Jump to content

Recommended Posts

Posted
I had a problem with win 7 opening files on its own in fact the only way I could stop it is by shutting down which it done by itself when I held the pointer over the close down button. I then tried to restart and it came up with disc reading error press Ctrl, Alt, Del. It done this about 12 times and then started as normal. I thought that I should run Malwarebyte which showed 100 hits only 2 had ticks beside them. They were Trojan.Agent F (file) and Trojan . Agent F (Registry key ) all the others are Pup Optional with letters C, I, and S after them should I tick all and what do I do after that.
  • Replies 8
  • Created
  • Last Reply

Top Posters In This Topic

Posted

Hi

 

Until the security experts log in could you update MBAM - run it again - let MBAM deal with what it finds then post the log here please.

 

If you click on "Logs" and click on the most recent it will open in Notepad.

You can copy it from there.

There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !!

 

MiniToolBox

Network Test

Wireless Test

Posted
which showed 100 hits only 2 had ticks beside them. They were Trojan.Agent F (file) and Trojan . Agent F (Registry key )

Trojan:W32/Agent is a very large family of programs, most of which download and install adware or malware to the victim's machine. Agent variants may also change the configuration settings for Windows Explorer and/or for the Windows interface.

 

So without seeing the MBAM log, it's difficult to say exactly what the report is referring to.

Please post the full report as asked for by KenB.

 

Thanks.

Member of:

UNITE

Posted

Heres the log

 

http://www.malwarebytes.org

 

Database version: v2014.01.04.04

 

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 11.0.9600.16476

Eddy :: HAL [administrator]

 

04-Jan-14 5:17:39 PM

mbam-log-2014-01-04 (17-17-39).txt

 

Scan type: Full scan (C:\|E:\|G:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 448162

Time elapsed: 1 hour(s), 16 minute(s), 33 second(s)

 

Memory Processes Detected: 0

(No malicious items detected)

 

Memory Modules Detected: 0

(No malicious items detected)

 

Registry Keys Detected: 10

HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

HKCR\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1} (PUP.Optional.Conduit) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\MixiDJ_V30 (PUP.Optional.MixiDJ.A) -> Quarantined and deleted successfully.

HKCR\CLSID\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MixiDJ_V30 Toolbar (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

 

Registry Values Detected: 4

HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: =´"�î0?@›ú<É›�*Ý -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: MixiDJ V30 Toolbar -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: -> Quarantined and deleted successfully.

 

Registry Data Items Detected: 1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs (PUP.Optional.Conduit.A) -> Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll) Good: () -> Quarantined and repaired successfully.

 

Folders Detected: 28

C:\Program Files (x86)\SearchProtect (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\Main (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\Main\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\Main\Logs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\Main\rep (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\SearchProtect (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\SearchProtect\Logs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\SearchProtect\rep (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\UI\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\UI\dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\protection (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\settings (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\rep (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30 (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

 

Files Detected: 135

C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (PUP.Optional.Conduit.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll (PUP.Optional.Conduit.A) -> Delete on reboot.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\MixiDJ_V30ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Conduit\CT3289075\u*******Control_v6AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Conduit\CT3298566\MixiDJ_V30AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\+TQaFx+8.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\B+XCgdIy.exe.part (PUP.Optional.Installex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\checktbexist.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\et75BXD0.exe.part (PUP.Optional.Installrex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\h+QDPKCQ.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\JCqIN+4l.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\nsa8978.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\nsaD38F.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\nsfDDBF.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\nsq778B.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\nsu5D37.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\nsvB1EF.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ooLTqI8C.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\pKp+x3Wv.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\sbn5ymn6.exe.part (PUP.Optional.Installrex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\SecondStepInstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\To50oUdZ.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\AU\SPSetup.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\chLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\ffLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\spch.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\spff.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Windows\Temp\nsb8940.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Windows\Temp\nsg8826.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Windows\Temp\nsw8AA5.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Windows\Temp\nswD5EA.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\EULA.txt (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\mconduitinstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\CT3289075.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\CT3289075.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\dtime.csf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\initData.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\manifest.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\chromeid.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\CT3298566.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\CT3298566.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\initData.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\manifest.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\setup.ini.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\GottenAppsContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\hk64tbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\hktbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\ldrtbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\OtherAppsContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\prxtbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\SharedAppsContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\tbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\toolbar.cfg (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\ToolbarContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MixiDJ_V30\uninstall.exe (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully.

 

(end)

Posted

Hi mercycle

 

Thanks for the MBAM report.

As there seems to be quite a lot of adware on the system, i recommend running some dedicated Adware removal tools.

Best to be safe than sorry.

 

Step 1

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

 

 

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer.
  • After the scan has finished...
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

 

 

In your next reply, please submit:

JRT.txt

AdwCleaner report

 

 

Thanks.

Member of:

UNITE

Posted (edited)

I done another Malwarebyte check today after yesterdays one's cleanup and it's come up with

 

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org

 

Database version: v2014.01.05.02

 

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 11.0.9600.16476

Eddy :: HAL [administrator]

 

05-Jan-14 2:54:00 PM

mbam-log-2014-01-05 (14-54-00).txt

 

Scan type: Full scan (C:\|E:\|G:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 447284

Time elapsed: 1 hour(s), 13 minute(s), 53 second(s)

 

Memory Processes Detected: 0

(No malicious items detected)

 

Memory Modules Detected: 0

(No malicious items detected)

 

Registry Keys Detected: 0

(No malicious items detected)

 

Registry Values Detected: 0

(No malicious items detected)

 

Registry Data Items Detected: 0

(No malicious items detected)

 

Folders Detected: 0

(No malicious items detected)

 

Files Detected: 0

(No malicious items detected)

 

(end)

 

Do I have to do the other stuff still or has it been cleaned to a shine.

Edited by mercycle
Posted

here's the first part

 

hisisu

Version: 6.0.9 (01.01.2014:1)

OS: Windows 7 Home Premium x64

Ran by Eddy on 07-Jan-14 at 16:10:07.04

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

~~~ Services

 

Successfully stopped: [service] wcuservice_stc_ie

Successfully deleted: [service] wcuservice_stc_ie

 

 

 

~~~ Registry Values

 

 

 

~~~ Registry Keys

 

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthelper.exe

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\viprotocol.dll

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ige****ttings

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\s

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2786678

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3289075

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3298566

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASMANCS

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASAPI32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASMANCS

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0DA562E7-0C1E-4F3E-8E79-DE8B45D5A77E}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96f454ea-9d38-474f-b504-56193e00c1a5}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{96f454ea-9d38-474f-b504-56193e00c1a5}

 

 

 

~~~ Files

 

Successfully deleted: [File] "C:\Users\Eddy\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage"

Successfully deleted: [File] "C:\Users\Eddy\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage-journal"

Successfully deleted: [File] "C:\Users\Eddy\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"

Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\nsprotector.js"

Successfully deleted: [File] "C:\end"

 

 

 

~~~ Folders

 

Successfully deleted: [Folder] "C:\ProgramData\big fish"

Successfully deleted: [Folder] "C:\ProgramData\big fish games"

Successfully deleted: [Folder] "C:\ProgramData\premium"

Successfully deleted: [Folder] "C:\ProgramData\splashtop"

Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\big fish games"

Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\getrighttogo"

Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\splashtop"

Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\thinstall"

Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\w3i, llc"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\big fish"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\conduit"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\cre"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\searchprotect"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\thinstall"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\locallow\conduit"

Successfully deleted: [Folder] "C:\Users\Eddy\appdata\locallow\pricegong"

Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"

Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"

Failed to delete: [Folder] "C:\Program Files (x86)\splashtop"

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{001BF517-B6EB-4DE7-9649-CDDD536107A0}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{002DDDA5-91D4-4F0C-92E3-0E0C2F6F81BF}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{00809BE5-93EC-4BD4-A7AF-8E32583ACF78}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{009A5612-F0C6-4F6A-832B-242660947AE2}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{00A34625-AE76-40A4-AEB0-9C7FA720F08E}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{012C8843-3D37-4AD0-A24C-19BCFC80BFF2}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{01C5652A-5E90-4BAC-A87B-EA1E014E95B2}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{01E2E6E9-995E-44B0-8C39-93FCE9DA6266}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{02262F57-30B0-4F51-8823-AB84DB1A4209}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{022B0FFA-0E89-4109-9486-B6470D0BFBE8}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0258F588-43F1-4603-8470-99FD9D8301CA}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{02AB8FEC-0005-4E0E-9125-29BBC78BAC3D}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{02B71CDB-D8D4-41F9-8A26-B33AF1E13F63}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{031D01A8-9A23-4B65-9277-5E0ADE108DD1}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{033690BB-C1B4-4E59-8765-D0786FBE9EE5}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{036B5EFA-3665-4551-8CB7-D4E01D2A08F3}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{03FE53F0-1C42-4D8D-B1A8-150BFDF8F2ED}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0411C9F1-1FB1-4FAD-B0A6-B3D839C4ABFE}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{04EE67EC-BD72-4799-856D-38667CB4EAB6}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{05708817-CE71-40FE-BBB6-9766D042C5AE}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{057390FB-327D-4A39-B0F8-5AB01C549D9B}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{05970191-03D0-4EE1-BD20-E4CBEE1EA2F1}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{06027080-D7DB-404D-96A6-412678F6BFA4}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0605C1C6-ABFC-4A8D-9A93-49D56370745E}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0630CC01-95FA-4622-B135-DA56BF547092}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{064D2B79-B7CD-4198-8CE3-91D6C0D4B40B}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0677728E-34CF-4BFF-BE39-9BFBA6FC29D3}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{069D4DBA-B5C3-4B67-83B1-AC77DA87CFA0}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{06E5BB10-9CF6-440A-9697-E2DC22C224A1}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{075D5E07-5987-4D2A-AFE3-832F5B4CF12F}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{076D33B9-6B75-4CFD-819B-3BBE6F4D896A}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{07DC312F-F5DE-45B0-BD7B-09088834F7CE}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{07EC827C-4D80-4C66-9332-4A369617177A}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{080277EB-F186-41CE-8B54-0669E6D7BE72}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{08196051-98D5-44C3-B36B-5D1B6691DA41}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{081E180E-476F-426D-BFA6-7F1386308A34}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{083E600A-29AE-46E3-A13F-1DE297B61D92}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{088B444C-F455-4F8E-96FE-8EC176F6571D}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{08AFF2BD-FA99-4511-A21B-0CF5C6C434A4}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{08D226DE-A991-4A17-9254-7C34F733DEA5}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{090A7BE9-C946-432F-AA9E-50BB8DB34BE0}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{091D7CE3-BF4B-4CDC-83CE-721F91395BE1}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0937CA7C-1A12-48F1-A58C-B3413D2EE7F4}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{095C0334-2C38-41D6-A333-E65B961376BB}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{099FAA00-00EB-4348-A6C3-5C743B4C7A22}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{09C773AE-5EA1-4C5C-8074-A697441BD7D7}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{09E90761-9F00-4766-8701-74EAEBF870A3}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{09EDC2C5-8B1F-4854-853D-BA02EF13D971}

Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0A406655-C1C7-407E-ADCD-146B37FD7BD7}

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...