mercycle Posted January 3, 2014 Posted January 3, 2014 I had a problem with win 7 opening files on its own in fact the only way I could stop it is by shutting down which it done by itself when I held the pointer over the close down button. I then tried to restart and it came up with disc reading error press Ctrl, Alt, Del. It done this about 12 times and then started as normal. I thought that I should run Malwarebyte which showed 100 hits only 2 had ticks beside them. They were Trojan.Agent F (file) and Trojan . Agent F (Registry key ) all the others are Pup Optional with letters C, I, and S after them should I tick all and what do I do after that. Quote
KenB Posted January 4, 2014 Posted January 4, 2014 Hi Until the security experts log in could you update MBAM - run it again - let MBAM deal with what it finds then post the log here please. If you click on "Logs" and click on the most recent it will open in Notepad. You can copy it from there. Quote There is an email going around offering processed pork - gelatin - and salt in a can ......this is simply SPAM !! MiniToolBoxNetwork TestWireless Test
Starbuck Posted January 4, 2014 Posted January 4, 2014 which showed 100 hits only 2 had ticks beside them. They were Trojan.Agent F (file) and Trojan . Agent F (Registry key ) Trojan:W32/Agent is a very large family of programs, most of which download and install adware or malware to the victim's machine. Agent variants may also change the configuration settings for Windows Explorer and/or for the Windows interface. So without seeing the MBAM log, it's difficult to say exactly what the report is referring to. Please post the full report as asked for by KenB. Thanks. Quote Member of:UNITE
mercycle Posted January 4, 2014 Author Posted January 4, 2014 Heres the log http://www.malwarebytes.org Database version: v2014.01.04.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Eddy :: HAL [administrator] 04-Jan-14 5:17:39 PM mbam-log-2014-01-04 (17-17-39).txt Scan type: Full scan (C:\|E:\|G:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 448162 Time elapsed: 1 hour(s), 16 minute(s), 33 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 10 HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. HKCR\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1} (PUP.Optional.Conduit) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\MixiDJ_V30 (PUP.Optional.MixiDJ.A) -> Quarantined and deleted successfully. HKCR\CLSID\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MixiDJ_V30 Toolbar (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. Registry Values Detected: 4 HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: =´"�î0?@›ú<É›�*Ý -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: MixiDJ V30 Toolbar -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{1122B43D-30EE-403F-9BFA-3CC99B0CADDD} (PUP.Optional.MixiDJToolbar.A) -> Data: -> Quarantined and deleted successfully. Registry Data Items Detected: 1 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs (PUP.Optional.Conduit.A) -> Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll) Good: () -> Quarantined and repaired successfully. Folders Detected: 28 C:\Program Files (x86)\SearchProtect (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\Main (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\Main\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\Main\Logs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\Main\rep (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\SearchProtect (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\SearchProtect\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\SearchProtect\Logs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\SearchProtect\rep (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\UI\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\UI\dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\protection (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\settings (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\rep (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30 (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. Files Detected: 135 C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (PUP.Optional.Conduit.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll (PUP.Optional.Conduit.A) -> Delete on reboot. C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll (PUP.Optional.Conduit) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\MixiDJ_V30ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Conduit\CT3289075\u*******Control_v6AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Conduit\CT3298566\MixiDJ_V30AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\+TQaFx+8.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\B+XCgdIy.exe.part (PUP.Optional.Installex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\checktbexist.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\et75BXD0.exe.part (PUP.Optional.Installrex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\h+QDPKCQ.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\JCqIN+4l.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\nsa8978.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\nsaD38F.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\nsfDDBF.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\nsq778B.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\nsu5D37.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\nsvB1EF.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ooLTqI8C.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\pKp+x3Wv.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\sbn5ymn6.exe.part (PUP.Optional.Installrex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\SecondStepInstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\To50oUdZ.exe.part (PUP.Optional.InstalleRex) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\AU\SPSetup.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\chLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\ffLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\spch.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\spff.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Windows\Temp\nsb8940.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Windows\Temp\nsg8826.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Windows\Temp\nsw8AA5.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Windows\Temp\nswD5EA.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\EULA.txt (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\mconduitinstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\CT3289075.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\CT3289075.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\dtime.csf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\initData.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\manifest.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\CT3289075\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\chromeid.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\CT3298566.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\CT3298566.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\initData.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\manifest.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\setup.ini.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\Eddy\AppData\Local\Temp\ct3298566\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\GottenAppsContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\hk64tbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\hktbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\ldrtbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\OtherAppsContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\prxtbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\SharedAppsContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\tbMixi.dll (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\toolbar.cfg (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\ToolbarContextMenu.xml (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. C:\Program Files (x86)\MixiDJ_V30\uninstall.exe (PUP.Optional.MixiDJToolbar.A) -> Quarantined and deleted successfully. (end) Quote
Starbuck Posted January 4, 2014 Posted January 4, 2014 Hi mercycle Thanks for the MBAM report. As there seems to be quite a lot of adware on the system, i recommend running some dedicated Adware removal tools. Best to be safe than sorry. Step 1 Please download Junkware Removal Tool to your desktop. Shut down your protection software now to avoid potential conflicts. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator". The tool will open and start scanning your system. Please be patient as this can take a while to complete depending on your system's specifications. On completion, a log (JRT.txt) is saved to your desktop and will automatically open. Post the contents of JRT.txt into your next message. Please download AdwCleaner by Xplode onto your desktop.Close all open programs and internet browsers. Double click on adwcleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator. Click on the Scan button. AdwCleaner will begin to scan your computer. After the scan has finished... Click on the Clean button. Press OK when asked to close all programs and follow the onscreen prompts. Press OK again to allow AdwCleaner to restart the computer and complete the removal process. After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically. Copy and paste the contents of that logfile in your next reply. A copy of that logfile will also be saved in the C:\AdwCleaner folder. In your next reply, please submit: JRT.txt AdwCleaner report Thanks. Quote Member of:UNITE
mercycle Posted January 5, 2014 Author Posted January 5, 2014 (edited) I done another Malwarebyte check today after yesterdays one's cleanup and it's come up with Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2014.01.05.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Eddy :: HAL [administrator] 05-Jan-14 2:54:00 PM mbam-log-2014-01-05 (14-54-00).txt Scan type: Full scan (C:\|E:\|G:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 447284 Time elapsed: 1 hour(s), 13 minute(s), 53 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Do I have to do the other stuff still or has it been cleaned to a shine. Edited January 5, 2014 by mercycle Quote
Starbuck Posted January 5, 2014 Posted January 5, 2014 MBAM is not a dedicated Adware remover. I'm betting that the 2 programs i requested will still find entries. Quote Member of:UNITE
mercycle Posted January 7, 2014 Author Posted January 7, 2014 here's the first part hisisu Version: 6.0.9 (01.01.2014:1) OS: Windows 7 Home Premium x64 Ran by Eddy on 07-Jan-14 at 16:10:07.04 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [service] wcuservice_stc_ie Successfully deleted: [service] wcuservice_stc_ie ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthelper.exe Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\viprotocol.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ige****ttings Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\s Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2786678 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3289075 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3298566 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_u*******_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0DA562E7-0C1E-4F3E-8E79-DE8B45D5A77E} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96f454ea-9d38-474f-b504-56193e00c1a5} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{96f454ea-9d38-474f-b504-56193e00c1a5} ~~~ Files Successfully deleted: [File] "C:\Users\Eddy\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage" Successfully deleted: [File] "C:\Users\Eddy\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage-journal" Successfully deleted: [File] "C:\Users\Eddy\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com" Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\nsprotector.js" Successfully deleted: [File] "C:\end" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\big fish" Successfully deleted: [Folder] "C:\ProgramData\big fish games" Successfully deleted: [Folder] "C:\ProgramData\premium" Successfully deleted: [Folder] "C:\ProgramData\splashtop" Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\big fish games" Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\getrighttogo" Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\splashtop" Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\thinstall" Successfully deleted: [Folder] "C:\Users\Eddy\AppData\Roaming\w3i, llc" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\big fish" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\conduit" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\cre" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\searchprotect" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\local\thinstall" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\locallow\conduit" Successfully deleted: [Folder] "C:\Users\Eddy\appdata\locallow\pricegong" Successfully deleted: [Folder] "C:\Program Files (x86)\conduit" Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec" Failed to delete: [Folder] "C:\Program Files (x86)\splashtop" Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{001BF517-B6EB-4DE7-9649-CDDD536107A0} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{002DDDA5-91D4-4F0C-92E3-0E0C2F6F81BF} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{00809BE5-93EC-4BD4-A7AF-8E32583ACF78} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{009A5612-F0C6-4F6A-832B-242660947AE2} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{00A34625-AE76-40A4-AEB0-9C7FA720F08E} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{012C8843-3D37-4AD0-A24C-19BCFC80BFF2} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{01C5652A-5E90-4BAC-A87B-EA1E014E95B2} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{01E2E6E9-995E-44B0-8C39-93FCE9DA6266} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{02262F57-30B0-4F51-8823-AB84DB1A4209} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{022B0FFA-0E89-4109-9486-B6470D0BFBE8} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0258F588-43F1-4603-8470-99FD9D8301CA} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{02AB8FEC-0005-4E0E-9125-29BBC78BAC3D} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{02B71CDB-D8D4-41F9-8A26-B33AF1E13F63} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{031D01A8-9A23-4B65-9277-5E0ADE108DD1} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{033690BB-C1B4-4E59-8765-D0786FBE9EE5} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{036B5EFA-3665-4551-8CB7-D4E01D2A08F3} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{03FE53F0-1C42-4D8D-B1A8-150BFDF8F2ED} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0411C9F1-1FB1-4FAD-B0A6-B3D839C4ABFE} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{04EE67EC-BD72-4799-856D-38667CB4EAB6} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{05708817-CE71-40FE-BBB6-9766D042C5AE} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{057390FB-327D-4A39-B0F8-5AB01C549D9B} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{05970191-03D0-4EE1-BD20-E4CBEE1EA2F1} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{06027080-D7DB-404D-96A6-412678F6BFA4} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0605C1C6-ABFC-4A8D-9A93-49D56370745E} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0630CC01-95FA-4622-B135-DA56BF547092} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{064D2B79-B7CD-4198-8CE3-91D6C0D4B40B} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0677728E-34CF-4BFF-BE39-9BFBA6FC29D3} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{069D4DBA-B5C3-4B67-83B1-AC77DA87CFA0} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{06E5BB10-9CF6-440A-9697-E2DC22C224A1} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{075D5E07-5987-4D2A-AFE3-832F5B4CF12F} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{076D33B9-6B75-4CFD-819B-3BBE6F4D896A} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{07DC312F-F5DE-45B0-BD7B-09088834F7CE} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{07EC827C-4D80-4C66-9332-4A369617177A} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{080277EB-F186-41CE-8B54-0669E6D7BE72} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{08196051-98D5-44C3-B36B-5D1B6691DA41} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{081E180E-476F-426D-BFA6-7F1386308A34} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{083E600A-29AE-46E3-A13F-1DE297B61D92} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{088B444C-F455-4F8E-96FE-8EC176F6571D} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{08AFF2BD-FA99-4511-A21B-0CF5C6C434A4} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{08D226DE-A991-4A17-9254-7C34F733DEA5} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{090A7BE9-C946-432F-AA9E-50BB8DB34BE0} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{091D7CE3-BF4B-4CDC-83CE-721F91395BE1} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0937CA7C-1A12-48F1-A58C-B3413D2EE7F4} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{095C0334-2C38-41D6-A333-E65B961376BB} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{099FAA00-00EB-4348-A6C3-5C743B4C7A22} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{09C773AE-5EA1-4C5C-8074-A697441BD7D7} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{09E90761-9F00-4766-8701-74EAEBF870A3} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{09EDC2C5-8B1F-4854-853D-BA02EF13D971} Successfully deleted: [Empty Folder] C:\Users\Eddy\appdata\local\{0A406655-C1C7-407E-ADCD-146B37FD7BD7} Quote
Starbuck Posted January 7, 2014 Posted January 7, 2014 That's a bit more like it. Now you can see the difference that a dedicated remover makes. Quote Member of:UNITE
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.