Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-01-2015
Ran by frank&jose (administrator) on QUAD on 11-01-2015 21:19:20
Running from C:\Users\frank&jose\Downloads
Loaded Profile: frank&jose (Available profiles: frank&jose & Rachel & Jochem & Tessa & Spel)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Nederlands (Nederland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411952 2014-11-04] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-02-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Reader Application Helper] => F:\Programs\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2014-05-23] (Sony Corporation)
HKLM-x32\...\Run: [QuickTime Task] => F:\Programs\QuickTime\QTTask.exe [417792 2009-11-10] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [KiesTrayAgent] => F:\ProgramFiles\samsungkies\Kies\KiesTrayAgent.exe [310064 2014-06-14] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-158038807-2111473649-2187484589-1001\...\Run: [DAEMON Tools Lite] => F:\Programs\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-158038807-2111473649-2187484589-1001\...\Run: [KiesPreload] => F:\ProgramFiles\samsungkies\Kies\Kies.exe [1563440 2014-06-14] (Samsung)
HKU\S-1-5-21-158038807-2111473649-2187484589-1001\...\Run: [KiesAirMessage] => F:\ProgramFiles\samsungkies\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-158038807-2111473649-2187484589-1001\...\Run: [] => F:\ProgramFiles\samsungkies\Kies\External\FirmwareUpdate\KiesPDLR.exe [843568 2014-06-14] (Samsung)
HKU\S-1-5-21-158038807-2111473649-2187484589-1001\...\RunOnce: [Shockwave Updater] => C:\Windows\SysWOW64\Adobe\Shockwave 11\SwHelper_1103471.exe [460216 2008-11-24] (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ComproRemote.lnk
ShortcutTarget: ComproRemote.lnk -> C:\Program Files (x86)\Common Files\VideoMate\ComproRemote.exe (Compro Technology, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ComproSchedulerDTV.lnk
ShortcutTarget: ComproSchedulerDTV.lnk -> C:\Program Files (x86)\Common Files\VideoMate\ComproSchedulerDTV.exe (Compro Technology, Inc.)
Startup: C:\Users\frank&jose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Karen's Replicator.lnk
ShortcutTarget: Karen's Replicator.lnk -> C:\Program Files (x86)\Karen's Power Tools\Replicator\PTReplicator.exe (Karen Kenworthy)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-158038807-2111473649-2187484589-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.nl/
BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> F:\ProgramFiles\TechSmith\SnagIt 9\DLLx64\SnagItBHO64.dll (TechSmith Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> F:\ProgramFiles\TechSmith\SnagIt 9\SnagItBHO.dll (TechSmith Corporation)
BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Toolbar: HKLM-x32 - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\ProgramFiles\TechSmith\SnagIt 9\SnagItIEAddin.dll (TechSmith Corporation)
DPF: HKLM-x32 {6E718D87-6909-4FCE-92D4-EDCB2F725727} http://www.navigram.com/engine/v1140/Navigram.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.4.2/jinstall-1_4-windows-i586.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\..\Interfaces\{D15AE699-8E0A-42B2-839E-0696B0D4FFEF}: [NameServer] 192.168.2.254,195.121.1.34
FireFox:
========
FF ProfilePath: C:\Users\frank&jose\AppData\Roaming\Mozilla\Firefox\Profiles\ohauw4kk.default
FF Homepage: https://www.google.nl/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @sony.com/ReaderDesktop -> F:\Programs\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> F:\ProgramFiles\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: DownloadHelper - C:\Users\frank&jose\AppData\Roaming\Mozilla\Firefox\Profiles\ohauw4kk.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-06]
Chrome:
=======
CHR StartupUrls: Default -> "https://www.google.nl/?gfe_rd=cr&ei=NEryU8WpG8XO-gbWroCYCQ"
CHR Profile: C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Documenten) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-18]
CHR Extension: (Google Drive) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-18]
CHR Extension: (YouTube) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-18]
CHR Extension: (Google Zoeken) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-18]
CHR Extension: (Bitdefender QuickScan) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2015-01-11]
CHR Extension: (Gmail) - C:\Users\frank&jose\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-18]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4942384 2014-10-17] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [24576 2013-11-03] (The OpenVPN Project) [File not signed]
S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2014-04-25] (Sony Corporation) [File not signed]
S2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2005-01-31] (Ulead Systems, Inc.) [File not signed]
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2014-10-17] (AVG Technologies CZ, s.r.o.)
R3 ComproHID; C:\Windows\System32\DRIVERS\ComproHID64.sys [9088 2007-10-01] (Compro Tech., Inc.)
R3 ComproHID; C:\Windows\SysWOW64\DRIVERS\ComproHID64.sys [9088 2007-10-01] (Compro Tech., Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-02-09] (Disc Soft Ltd)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-11] (Malwarebytes Corporation)
S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 ULCDRHlp; C:\Windows\SysWOW64\Drivers\ULCDRHlp.sys [27392 2004-12-23] (Ulead Systems, Inc.) [File not signed]
S3 VMHybrid64; C:\Windows\System32\DRIVERS\VMHybr64.sys [1403648 2011-05-06] (Compro Technology, Inc.)
S3 VMHybrid64; C:\Windows\SysWOW64\DRIVERS\VMHybr64.sys [1410048 2011-03-14] (Compro Technology, Inc.)
S3 MFE_RR; \??\C:\Users\FRANK&~1\AppData\Local\Temp\mfe_rr.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-11 21:15 - 2015-01-11 21:15 - 00024075 _____ () C:\Users\frank&jose\Downloads\Addition.txt
2015-01-11 21:14 - 2015-01-11 21:19 - 00011604 _____ () C:\Users\frank&jose\Downloads\FRST.txt
2015-01-11 21:14 - 2015-01-11 21:19 - 00000000 ____D () C:\FRST
2015-01-11 21:14 - 2015-01-11 21:14 - 02124288 _____ (Farbar) C:\Users\frank&jose\Downloads\FRST64.exe
2015-01-11 21:10 - 2015-01-11 21:10 - 01059840 _____ () C:\Users\frank&jose\Downloads\MicrosoftFixit50981.msi
2015-01-11 21:10 - 2015-01-11 21:10 - 01059840 _____ () C:\Users\frank&jose\Downloads\MicrosoftFixit50981 (1).msi
2015-01-11 21:00 - 2015-01-11 21:00 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\frank&jose\Downloads\rkill.exe
2015-01-11 21:00 - 2015-01-11 21:00 - 00002956 _____ () C:\Users\frank&jose\Desktop\Rkill.txt
2015-01-11 20:35 - 2015-01-11 21:05 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-11 20:11 - 2015-01-11 20:11 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-01-11 20:09 - 2015-01-11 20:09 - 00184704 _____ () C:\Users\frank&jose\Downloads\qsinstaller.exe
2015-01-11 20:01 - 2015-01-11 20:04 - 00000490 _____ () C:\delrepwv.log
2015-01-11 20:00 - 2015-01-11 20:00 - 00103792 _____ () C:\Users\frank&jose\Downloads\delrepwv_en.exe
2015-01-11 20:00 - 2015-01-11 20:00 - 00000000 ____D () C:\AVGTemp
2015-01-11 19:43 - 2015-01-11 19:43 - 00495712 _____ (Kaspersky Lab) C:\Users\frank&jose\Downloads\setup.exe
2015-01-11 19:28 - 2015-01-11 21:05 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-11 19:19 - 2015-01-11 20:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-11 19:19 - 2015-01-11 20:42 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-11 19:19 - 2015-01-11 20:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-11 19:19 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-11 19:19 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-11 19:17 - 2015-01-11 19:17 - 00000000 ____D () C:\Nieuwe map
2015-01-11 19:02 - 2015-01-11 19:02 - 00000000 ____D () C:\Users\frank&jose\Downloads\mbam-chameleon-3.1.7.0
2015-01-11 19:01 - 2015-01-11 19:01 - 04909382 _____ () C:\Users\frank&jose\Downloads\mbam-chameleon-3.1.7.0.zip
2015-01-11 13:32 - 2015-01-11 13:32 - 02494560 _____ (Trend Micro Inc.) C:\Users\frank&jose\Downloads\HousecallLauncher64 (1).exe
2015-01-11 13:26 - 2015-01-11 13:26 - 02494560 _____ (Trend Micro Inc.) C:\Users\frank&jose\Downloads\HousecallLauncher64.exe
2015-01-11 13:26 - 2015-01-11 13:26 - 00000036 _____ () C:\Users\frank&jose\AppData\Local\housecall.guid.cache
2015-01-11 13:23 - 2015-01-11 21:02 - 00000178 _____ () C:\Windows\system32\avgrep.txt
2015-01-10 16:28 - 2015-01-10 16:29 - 09532388 _____ () C:\Users\frank&jose\Downloads\oPlayer.zip
2015-01-10 16:26 - 2015-01-10 16:26 - 03028178 _____ () C:\Users\frank&jose\Downloads\Search_tool.rar
2015-01-10 16:17 - 2015-01-11 13:03 - 00000000 ____D () C:\Program Files\VideoActiveX
2015-01-10 16:17 - 2015-01-10 16:17 - 00000000 ____D () C:\Program Files\wanscam
2015-01-08 19:29 - 2015-01-11 19:17 - 00000000 ____D () C:\temp
2014-12-26 11:55 - 2015-01-11 20:50 - 00000168 _____ () C:\Windows\setupact.log
2014-12-26 11:55 - 2014-12-26 11:55 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-24 10:10 - 2014-12-24 10:10 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-21 14:58 - 2014-12-21 14:58 - 00000000 ____D () C:\Users\Tessa\AppData\Local\Apple
2014-12-18 21:44 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 21:44 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-12 13:26 - 2014-12-12 13:26 - 00000000 ____D () C:\Windows\system32\appraiser
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-11 21:09 - 2014-01-25 20:56 - 00745424 _____ () C:\Windows\system32\perfh013.dat
2015-01-11 21:09 - 2014-01-25 20:56 - 00153376 _____ () C:\Windows\system32\perfc013.dat
2015-01-11 21:09 - 2009-07-14 06:13 - 01669560 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-11 20:57 - 2014-01-25 12:03 - 01483182 _____ () C:\Windows\WindowsUpdate.log
2015-01-11 20:57 - 2009-07-14 05:45 - 00035504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-11 20:57 - 2009-07-14 05:45 - 00035504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-11 20:50 - 2014-08-18 15:27 - 00001052 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-11 20:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-11 20:02 - 2010-11-21 04:47 - 00045488 _____ () C:\Windows\PFRO.log
2015-01-11 13:25 - 2014-11-20 21:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-11 13:23 - 2014-01-25 12:17 - 00000000 ____D () C:\Users\frank&jose\AppData\Local\Avg2013
2015-01-11 13:21 - 2014-01-26 14:48 - 00000000 ____D () C:\Users\frank&jose\AppData\Roaming\Malwarebytes
2015-01-11 13:14 - 2014-01-25 12:03 - 00000000 ____D () C:\Users\frank&jose
2015-01-11 13:13 - 2014-01-26 14:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-11 13:13 - 2014-01-25 22:47 - 00000000 ____D () C:\Users\frank&jose\AppData\Local\Spotnet
2015-01-11 13:13 - 2014-01-25 22:36 - 00000000 ____D () C:\Users\frank&jose\AppData\Local\sabnzbd
2015-01-11 13:13 - 2014-01-25 22:34 - 00000000 ____D () C:\Users\frank&jose\AppData\Roaming\vlc
2015-01-11 13:13 - 2014-01-25 18:49 - 00000000 ____D () C:\Users\Tessa
2015-01-11 13:13 - 2014-01-25 18:31 - 00000000 ____D () C:\Users\Spel
2015-01-11 13:13 - 2014-01-25 18:24 - 00000000 ____D () C:\Users\Rachel
2015-01-11 13:13 - 2014-01-25 18:18 - 00000000 ____D () C:\Users\Jochem
2015-01-11 13:13 - 2014-01-25 12:17 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-11 13:13 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-01-11 13:13 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-01-10 17:40 - 2014-01-25 17:51 - 00000000 ____D () C:\Users\frank&jose\Documents\frank
2014-12-30 23:34 - 2014-01-26 22:27 - 00000000 ____D () C:\Users\frank&jose\Documents\Volleybal_2014
2014-12-26 14:43 - 2014-08-18 15:27 - 00001056 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-25 15:31 - 2014-01-28 22:36 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{C80EC599-400D-4F30-A69C-96ACC30A0A73}
2014-12-24 16:43 - 2014-07-29 20:23 - 00000000 ____D () C:\Users\frank&jose\AppData\Roaming\DVD Flick
2014-12-24 16:21 - 2014-07-30 18:57 - 00000000 ____D () C:\ProgramData\DVD Shrink
2014-12-23 16:37 - 2014-11-02 21:33 - 00000000 ____D () C:\Users\frank&jose\AppData\Roaming\Kodi
2014-12-17 21:43 - 2014-02-04 15:51 - 00000000 ____D () C:\Users\frank&jose\Documents\tessa
2014-12-16 22:31 - 2014-01-25 17:51 - 00000000 ____D () C:\Users\frank&jose\Documents\adressen
2014-12-14 18:50 - 2014-01-27 21:38 - 00038478 _____ () C:\Users\frank&jose\AppData\Roaming\Door lijstscheidingstekens gescheiden waarden (Windows).ADR
2014-12-14 12:50 - 2014-03-19 17:03 - 00000000 ____D () C:\Users\Tessa\Documents\inge
2014-12-12 16:04 - 2014-01-25 21:39 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-12 13:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 13:43 - 2014-08-18 15:27 - 00002207 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-12 13:26 - 2014-05-06 22:08 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-12 13:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
Files to move or delete:
====================
C:\Users\frank&jose\ghost.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed