start CreateRestorePoint: HKU\S-1-5-21-3651363734-1596917187-1413340531-1001\...409d6c4515e9\InprocServer32: [Default-shell32] <==== AANDACHT IFEO\MRT.exe: [Debugger] C:\Program Files\Pevucult\_ALLOWDEL_1fd4083\Gubed.exe -Yrrehs GroupPolicy: Restrictie - Chrome <======= AANDACHT Toolbar: HKU\S-1-5-21-3651363734-1596917187-1413340531-1001 -> Geen Naam - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - Geen bestand Toolbar: HKU\S-1-5-21-3651363734-1596917187-1413340531-1001 -> Geen Naam - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - Geen bestand S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] S2 udpproxy; "C:\Users\thuis\Downloads\UdpProxy.exe" /service [X] U3 aswbdisk; geen ImagePath S3 hmatap; system32\DRIVERS\hmatap.sys [X] S3 NAVENG; \??\C:\Program Files\Norton Security with Backup\NortonData\22.9.1.12\Definitions\SDSDefs\20170522.018\NAVENG.SYS [X] S3 NAVEX15; \??\C:\Program Files\Norton Security with Backup\NortonData\22.9.1.12\Definitions\SDSDefs\20170522.018\NAVEX15.SYS [X] U4 npcap_wifi; geen ImagePath S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] C:\Program Files\Pevucult Task: {00731B0A-8E15-4AD6-9160-0987BE65239D} - System32\Tasks\{DF06C5DE-8199-4610-8A53-D9D1BD47BEEE} => pcalua.exe -a C:\Users\thuis\AppData\Local\Temp\jre-8u101-windows-au.exe -d C:\Windows\system32 -c /installmethod=jau FAMILYUPGRADE=1 <==== AANDACHT Task: {0267196D-FFBC-488F-9507-10D779F9DBBB} - System32\Tasks\Manogeernery Module => C:\Program Files\Pevucult\kuvas.exe Task: {0B130142-B15B-494E-8803-63E39F9B1B21} - \AutoPico Daily Restart -> Geen bestand <==== AANDACHT Task: {0FF3E86A-7286-42A4-9419-B6CC879751BF} - System32\Tasks\Adobe => C:\Users\thuis\AppData\Local\Temp\keye.exe <==== AANDACHT Task: {9E0111DF-35A4-424E-82B9-9A005B220A6F} - \UCBrowserUpdater -> Geen bestand <==== AANDACHT Task: {E285460A-A3D5-47E0-A8D2-C5255E8D53DA} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: C:\Windows\Tasks\UCBrowserUpdater.job => <==== AANDACHT AlternateDataStreams: C:\Users\thuis\AppData\Local\Temp:{34004D00-5100-3800-4500-650042004E00} [192] AlternateDataStreams: C:\Users\thuis\AppData\Local\Temp:{6F004C00-4500-7100-7100-2B0069007500} [640] FirewallRules: [{6A372D2C-46B0-4B7B-8A41-183C56AB674E}] => (Allow) ????????????????????? FirewallRules: [{C9BDFE01-4209-40F1-B9A3-BC048AF71EAA}] => (Allow) ??????????????????????e Reboot: end