FRST log
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by User (administrator) on PC_BUSSINES on 04-04-2015 01:55:16
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available profiles: User)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Nederlands (Nederland)
Internet Explorer Version 9 (Default browser not detected!)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
() C:\Program Files\Softex\OmniPass\opvapp.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Desktop.exe
(Microsoft Corporation) C:\Windows\System32\wermgr.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-3988253976-802080291-3916808085-1004\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-01-12] (Google Inc.)
HKU\S-1-5-21-3988253976-802080291-3916808085-1004\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-3988253976-802080291-3916808085-1004\...\MountPoints2: {c5b9bf51-6909-11e4-a34e-001bfc97586a} - E:\DTE_Privacy_launcher.exe
HKU\S-1-5-18\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Windows Live Aanmelden - Help -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-28] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-28] (Google Inc.)
Toolbar: HKU\S-1-5-21-3988253976-802080291-3916808085-1004 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-03-28] (Google Inc.)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 172.19.243.50
Tcpip\..\Interfaces\{C25BB66B-77AC-4196-863C-4478A13F7C78}: [NameServer] 134.184.250.7,134.184.15.13
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\93clg68m.default
FF NewTab:
FF DefaultSearchUrl: hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF SearchEngineOrder.3: Bing
FF Keyword.URL:
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Picasa2\npPicasa3.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2008-11-13] (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.450 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2010-01-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.448 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2010-01-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2010-01-29] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2010-02-25] (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32(76).dll [2013-09-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2010-01-29] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll [2010-01-29] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2010-01-29] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPSWF32.dll [2006-11-09] ()
FF Extension: Microsoft .NET Framework Assistant - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\93clg68m.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2014-03-17]
FF Extension: Packard Bell Settings - C:\Program Files\Mozilla Firefox\extensions\
[email protected] [2007-11-09]
FF Extension: Talkback - C:\Program Files\Mozilla Firefox\extensions\
[email protected] [2007-11-09]
FF Extension: Google Toolbar for Firefox - C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007-11-09]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-25]
FF HKLM\...\Firefox\Extensions: [
[email protected]] - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\93clg68m.default\extensions
FF HKU\S-1-5-21-3988253976-802080291-3916808085-1004\...\Firefox\Extensions: [
[email protected]] - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\93clg68m.default\extensions
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
StartMenuInternet: Google Chrome.LX2IXEFA66ZXZ45XCZM335ABAI - C:\Users\Dushi\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
S4 NACAgent; C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe [783616 2010-08-19] (Cisco Systems, Inc.)
S4 omniserv; C:\Program Files\Softex\OmniPass\OmniServ.exe [40960 2006-12-15] (Softex Inc.) [File not signed]
S4 StkSSrv; C:\Windows\System32\StkCSrv.exe [24576 2006-12-11] (Syntek America Inc.)
S4 stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [73728 2006-09-14] (MicroVision Development, Inc.) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [139144 2006-12-15] (AuthenTec, Inc.)
S3 FIXUSTOR; C:\Windows\System32\DRIVERS\fixustor.sys [12544 2006-10-31] (Genesys Logic)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [6272 2006-10-27] ()
R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [36560 2006-09-27] (Sonic Solutions) [File not signed]
R3 StkCMini; C:\Windows\System32\DRIVERS\StkCMini.sys [1132544 2006-12-22] (Syntek)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 usbscan; system32\DRIVERS\usbscan.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-30 22:04 - 2015-03-30 22:04 - 00000000 ____D () C:\Users\User\AppData\Roaming\Real
2015-03-22 18:45 - 2015-03-22 18:45 - 05200384 _____ (AVAST Software) C:\Users\User\Desktop\aswmbr.exe
2015-03-15 19:29 - 2015-03-15 19:38 - 00000000 ____D () C:\AdwCleaner
2015-03-15 19:26 - 2015-03-15 19:26 - 02171392 _____ () C:\Users\User\Desktop\AdwCleaner.exe
2015-03-15 19:13 - 2015-03-15 14:33 - 01135104 _____ (Farbar) C:\Users\User\Desktop\FRST.exe
2015-03-15 15:15 - 2015-04-04 01:54 - 00000000 ____D () C:\Users\User\Desktop\15-03-2015 grote schoonmaak
2015-03-15 14:39 - 2015-03-15 15:11 - 00033485 _____ () C:\Users\User\Desktop\Addition.txt
2015-03-15 14:36 - 2015-04-04 01:55 - 00011467 _____ () C:\Users\User\Desktop\FRST.txt
2015-03-15 14:35 - 2015-04-04 01:55 - 00000000 ____D () C:\FRST
2015-03-15 14:20 - 2015-03-31 00:37 - 00001958 _____ () C:\Windows\system32\TeamViewer10_Hooks.log
2015-03-15 14:20 - 2015-03-31 00:36 - 00000843 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-03-15 14:20 - 2015-03-31 00:36 - 00000831 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-03-15 14:20 - 2015-03-31 00:36 - 00000831 _____ () C:\ProgramData\Desktop\TeamViewer 10.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-04 01:46 - 2008-01-08 00:04 - 02024129 _____ () C:\Windows\WindowsUpdate.log
2015-04-04 01:44 - 2007-11-09 21:43 - 00763554 _____ () C:\Windows\system32\perfh013.dat
2015-04-04 01:44 - 2007-11-09 21:43 - 00166132 _____ () C:\Windows\system32\perfc013.dat
2015-04-04 01:44 - 2006-11-02 12:33 - 01712506 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-04 01:41 - 2014-09-25 18:18 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-04 01:39 - 2007-11-09 14:20 - 00275612 _____ () C:\Windows\PFRO.log
2015-04-04 01:39 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-04 01:39 - 2006-11-02 14:47 - 00003168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-04 01:39 - 2006-11-02 14:47 - 00003168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-04 01:38 - 2007-11-09 13:38 - 00003204 _____ () C:\Windows\bthservsdp.dat
2015-04-04 01:38 - 2006-11-02 15:01 - 00032556 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-04 01:37 - 2014-09-22 13:42 - 00000000 ____D () C:\Users\User\AppData\Local\com
2015-04-04 01:37 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\DigitalLocker
2015-04-04 01:08 - 2014-05-02 10:46 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-03 21:59 - 2008-01-08 00:19 - 00000354 _____ () C:\Windows\Tasks\Uitgebreide garantie.job
2015-04-03 21:59 - 2008-01-08 00:19 - 00000354 _____ () C:\Windows\Tasks\Recovery DVD Creator.job
2015-03-31 00:37 - 2014-03-16 17:17 - 00000000 ____D () C:\Program Files\TeamViewer
2015-03-31 00:28 - 2014-03-16 17:49 - 00000000 ____D () C:\Users\User\AppData\Local\VirtualStore
2015-03-26 18:05 - 2014-05-02 10:46 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-26 18:05 - 2014-05-02 10:46 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-26 18:05 - 2014-04-17 17:35 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-03-22 20:10 - 2014-03-18 13:08 - 00000512 _____ () C:\Users\User\Desktop\MBR.dat
2015-03-16 02:13 - 2014-03-16 19:07 - 00000000 ____D () C:\Users\User\Tracing
2015-03-15 19:38 - 2015-02-13 11:54 - 00000958 _____ () C:\Users\User\Desktop\Internet Explorer (2).lnk
2015-03-15 19:38 - 2014-03-16 17:49 - 00000988 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-15 19:38 - 2007-11-09 13:59 - 00000925 _____ () C:\Users\Public\Desktop\Internet - Firefox.lnk
2015-03-15 19:38 - 2007-11-09 13:59 - 00000925 _____ () C:\ProgramData\Desktop\Internet - Firefox.lnk
2015-03-15 19:38 - 2007-11-09 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2015-03-15 19:22 - 2006-11-02 14:47 - 00423864 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-15 19:08 - 2014-03-16 18:22 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2015-03-15 19:08 - 2007-11-09 14:04 - 00000000 ____D () C:\Program Files\Google
2015-03-15 14:31 - 2014-03-16 17:50 - 00116464 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-12 23:56 - 2013-09-16 01:18 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2015-03-12 23:53 - 2014-09-25 18:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-12 23:53 - 2014-09-25 18:17 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-12 23:53 - 2014-03-18 16:57 - 00000902 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-12 23:53 - 2014-03-18 16:57 - 00000902 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-12 23:32 - 2014-01-25 17:26 - 00000000 ____D () C:\Windows\pss
2015-03-12 01:15 - 2015-01-08 15:15 - 00000086 _____ () C:\Users\User\AppData\Roaming\WB.CFG
==================== Files in the root of some directories =======
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\User\AppData\Roaming\IGTZIQD
2015-01-08 01:02 - 2015-01-08 01:02 - 1356768 _____ () C:\Users\User\AppData\Roaming\IGTZIQD.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\User\AppData\Roaming\VQUFGO
2014-09-22 12:25 - 2014-09-22 12:25 - 1968544 _____ () C:\Users\User\AppData\Roaming\VQUFGO.exe
2015-01-08 15:15 - 2015-03-12 01:15 - 0000086 _____ () C:\Users\User\AppData\Roaming\WB.CFG
2014-06-09 18:11 - 2014-06-09 18:11 - 0000552 _____ () C:\Users\User\AppData\Local\d3d8caps.dat
2014-04-01 11:35 - 2014-11-17 04:41 - 0003584 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-04 01:46
==================== End Of Log ============================