.exe Task: {6F563306-2352-4076-B769-E3E3E6D92DD4} - System32\Tasks\KuaiZip_Update => C:\Program Files\快压\X86\Update.exe [2017-01-01] (Shanghai Guangle Network Technology Ltd Task: {7E9F4588-BE61-4400-A404-BE0C278F7C82} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe [2016-12-27] (UCWeb Inc) <==== AANDACHT Task: {B97983F5-CBDD-4A74-A4BB-1808C3ED6507} - System32\Tasks\psv_Xxx-sing => /c regedit.exe /s "C:\ProgramData\Hotfresh\Over-Fax.reg" & del "C:\ProgramData\Hotfresh\Over-Fax.reg" & SCHTASKS /Delete /TN "psv_Xxx-sing" /F <==== AANDACHT Task: {BAB31928-B2CF-47EA-90BC-FA43021DB3C3} - System32\Tasks\Jiterckgeters Mapper => C:\Program Files (x86)\Qphchfepy\ermery.exe [2017-01-01] (Glarysoft Ltd) Task: {C0CD946B-32A5-48A0-912F-78D08756C491} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe [2016-01-28] (Optimal Software s.r.o.) <==== AANDACHT Task: {C164D693-B77B-4902-A3D2-E817200C053D} - System32\Tasks\osTip => Chrome.exe <==== AANDACHT Task: C:\WINDOWS\Tasks\PC SpeedUp Service Deactivator.job => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== AANDACHT Task: C:\WINDOWS\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== AANDACHT Task: C:\WINDOWS\Tasks\UCBrowserUpdaterCore.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== AANDACHT AlternateDataStreams: C:\WINDOWS\system32\drivers:ucdrv-x64.sys [23652] AlternateDataStreams: C:\WINDOWS\system32\drivers:x64 [1479458] AlternateDataStreams: C:\WINDOWS\system32\drivers:x86 [1205026] FirewallRules: [{C87A2BD2-E763-40C7-81A7-C7AE9198FF0E}] => C:\Users\Fenny Beernink\AppData\Local\Temp\is-9ICNG.tmp\download\MiniThunderPlatform.exe FirewallRules: [{6F8C243A-6F3D-425C-8785-37E4E9D13B35}] => C:\Users\Fenny Beernink\AppData\Local\Temp\00030292\inst_buychannel_37.exe FirewallRules: [{6A05AA40-F5AE-4D53-B985-D9DB9A857BD4}] => C:\Users\Fenny Beernink\AppData\Local\Temp\00030292\inst_buychannel_37.exe FirewallRules: [{11111FAA-FE93-4013-AFCF-C40CD81923C8}] => C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe FirewallRules: [{89A8C906-9787-4015-9351-DA0F1760F231}] => C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe FirewallRules: [{4B0C0386-DD2F-4BD1-809F-B8922837B87F}] => C:\Program Files (x86)\UCBrowser\Application\Downloader\download\MiniThunderPlatform.exe FirewallRules: [{0B4EB1C3-267C-47B2-AA7D-73C4AC81F9BA}] => C:\Program Files (x86)\LuDaShi\Utils\Down.exe FirewallRules: [{F1CBDE3F-2330-49A8-A89B-A99F3C2BAE26}] => C:\Program Files (x86)\LuDaShi\Utils\Down.exe FirewallRules: [{90CADD58-1692-43BF-90B4-B913A4E53F5D}] => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe FirewallRules: [{5C1834C3-52B5-42E3-8CF3-9188828C334C}] => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe HKLM\...\Run: [vnlgp] => C:\Users\Fenny Beernink\AppData\Roaming\vnlgp\vnlgp.exe [1546752 2016-12-16] () <===== AANDACHT HKLM-x32\...\Run: [BestCleaner] => "C:\Program Files (x86)\BestCleaner\BestCleaner.exe" <===== AANDACHT HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [HBPPY2VQVN] => C:\Program Files\SU6OSSYMPR\SU6OSSYMP.exe [369664 2017-01-01] () HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [OZJ81Y4ZK9] => C:\Program Files\IO15CW467R\IO15CW467.exe [369664 2017-01-01] () HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [RIL4T1GK16] => "C:\Program Files (x86)\BestCleaner\3LYFA6HBZ4.exe" <===== AANDACHT HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [FL5IYFCNP7] => C:\Program Files\9WGJ08H4DM\9WGJ08H4D.exe [369664 2017-01-01] () HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [msiql] => C:\Users\Fenny Beernink\AppData\Local\Temp\00030243\msiql.exe [2071552 2017-01-01] () <===== AANDACHT HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [PCSpeedUp] => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe [354976 2016-01-28] (Optimal Software s.r.o.) <===== AANDACHT HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [ComputerZ-Tray] => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe [2977704 2016-12-12] () HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\Chrome.exe [7204864 2016-12-06] () HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\...\Run: [360wp-srv] => C:\Users\Fenny Beernink\AppData\Roaming\360bizhi\360wpsrv.exe [1636264 2016-12-26] (360.cn) HKLM\...\Providers\6t6bxo49: C:\Program Files (x86)\Stoidomperwgh Reports\local64spl.dll [292352 2017-01-01] () HKLM\...\Providers\6t6bxo49: C:\Program Files (x86)\Stoidomperwgh Reports\local64spl.dll [292352 2017-01-01] () AppInit_DLLs: C:\ProgramData\Hotfresh\OpeLa.dll => C:\ProgramData\Hotfresh\OpeLa.dll [358912 2017-01-01] () AppInit_DLLs-x32: C:\ProgramData\Hotfresh\Tantraxlex.dll => C:\ProgramData\Hotfresh\Tantraxlex.dll [248320 2017-01-01] () ShellExecuteHooks: Geen Naam - {7D42FA1C-CC34-11E6-B49D-64006A5CFC23} - C:\Users\Fenny Beernink\AppData\Roaming\Berserward\Shacientteile.dll [144896 2017-01-01] () ShellExecuteHooks: Geen Naam - {5F51FFFE-7463-4220-B711-E5B9ACB8EDFE} - C:\ProgramData\igfxDH.dll [965120 2016-12-26] () ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\快压\X64\KZipShell.dll [2017-01-01] () HKU\S-1-5-21-3032902047-1669751184-2458482982-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRHOjYN9_5EdL7qPpMxklPcbRq6vYZg_6HchTO9MPxSann48BgQHUZWcZWhuIzCJBmeeQyMxr2rv49njqibWt1S3nabbmSl1MExHxYbAjvjnntxtjjNR_nuAux4xGi4WqCZ2B4BDxKQYlEm2FagXu2Lcbwq4dJjgUEUZUJ8pvv_wQW761PEdaDsd7M8g,,&q={searchTerms} SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRHOjYN9_5EdL7qPpMxklPcbRq6vYZg_6HchTO9MPxSann48BgQHUZWcZWhuIzCJBmeeQyMxr2rv49njqibWt1S3nabbmSl1MExHxYbAjvjnntxtjjNR_nuAux4xGi4WqCZ2B4BDxKQYlEm2FagXu2Lcbwq4dJjgUEUZUJ8pvv_wQW761PEdaDsd7M8g,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-3032902047-1669751184-2458482982-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRHOjYN9_5EdL7qPpMxklPcbRq6vYZg_6HchTO9MPxSann48BgQHUZWcZWhuIzCJBmeeQyMxr2rv49njqibWt1S3nabbmSl1MExHxYbAjvjnntxtjjNR_nuAux4xGi4WqCZ2B4BDxKQYlEm2FagXu2Lcbwq4dJjgUEUZUJ8pvv_wQW761PEdaDsd7M8g,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-3032902047-1669751184-2458482982-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRHOjYN9_5EdL7qPpMxklPcbRq6vYZg_6HchTO9MPxSann48BgQHUZWcZWhuIzCJBmeeQyMxr2rv49njqibWt1S3nabbmSl1MExHxYbAjvjnntxtjjNR_nuAux4xGi4WqCZ2B4BDxKQYlEm2FagXu2Lcbwq4dJjgUEUZUJ8pvv_wQW761PEdaDsd7M8g,,&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = S2 GoogleChromeUpService; C:\ProgramData\service.exe [1620992 2017-01-01] () [Bestand niet getekend] <==== AANDACHT R2 Hotfresh; C:\ProgramData\\Hotfresh\\Hotfresh.exe [629760 2017-01-01] () [Bestand niet getekend] R2 HpSvc; C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll [252328 2016-11-18] () <==== AANDACH R2 KuaizipUpdateChecker; C:\Program Files\快压\X86\kuaizipUpdateChecker.dll [219032 2017-01-01] () R2 Mokeght; C:\Program Files (x86)\Qphchfepy\Cliwleeng.dll [179200 2017-01-01] () [Bestand niet getekend] R2 PCSUService; C:\Program Files (x86)\PC Speed Up\PCSUService.exe [445600 2016-01-28] (Optimal Software s.r.o.) <==== AANDACHT R2 SCService; C:\Program Files (x86)\PC Speed Up\SpeedCheckerService.exe [79520 2016-10-24] (Optimal Software s.r.o.) <==== AANDACHT R2 Nettrans; C:\ProgramData\NetworkPacketManitor\Nettrans.exe [43520 2017-01-01] () [Bestand niet getekend] R2 UCBrowserSvc; C:\Program Files (x86)\UCBrowser\Application\UCService.exe [935312 2016-12-27] () R2 WpSvc; C:\Users\Fenny Beernink\AppData\Roaming\360bizhi\lpi\WpSvc.dll [253352 2016-11-17] () R1 a21cb2b62b110048d6d629294fe0f5b8; C:\WINDOWS\system32\drivers\a21cb2b62b110048d6d629294fe0f5b8.sys [95040 2016-12-16] (97V68D) <==== AANDACHT S3 ComputerZ_x64; C:\Program Files (x86)\LuDaShi\ComputerZ_x64.sys [49152 2016-06-27] (ludashi.com) <==== AANDACHT R2 KuaiZipDrive; C:\WINDOWS\system32\drivers\KuaiZipDrive.sys [92832 2017-01-01] (WinMount International Inc) R1 ucdrv; C:\Program Files (x86)\UCBrowser\Security:ucdrv-x64.sys [23652 ] (UC Web Inc.) <==== AANDACHT NETSVCx32: HpSvc -> C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll () NETSVCx32: WpSvc -> C:\Users\Fenny Beernink\AppData\Roaming\360bizhi\lpi\WpSvc.dll () 2017-01-01 17:36 - 2017-01-01 17:36 - 00003036 _____ C:\WINDOWS\System32\Tasks\osTip 2017-01-01 17:36 - 2017-01-01 17:36 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\LDSGameAssistant 2017-01-01 17:36 - 2017-01-01 17:36 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\360wp 2017-01-01 17:36 - 2017-01-01 17:36 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\360bizhi 2017-01-01 17:36 - 2017-01-01 17:36 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Local\Chromium 2017-01-01 17:36 - 2017-01-01 17:36 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Local\CEF 2017-01-01 17:36 - 2017-01-01 17:36 - 00000000 ____D C:\Program Files (x86)\360 2017-01-01 17:35 - 2017-01-02 20:14 - 00000342 _____ C:\WINDOWS\Tasks\UCBrowserUpdaterCore.job 2017-01-01 17:35 - 2017-01-02 19:57 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\KuaiZip 2017-01-01 17:35 - 2017-01-02 16:43 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\Ludashi 2017-01-01 17:35 - 2017-01-02 16:40 - 00000506 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job 2017-01-01 17:35 - 2017-01-02 16:40 - 00000000 ____D C:\Program Files (x86)\LuDaShi 2017-01-01 17:35 - 2017-01-01 18:35 - 00002696 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdaterCore 2017-01-01 17:35 - 2017-01-01 17:36 - 00000000 __SHD C:\ProgramData\WindowsMsg 2017-01-01 17:35 - 2017-01-01 17:36 - 00000000 ____D C:\Program Files (x86)\LDSGameCenter 2017-01-01 17:35 - 2017-01-01 17:35 - 00092832 _____ (WinMount International Inc) C:\WINDOWS\system32\Drivers\KuaiZipDrive.sys 2017-01-01 17:35 - 2017-01-01 17:35 - 00003594 _____ C:\WINDOWS\System32\Tasks\KuaiZip_Update 2017-01-01 17:35 - 2017-01-01 17:35 - 00003542 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdater 2017-01-01 17:35 - 2017-01-01 17:35 - 00001606 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC???.lnk 2017-01-01 17:35 - 2017-01-01 17:35 - 00000889 _____ C:\Users\Fenny Beernink\AppData\Roaming\Microsoft\Windows\Start Menu\快压.lnk 2017-01-01 17:35 - 2017-01-01 17:35 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\Softlink 2017-01-01 17:35 - 2017-01-01 17:35 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\navplugin 2017-01-01 17:35 - 2017-01-01 17:35 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Local\UCBrowser 2017-01-01 17:35 - 2017-01-01 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\??? 2017-01-01 17:35 - 2017-01-01 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC??? 2017-01-01 17:35 - 2017-01-01 17:35 - 00000000 ____D C:\Program Files\快压 2017-01-01 17:34 - 2017-01-02 19:19 - 00000000 ____D C:\Program Files (x86)\PC Speed Up 2017-01-01 17:34 - 2017-01-02 16:46 - 00003074 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Fenny Beernink) 2017-01-01 17:34 - 2017-01-02 16:40 - 00000390 _____ C:\WINDOWS\Tasks\PC SpeedUp Service Deactivator.job 2017-01-01 17:34 - 2017-01-01 18:40 - 00000000 ____D C:\Program Files (x86)\UCBrowser 2017-01-01 17:34 - 2017-01-01 17:35 - 00000000 ____D C:\Users\Fenny Beernink\Documents\PCSpeedUp 2017-01-01 17:34 - 2017-01-01 17:34 - 00002848 _____ C:\WINDOWS\System32\Tasks\PC SpeedUp Service Deactivator 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\WINDOWS\IObit 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\Users\Public\Thunder Network 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\Mozilla 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\Users\Fenny Beernink\AppData\LocalLow\IObit 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\ProgramData\Thunder Network 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\ProgramData\ProductData 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Socia2Sear Browser Enhancer 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-01-01 17:34 - 2017-01-01 17:34 - 00000000 ____D C:\ProgramData\IObit 2017-01-01 17:33 - 2017-01-01 17:34 - 00000000 ____D C:\WINDOWS\system32\SSL 2017-01-01 17:33 - 2017-01-01 17:34 - 00000000 ____D C:\Program Files\63d6cb84dda4748f0be36e2378097c6a 2017-01-01 17:33 - 2017-01-01 17:33 - 07316480 _____ C:\Users\Fenny Beernink\AppData\Roaming\agent.dat 2017-01-01 17:33 - 2017-01-01 17:33 - 01938535 _____ C:\Users\Fenny Beernink\AppData\Roaming\Airnix.bin 2017-01-01 17:33 - 2017-01-01 17:33 - 01908230 _____ C:\Users\Fenny Beernink\AppData\Roaming\KonStrong.tst 2017-01-01 17:33 - 2017-01-01 17:33 - 00629760 _____ C:\Users\Fenny Beernink\AppData\Roaming\KonStrong.exe 2017-01-01 17:33 - 2017-01-01 17:33 - 00278519 _____ C:\Users\Fenny Beernink\AppData\Roaming\Lam-Lax.bin 2017-01-01 17:33 - 2017-01-01 17:33 - 00140288 _____ C:\Users\Fenny Beernink\AppData\Roaming\Installer.dat 2017-01-01 17:33 - 2017-01-01 17:33 - 00126464 _____ C:\Users\Fenny Beernink\AppData\Roaming\noah.dat 2017-01-01 17:33 - 2017-01-01 17:33 - 00070704 _____ C:\Users\Fenny Beernink\AppData\Roaming\Config.xml 2017-01-01 17:33 - 2017-01-01 17:33 - 00018432 _____ C:\Users\Fenny Beernink\AppData\Roaming\Main.dat 2017-01-01 17:33 - 2017-01-01 17:33 - 00016176 _____ C:\Users\Fenny Beernink\AppData\Roaming\InstallationConfiguration.xml 2017-01-01 17:33 - 2017-01-01 17:33 - 00006138 _____ C:\WINDOWS\System32\Tasks\Jiterckgeters Mapper 2017-01-01 17:33 - 2017-01-01 17:33 - 00005568 _____ C:\Users\Fenny Beernink\AppData\Roaming\md.xml 2017-01-01 17:33 - 2017-01-01 17:33 - 00002401 _____ C:\WINDOWS\SysWOW64\findit.xml 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\vnlgp 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\IObit 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Roaming\Berserward 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Users\Fenny Beernink\AppData\Local\Cdryanerguther 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\ProgramData\NetworkPacketManitor 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Program Files\SU6OSSYMPR 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Program Files\IO15CW467R 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Program Files\9WGJ08H4DM 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Program Files (x86)\Stoidomperwgh Reports 2017-01-01 17:33 - 2017-01-01 17:33 - 00000000 ____D C:\Program Files (x86)\Qphchfepy C:\Users\Fenny Beernink\AppData\Local\Temp\2O77WEDFBEAB.exe C:\Users\Fenny Beernink\AppData\Local\Temp\5NFKA7MRHZ8Z.exe C:\Users\Fenny Beernink\AppData\Local\Temp\A8E8.tmp.exe C:\Users\Fenny Beernink\AppData\Local\Temp\AutoTime51495.exe C:\Users\Fenny Beernink\AppData\Local\Temp\DriverBoosterSetup.exe C:\Users\Fenny Beernink\AppData\Local\Temp\global_installer.exe C:\Users\Fenny Beernink\AppData\Local\Temp\J9899ZG00HZP.exe C:\Users\Fenny Beernink\AppData\Local\Temp\ludashisetup.exe C:\Users\Fenny Beernink\AppData\Local\Temp\MSETUP4.EXE C:\Users\Fenny Beernink\AppData\Local\Temp\Rho.exe C:\Users\Fenny Beernink\AppData\Local\Temp\uninstall.exe C:\Users\Fenny Beernink\AppData\Local\Temp\wajam_install.exe C:\Users\Fenny Beernink\AppData\Local\Temp\Y491K65T9A.exe C:\WINDOWS\system32\drivers\KuaiZipDrive.sys C:\WINDOWS\system32\drivers\a21cb2b62b110048d6d629294fe0f5b8.sys C:\Program Files (x86)\BestCleaner C:\Program Files (x86)\Stoidomperwgh Reports C:\ProgramData\NetworkPacketManitor C:\ProgramData\Hotfresh C:\Program Files (x86)\UCBrowser C:\Program Files\快压 C:\Users\Fenny Beernink\AppData\Roaming\vnlgp C:\Program Files\SU6OSSYMPR C:\Users\Fenny Beernink\AppData\Roaming\Berserward C:\Program Files\IO15CW467R C:\Program Files\9WGJ08H4DM C:\Program Files (x86)\PC Speed Up c:\program files (x86)\ludashi c:\users\fenny beernink\appdata\roaming\360bizhi EmptyTemp: end