infected with linksbucks virus (i need help to remove it)

Discussion in 'Windows - Virus and spyware problems' started by xboxdvl2, Nov 16, 2013.

  1. xboxdvl2

    xboxdvl2 Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,174
    Likes Received:
    7
    Trophy Points:
    48
    hi guys
    my computer is infected with linkbucks browser redirect.can anyone tell me how to remove it please.if extra info is needed let me know

    i have been to a website which said to delete the following,
    (i only found the 6th in regedit).
    %appdata%\protector-%\{linkbucks}.exe
    %appdata%\result.db
    %AllUsersProfile%\{linksbucks}*.ink
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Regedit32
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\{linkbucks}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current\Winlogon:\"Shell"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Inter Explorer\Toolbar"{linkbucks}Toolbar

    also said end the process linksbucks .exe which im not finding.Also website said it might be hiding as csrss.exe but according to a google search thats an important system file,i have 2 of them 1.s an exe file and 1's a dll file.

    any info to solve this problem would be appreciated.I'm not very familiar with reg edit but if needed i can look in there and delete files if required.thanx in advance for your help
     
  2. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hi xboxdvl2,

    Linksbucks is not really considered as malware but, it is usually bundled with other Foistware that could have a Trojan or other malware.

    First download and run Malwarebytes Free if you haven’t already ran it. Then post a copy of the Log and we can see what else you need to do to get rid of it.

    MBAM Free Here:
    http://www.malwarebytes.org/

    if you have ran MBAM and have the Log, please post it.
    TNX
    2oG
     
  3. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,167
    Likes Received:
    136
    Trophy Points:
    143
    xboxdvl2, what browser are you using?
     
  4. xboxdvl2

    xboxdvl2 Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,174
    Likes Received:
    7
    Trophy Points:
    48
    i use chrome or waterfox.
    MBAM found 9 malware and removed them.
    i have the log here aswell

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 9:34:36 PM, on 17/11/2013
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v10.0 (10.00.9200.16736)
    Boot mode: Normal

    Running processes:
    C:\Windows\vsnpstd3.exe
    C:\Program Files (x86)\Steam\Steam.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\Ask.com\Updater\Updater.exe
    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
    O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
    O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
    O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
    O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
    O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - Startup: ACR Launcher.lnk = C:\Program Files (x86)\ACR\AutoClubRev\web\acrlauncher.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
     
    Last edited: Nov 17, 2013
  5. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    xboxdvl2,

    Hijackthis is no longer able to find problems in Chorme or other browsers. It however does show that you are infected and do not have an AntiVirus installed..

    Please run the following cleaners and Post the Logs so I can help you remove ALL of the infection.

    -Security Check-

    Download Security Check by screen317.
    Save it to your Desktop.

    Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    A Notepad document should open automatically called checkup.txt; please post the contents of that document.




    --AdwCleaner--

    Please download AdwCleaner by Xplode to your Desktop.

    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Delete tab follow the prompts.
    • A log file will automatically open after the scan has finished.
    • Please post the content of that log file with your next answer.
    • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).



    [​IMG] —Junkware Removal Tool--

    Please download Junkware Removal Tool to your Desktop.
    Please close your security software to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete, depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
    • Please post the contents of JRT.txt into your reply.




    --RogueKiller--

    • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
    • Quit all programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • For Vista or Windows 7, right-click and select "Run as Administrator to start"
    • For Windows XP, double-click to start.
    • Wait until pre-scan has finished ...
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and copy/paste the content of the Notepad into your next reply.
    • The log should be found in RKreport[1].txt on your Desktop
    • Exit/Close RogueKiller+


    Please paste the logs in your next reply.
    Let me know what problem persists.




    After running the Cleaning programs then Please download and install an AntiVirus program. I suggest Avast Free but it is your choice. http://www.afterdawn.com/software/security/antivirus/avast_free.cfm


    Then, run OTL which is a very powerful tool to remove any infections and leftovers that the cleaning programs miss..

    --OTL--

    Please download OTL by OldTimer to your Desktop.

    If you already have a copy of OTL, delete it and use this version.

    Double click OTL.exe to launch the program.

    Check the following.
    Scan all users.
    Standard Output.
    Lop check.
    Purity check.
    Under Extra Registry section, select Use SafeList
    Click the Run Scan button and wait for the scan to finish (usually about 10-15 mins).

    When finished it will produce two logs.
    OTL.txt (open on your desktop).
    Extras.txt (minimized in your taskbar)

    Please post me both logs


    2oG
     
  6. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,167
    Likes Received:
    136
    Trophy Points:
    143
    also will want to get rid of these.
    C:\Program Files (x86)\Ask.com\Updater\Updater.exe
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
     
  7. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    come on ddp Never remove Anything with HJT before running a cleaner. It takes away the reg keys and the Cleaner cannot find it.....

    HJT just removes the key NOT the program!
     
    Last edited: Nov 17, 2013
  8. xboxdvl2

    xboxdvl2 Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,174
    Likes Received:
    7
    Trophy Points:
    48
    security check log

    Results of screen317's Security Check version 0.99.77
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 10 Out of date!
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Microsoft Security Essentials
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.75.0.1300
    Java 7 Update 45
    Adobe Flash Player 11.9.900.117
    Adobe Reader XI
    Mozilla Firefox (25.0)
    Google Chrome 31.0.1650.48
    Google Chrome 31.0.1650.57
    ````````Process Check: objlist.exe by Laurent````````
    Microsoft Security Essentials MSMpEng.exe
    Microsoft Security Essentials msseces.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````

    adware

    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16736


    -\\ Mozilla Firefox v25.0 (en-US)

    [ File : C:\Users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\hbf4qyq1.default\prefs.js ]


    -\\ Google Chrome v31.0.1650.57

    [ File : C:\Users\Greg\AppData\Local\Google\Chrome\User Data\Default\preferences ]


    *************************

    AdwCleaner[R0].txt - [2904 octets] - [18/11/2013 06:29:53]

    ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2964 octets] ##########

    Junkware

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.0.8 (11.05.2013:1)
    OS: Windows 7 Home Premium x64
    Ran by Greg on Mon 18/11/2013 at 6:35:22.26
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}



    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2504091
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASMANCS
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{16C8C46E-C811-4977-BF0A-B5CC1FA78D95}



    ~~~ Files

    Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npcouponprinter.dll"
    Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npmozcouponprinter.dll"
    Successfully deleted: [File] "C:\end"
    Successfully deleted: [File] C:\Windows\syswow64\RENA6D4.tmp
    Successfully deleted: [File] C:\Windows\syswow64\RENA6D5.tmp



    ~~~ Folders

    Successfully deleted: [Folder] "C:\ProgramData\trymedia"
    Successfully deleted: [Folder] "C:\Users\Greg\appdata\locallow\conduit"
    Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
    Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{00F57622-B31D-4691-83AB-1D06345B01D7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{01067197-67D3-4426-9555-A9A33D50E5C4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{02D7D91A-730A-4323-AA83-5D498882A5BB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0319D4BE-0F68-47FA-BC72-5DAE8ED637A2}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{037545C8-DE62-443F-BF94-1B4C0A9DE033}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{038CF2C3-DC2E-4138-9273-0F12C0660F4D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{038D287B-D67C-4FDB-A891-DCBE57FA7D4A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{04305D12-712A-418C-872B-084B1BEBD0A3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{04EEA9C8-95FA-4750-9850-55801B0E541B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{06855D2B-38A6-421F-AA66-9995A84552A6}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{06FC380D-20A1-467B-86D8-946383B96D5A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{073A2AFC-2E8D-4AAA-9276-5E7171C86FF9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0755497C-19A8-4579-B378-D155370A84B8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0842DCA1-54E3-4B32-A8B2-75010F398E17}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{08EB4CE4-99A9-420B-8D81-34787E0E93BC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0A678479-2F83-4FE7-9135-989E0837F9A3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0ACAD1BE-E3BC-481F-AB71-546F76AF956F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0B5A442C-6743-4852-9BF0-5925D5CA1E66}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0BCC189D-1576-4B07-B09D-09DF386AE001}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0C5C4F11-3530-4379-AFE8-2CFDE98F8AA6}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0CB8DD89-9562-48FD-8675-CCA7A1457E6F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0CC9765B-6317-4983-BBAA-7213DEF64083}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{0CEE2202-A1A0-494C-86E2-4A4DD1D22716}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{10D6E795-6F9F-4C4E-B2F5-FBCDA868675C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{121D4732-0543-465D-8426-5470C9748581}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1394E94E-4D92-4809-999C-1FF55EB73F83}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1401BA99-EED2-4AA9-BB43-B9662DA9EB88}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{140CC09B-9CD9-44C8-9A31-EB54992DB1B9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{15886149-89A8-4A31-ABBF-21674BA82050}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1724557B-1EC4-41DE-8ED5-CC4B6F10BC17}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{198F66B9-BC48-44BF-9E22-EADCF8AE5D9A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{19E722DB-F021-484C-AD52-87CB4FD596BD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{19FD5CD5-A2DE-4CF6-95E9-382D5E953A19}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1A32CC55-353F-4C73-A59C-572CBD9916B0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1A3B7CD6-8C75-48C2-A29D-D938F56CBBE7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1AF7D1DC-7C27-4730-A181-D5C8D72309A0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1B63B084-6D3A-4F5C-BF42-4DE3BC5F15A4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1B68C15C-0D2C-48B5-B638-DF9952774AE8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1C535131-F6EF-4A3B-B725-7C6C1813E37A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1DCE6DD7-FA06-4764-B714-75E200D0A986}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1E22E32D-2592-4C88-965A-C4FE076E3F6F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1EAA3769-3D1E-4F34-B2A0-20C92DAA1B51}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1F736915-B011-454B-A484-7101F77E4E50}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1F7A06DE-F441-46F8-B57E-CFA0F482FE9B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1FC75D31-88E1-4AF5-9129-232E3675B08E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{1FEE0648-38AA-49F4-AE39-F0C8A818E46F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{200E34C1-C61D-43DF-BE9B-5E0E101963D5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{20DE9CD3-12FD-494A-8221-12CF58ACCFAB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{213098C3-11E4-4D81-BBB4-AD858B807732}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{21676CD7-41D7-48BF-A58F-7C81FCEB1A32}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{21730726-2E96-41D3-A669-56E978C6DA64}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{21CAFDC5-787C-4242-B637-601540162D4B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{22CA012E-0D8E-4F32-8EDE-CC66B3D5DDFB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{23608314-C915-4DF6-90C4-FBC52356EB48}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{23883D47-FA10-45A9-8E8E-F3DDD8394A95}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{23B662E7-4099-4B4E-8F99-8F2AF25BB9F9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{242B8EA1-CCD3-470C-AB4B-1F4187DA8472}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{243C6D77-865E-459E-8944-B47A86AB6DED}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{24AC7625-B5A4-489D-91CB-468E2190A546}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{24B9FD0C-AEA7-4CFC-8286-57C3027DCA2A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{25CDCD50-1104-4774-9BAE-427DB297E9DD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{270AA132-A21D-44A5-AE2B-F33200BF4CCC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{28D5A55E-BBD6-4B60-A9FA-E9BA61666BAB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{296343ED-C9CC-4912-B8EC-B8B935DE94CE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2A41E075-CDE3-4876-A109-64B36393C100}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2AD89E00-B4F3-46EE-AE5D-D565B14AF92E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2B4C432F-BCB1-4B5D-9342-D1BD45CC5555}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2C7022D2-3A6B-4819-9692-453F43F7A52A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2C9838D3-E80E-45EF-AA61-AD4DD52234A7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2CC5F367-4037-40E9-8C87-0A2A8CA9B14F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2DFE7301-4915-4196-BB6A-0D654FEBA4AD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2E4F5790-CD94-4453-B943-9CBD7CDA856E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2EBEA41C-5F94-4D11-82E2-BAAAA9456211}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2F1D6BAF-A6F5-41F5-9A8D-AB83296803C1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2F7176F3-5EA0-4EF4-A3FD-6B2206DC394F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2F9A3103-7A31-4F85-B276-A1FBF058DE2E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{2FDC671B-DE31-4CE7-B79E-A287EE7B9491}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3027BA49-C54D-43B7-AD93-6024B44D5F36}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{30E62084-658A-4386-B668-B96D099002AD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{31C888B0-8990-49D0-9E26-4EB8E32A7559}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{31CF799C-D8E6-4546-8639-DF90D05A9AB9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{32472329-87EB-4700-96C7-6929A40E8981}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{32ECFE45-222C-49B3-9EFE-4ECCD14B4AF4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{330B0D9A-0AF2-4E22-A68F-C3AA740F92F8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3370A387-85C8-4BEA-9DC4-901316946B86}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{33A1FB87-392F-4FED-BFDB-4DCB68A19F60}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3509EB2A-7A59-455C-A5EC-BC062B47B14B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{352F6AAC-AEB4-4AAA-A2B5-4E64A6CC8329}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3687D92A-E66F-431A-BA4E-DE971A284565}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{374A3949-5E5A-424B-85DE-4A56F50D1B8D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{37514002-6114-4972-8601-D8EEC247CDC1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{37CC303C-4A6C-46CF-8343-426DDFFD45CB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{37E014C1-66F6-4B8C-8DD0-648AD45F5C35}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{37EA7D03-322F-4014-B272-F25A65F4FA6E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{38959491-20B0-4BD0-8D98-47021046E950}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{38B74807-9A2B-4A62-BE04-DB7E5BCD5287}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3963355B-DE16-45CC-8AD0-6C434EAD344A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{39C75C71-45CC-490A-9F30-0C4448974C4D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3A73A177-ED1F-4216-B313-0651FDB61F40}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3ABA84D9-ED28-4325-A92A-39EAE0B9090B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3BF1F28E-10A1-4F80-B388-D7D83222DD7D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3C1D1358-53BB-41A5-A15A-5034204B76A9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3C23CDD8-3857-4412-B918-A84203EF2BD9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3C8FC3E4-C147-46FD-9158-EB623873514A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3CFF907B-DFDE-4D13-848C-C91423D74CCC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3D854D09-62E3-4918-860E-018C02533388}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3DEDE2B1-F7F3-4350-AFD0-BCAEE2B33D5E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3E6C128F-33CB-4DC9-92B3-16E2262ECC2C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3EE1FBB1-034F-444D-847D-F20697B1596F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3F0A0440-ED9C-4CCB-94F5-B65C56E6D211}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{3F217EB3-6B50-4EE3-A9F4-609F00EEDBE8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4058E37C-EE64-435F-A0C2-0610653BFD86}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{415BE5F7-14CA-4603-8FF8-E3E0F83FD1B7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{41629666-691A-4CDC-8308-3A33EBB5BC81}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{42163BC8-0007-4258-9017-B320FDAA0BA9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{424DDC90-41D9-44A6-87EE-0F5ABF0CF957}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{429FC5F9-52F8-4340-9689-EA36105B050F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{42E90ABE-CCB8-43F5-B4B5-EE1DB437956E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{43E402EB-098D-40C5-9A70-46119D156D41}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{43F2C444-D750-4015-8785-FF60CB8091FA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{442CEBE1-A4C6-4C24-BFFA-E04E89C232AB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{447AC96B-88EB-4170-8DEF-8C7CD74EF0F1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{45B6FE36-CDB8-45B8-98CB-51AB3878C8D2}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4719DB39-7F6A-41E7-BF08-3FEA23318F0B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{474C595E-9CFE-4A23-9C9B-201FA7AB50E7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{47A55669-7FF7-4288-AEE0-4A90AF695C97}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{47BE7606-34CC-4095-91F0-C22EB4BBD94B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{48105F44-719D-4522-9EBF-B0D19C1329CF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{49317419-13A1-4CE6-B5D9-5DC1CA3790F3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4A2A7D5B-6B91-4CC8-9122-63D7DDC7B324}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4B58B7ED-DDBA-42D0-8A66-64A94AF06B46}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4BB8411C-76F1-48DC-ADB6-83259CBDD1F4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4C58F4C3-4BF4-43E6-91F6-6640DCF55805}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4CD0B6ED-A682-4061-8129-444135D1F44F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4DE6F058-ACDF-4565-A354-9E1AFCB04389}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4ECBB9F7-14DE-4F16-AEF3-6DEDFECE1AE8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{4EE72E77-C2D9-4503-B574-09B1C7C19DEF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5008FECD-3B6E-452B-97F5-D0D293ABF453}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{50509C20-AB19-47A4-8867-1CE862F8CCE5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{507AF33E-7D1F-4A41-A4C1-C4320C08B2AE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{508A6B0E-E0BA-478C-8FD0-A995B6400527}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{50CFF5B4-C2AD-4C97-9308-C28BFAA35721}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{51A2A04C-F112-41B7-A542-1E2333964329}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5251D3F6-05AD-4074-9232-6F012CE46797}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{525368D8-66F1-4C14-BF5D-391F3E747905}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5354663A-BDB5-4A6A-9480-290905D0F15B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{540F6515-29B3-4B10-B974-E2BB962373EE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{54E9F708-74B1-4135-8446-BDD4964F8A80}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{55003705-7D25-434B-9851-2E819774FB54}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5502F730-8E9B-49D6-B6AC-5ADF13927A75}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5544D24F-83D5-468F-8A48-32595C873E2F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{56B5D378-5ED9-4082-8959-91EF31826970}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{570D124A-1D96-44B4-A374-C93CB0AD65E9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5750A81E-8D93-4B3B-A407-35B079754279}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{580A55F4-E3DA-466B-BC18-EDBC904EA66B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5845EAE0-FFDB-4502-97A8-68629469397B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{587675F2-B397-472B-A5A4-A85D3FC53D5D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5A00BC82-449A-45E6-937B-9E0369BB9E69}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5A24B5E9-BD64-4BF1-9D68-3912CBEF2DAD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5A37AB50-6665-439C-BA9C-E97F55FF08EE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5A561197-BEEB-4D69-8777-EAF9B013DDFC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5AD1F78D-04A8-4D3D-A01F-634F8843FE16}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5B0D2438-83E3-4E5F-9773-2453FE646EAA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5BB9C5B0-8DAE-48F0-88E7-0A843E08C50E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5C285E20-D717-49E1-9DC3-4B9DA827DC8E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5CA843B8-1DEA-4DF9-9BF4-3A84FD592A7D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5D2BF6BC-104F-4749-8430-56FCC8EFCA64}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5DC8389A-E089-40FE-AEF2-A08D92173FE0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5E044BE0-2244-4160-A0C2-E34620FBE70E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5E9DE1D1-0792-4C5E-8D46-47ADCA3FDE5B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{5F1FB0B9-E3AE-416A-8474-50835AFA6313}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{60E80FA2-DFAC-4828-82F6-2822FC7ADFB7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{60F2F91C-0AB3-4D97-AD63-DCBF3D77807D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6134F61E-2656-4E66-B5DB-94F8CCBEBD72}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{618586EA-6CC5-4990-95DD-75F29B55AD3D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{61A682EB-A26B-438B-82C6-309CCEEB35CA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{61F7ECD7-78B4-4CBF-AD79-BC561F92F1E4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{63567DDE-A300-420D-9A0A-6704A39E126C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{63D30DD9-8B19-4130-810F-A0E2ED2DF418}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{64B8B43C-8C7F-4A6B-89A4-4A251C2BCC52}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6598C9A0-7213-4B01-B3C9-D3C95A5ED5B4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{65FBB829-1F03-4001-99FB-563298A1FFA4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6736638C-5B74-404E-8B60-C0B79F15D54D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{67D14037-A21A-4DA3-9A9C-E517ED65FA1D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{67DD2548-2902-4791-890B-06917EA5A17B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6809A884-036E-43A6-8C37-00AB8F7329ED}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{68B0D0BF-3EEE-4B8C-9E5A-B998022CD21F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{68F1A875-3EBE-42D7-9DC0-86A4D329F082}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{690269AC-2012-42B2-A919-464979005328}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{69219DD3-BC4C-432B-ABD8-AE2FD9B545F3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{695600F4-D201-47E4-ADD3-5F2489743F4C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6A041AF0-8A60-4596-8C49-CF6B39BF2EDB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6A105BD0-2319-4D99-9426-A2F7EE03DE82}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6A7BF546-EFA8-4518-B9D6-6579EBDECC1E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6AF5C6C3-629B-4F1F-BAEF-C59DE86322BC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6B00DA0C-C259-408F-9185-CCB4E23D0CD1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6BA045E6-687D-4C10-AA21-B90625EFE381}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6DC7A7BE-8BF7-4945-A758-773CBBE3F8A5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6DE50A4B-02FA-493E-8805-1AB421263BC2}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6E545CFC-4D24-4EA5-8F0A-E67D78138A89}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6EA30855-3358-410E-8E3C-CA4F12DB58B5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6ECA157B-1928-4C0A-9E81-5135236815D7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6EDD7BE7-B301-4387-A77C-85AAA79E123F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6EFE4D56-F3EA-477B-8044-B8896E6DD2D1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{6F55C79C-E59D-4223-9D98-50F209CE64D4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7013FA9B-FA40-4408-8731-F88F6ECFB71E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7087332A-E90E-4327-8E30-B6C7B409663F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{71A63B5E-7846-407A-A8A8-CEFF00E34848}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{721A7E02-BDBA-4BEA-8396-72715DDD7035}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{721E6A78-C4E3-4A47-9559-BA1B6C7A5D8F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{72D1EA43-1CAA-449D-A955-873107B50507}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7385A76D-80AB-4D48-8B4E-BF8DCF8D8AB3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{73D39DB9-DB89-4CE4-AA92-E3D9ED6A8A0C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{76B65D0C-EEE0-470E-A57B-41D8ADD225C5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{77EAC34B-2D7F-4CEC-B8E1-A2A13C0242B8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{787D664B-5208-4AEA-8756-138E6D32A07E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{79A73F62-0157-4DB2-828B-A739EFB9A3BF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7A579C68-CA0D-4C81-9BBC-11CC6E4DBAE4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7A961716-0167-489F-BE9A-DCB8928DFF1E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7BCDBCF8-7559-4810-AFF5-1B22762137C3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7CCE1CB8-3DA7-4DCF-A686-948DF04B1192}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7CF388FE-752C-469D-B126-37705F1BDAD9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7D568E77-FD0C-4795-B607-FC2722683746}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7DED8A66-ECA4-4CC9-A893-7FF96D01D615}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7E3042B7-0986-49ED-98DB-7E6CEBCCF2E7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7EA7665B-4752-4928-8AA3-28D8812B26A5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{7EE89E69-9E17-43DA-B04D-02158B07CC27}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{804A9D1E-CC08-4698-80C7-55D2846D7A97}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8098B918-B5BB-4AED-9758-1A2341829F21}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{80AA9FA0-DA1B-4570-9E0D-7F3677BC4687}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{80C341BD-BAB4-4BD0-BD53-9EE44A0299CA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{818EDFD0-F1EF-4DBD-9B1D-C62044DBBF78}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{81DACB0A-48EF-4F08-BBF2-11DA1E6DC9BB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{85717BFF-6560-4A20-92E3-BF141DEAC031}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{858B0AD5-E3BB-447C-BE79-F6623E5C9EA3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8754A9D7-50F3-4885-A57A-90B86A0F841F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8789749B-F12E-4979-92C7-640B303C48CE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{87A04B98-8502-4F32-90D5-D82B79401A1F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{882BEF03-2C1A-4C2D-BE54-1B7043F81674}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8887DA95-7711-4B70-A6EE-4AFED21E193A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{88913596-4E73-4124-8CD6-90936625C85F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8919E5D3-10F8-42B1-A296-E9C62B13058D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{89ACE253-DD23-405B-A020-AD0F7307AC4D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{89D42504-257F-4A87-B568-0065F5299F47}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8A7F5758-D0B9-4058-BB25-919D975CCC9F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8AB806C4-428D-4DA4-B95F-7126030DF5D8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8BF90148-F459-4513-88D5-F5DDC975FFCF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8BFAFC12-D0C1-4084-92E0-9E269EAEFF9E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8C6A1400-9BC8-4FE1-8F7A-33DE57E89BF6}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8C7C47CA-360B-43FF-91F2-F5E541EFCB4F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8CEAB877-E2F2-4FBD-8894-229A264B967B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8E85BE6B-57E8-4406-9E4D-9B615E846B78}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8F89DCB4-FA26-49A6-A39D-F67C1A45EEBA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{8FFFBFB5-FA8C-471A-A957-FFE67A6321FB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{906445DC-05F4-456B-8E3A-6C1BE12DCC20}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{90A4086B-82C5-427B-B49C-EA3CC78EEEB5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{90FB4101-508E-4A42-A07C-EE43E2B6F694}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9176325D-C995-4248-B1B2-01ECE7FF95D2}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{917BB3CC-484D-451E-B4D2-67FAD8474A6D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9185D6B7-1F62-4861-8605-1FB132960FB8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{91B0DF7C-5736-4E5B-878D-3ECF2C3AF901}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{93799B24-3E1C-4C94-ADDA-07A68D3CE494}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9499FC7A-DFBC-4BD7-ADB5-2B0349223C4D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{94F13785-AC56-4213-A8AD-A793614112A0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{96429829-9424-463E-8C0C-6976C479C619}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{969C123F-1497-4156-A662-5AC9D1226ED4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{96D82BD6-BA36-4FBB-90BB-1990367FE64E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{96EEA9B7-1D71-4026-B502-A9DF851A02E4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{97DB54F7-8291-409D-816E-23AB7001DF56}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{98E7E9A6-941D-4006-8E50-3F63BA8D2F19}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9B19831F-02A4-47A2-AA68-75E8CEAE0A44}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9BF36E7D-6D02-4F08-893B-10D093D4BFD8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9C02547B-6074-47FC-BAFB-BF8D16233381}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9CCB18E2-D209-4EC7-95C0-A4C962A27791}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9CCE13FD-DE26-484C-9923-59ED45FD902B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9D202B16-6801-449E-92EA-8E6B33AD1575}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9D3988B2-C4E6-4BE8-A052-F1FD30C18C0D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9E00488A-E58E-47D2-BB6B-7790C21888C0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{9F308388-5971-41B3-A1AA-1EA74CEBCFD0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A033819B-C5D6-412C-94B9-E3C4990B7D92}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A0FF6768-847A-4FEF-BED6-657BE435A29C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A13A8CD0-0A35-48D6-BA50-91344FF59686}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A19C85F4-EB30-4130-8AC8-B627FDA74520}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A21E2767-B7F8-4EFA-914F-91E9E04C33F3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A2E36FCD-C583-4298-ACF5-B1AD73F1A88C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A2EF245C-A6E7-4408-8F03-C5A2BF64703B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A5BE1008-F3C0-4B27-B2AB-DA1525B00013}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A697D6A2-4FE5-41EF-AFB4-0B829BF33F88}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A744A059-11E4-4C02-B59D-2F034E49CA0F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A74E3F36-E12D-4059-8E0B-8AB7018CFDB5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A8122A90-CF54-4CB9-B4A9-DF6BABD4FD5F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A8171019-397E-406A-BDB6-FC1746254E06}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A83C89F7-6C85-4286-9B09-6ECACD8F24DE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A987EF61-2EE8-4B69-91C6-30B9BD3F6C05}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{A998CDFA-EE51-4D2F-8A9C-83DDA2CB0036}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AB55CEAF-778B-4415-8E8C-CF3BC19867D7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{ABDBA036-7D21-445C-9570-109D088EAA18}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AC530958-74D2-4D95-876E-15A303D9755E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AC71AC03-8321-4CCD-8288-509F0B4925B7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{ACB77773-D1EE-4B28-8521-38A372FA22FD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AE09B326-6C50-4C4F-BD9E-91191C58E097}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AE549D4C-FD9F-49DD-86F0-F6D8DFD7A714}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AE6B60FC-1640-47EF-A5B2-19FCD14ABF28}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{AF2E32FA-0F6B-4C9F-A95A-235CEDA6D0F1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B04C585F-3285-42CE-800B-FBE392962497}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B12961D7-8B8D-4066-BC4A-7E1B4504D3E4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B1440548-EEB8-4E42-82E2-2125BC60ECDD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B14F7666-B756-432D-88B2-74D1967B0487}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B1B6D668-A8AC-4ADC-BC7C-EB3ACEAC4102}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B1C7640E-4657-4F9B-888C-50B680A96918}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B275B8A7-995C-4A3E-8B0B-6795AFCAA826}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B3D022EA-9059-44C1-B39B-463D0D996536}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B4BEEC47-BCA3-488B-B173-6F6DDCEF7E25}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B66070C3-83B1-478C-B8DF-5BD5C5DDB2FF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B6E34A5C-A007-4AD1-A66F-C55AA09CA1D8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B7CC6134-BF86-4D70-A3B9-73487875322E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B7D63955-E584-48D3-A17A-AE9581CB5D0A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B871A3CD-C681-41B6-9891-D8F98484C0D2}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B8F24FD8-F20B-4ABD-B95C-4D0731963B25}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B974A429-47C1-497B-91A7-D35FC10E3EBE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B98D6368-6B4A-49A0-9914-69B223FB7F32}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{B9A48E08-36D8-444E-B674-EFEC234BB0E6}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BAC6E80B-144E-4E1F-A563-24AEA76B2559}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BB2B51FF-3411-4F06-B979-62C89929EFF1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BB92981B-C86B-4913-ABA8-EF9D4C6FB909}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BC4D8E5F-AE09-4FBB-A5D9-9DEBEAC968CA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BCDB3C90-A50E-4FEB-9968-A18F4F60E7F6}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BD0DA829-8194-4643-927E-05B893C3FAD0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BE811C0F-68E6-4926-9F92-76EA8F53D851}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{BF870C29-4A2E-47F9-8499-559ADCA28E93}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C0524CE0-C236-4C41-A912-A2D337A0F5E0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C144780B-18A1-4BEB-BF88-C567AF1DDABE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C19AA90E-EB94-471D-A6AA-C211B6C01EA5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C1A78A80-7B8B-40F4-A236-6465061F1612}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C1E4B154-F820-4F2B-8D7A-453B76DB85A7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C21BDD1A-DFC0-4F93-B5C3-F0376DEFD5D9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C24A3660-4690-440A-9C56-D8A471797CBD}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C2F533C9-0040-469A-BBA1-21DB147976B7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C319F55B-C739-4735-A1C1-C68757646A4A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C44E1166-5340-430D-8FF7-D229FE49FE69}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C58FD89E-07CF-438F-AB30-DE4504547C5F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C64DCEE7-6673-4A6A-A750-F6297F015F2E}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C6526BE4-1459-41F7-999C-6168FB3857D9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C74AE49E-5AE9-491B-A2EC-136175A1FBE0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C7507D29-8AFB-437C-A1DA-9A0130F9C8B3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C7EF210D-445C-423E-A7A9-35B0DA2C8AF1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{C8433EC1-5B03-42AF-AF43-19CF6ECA99CB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CBADA1DF-D24A-4171-8200-9D938BA1A049}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CBD8EA18-F9F3-4AC4-9187-B715F0EDECA8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CC760BDC-120D-448C-95D5-E89724657992}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CCF5D3E8-504A-4697-8090-65D196C07BE0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CD2F9A4D-13C2-4970-B570-457C96A5A31B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CDAD0901-54B8-4767-9DB8-A88CDD49949B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{CFA0DDF7-72E0-4E4E-BF8C-83C26A78A259}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D00298E7-B0BB-46CD-BBF7-E7F87844A224}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D0DCC656-DA78-436E-80DA-51D0A16F291F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D0F173D3-A8E0-4965-802E-57EDF8FC1E88}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D1CA7B10-D998-460C-8CF0-80832E766DC4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D271687A-EE0E-48A8-9C78-8D6C15524805}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D2A77AB7-E8AB-4C83-AB7A-2B38A39560D7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D3BB7A2F-9B80-4FC4-9B3C-EF2C59382130}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D4E1C338-BBF5-4189-9A59-151FD793867D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D4E45CB1-8F47-418E-8B5D-D078275E51B7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D4F999C7-1138-4DE3-97E7-8AB8E824B0BB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D5A01C57-F8BF-401F-A859-4C28EA404F39}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D5F66CD1-803F-4143-AA5C-C44B69128C79}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D6F5877A-AE5D-4ECE-81E4-FD03CE11AE62}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D783303B-F905-4D06-BDDA-A14BEBEE1070}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D7918260-F67A-4E40-893A-FE5E107012B2}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D8D05269-F1C2-4C38-B7EC-2C82280D945C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{D947AD89-F411-4A5A-879F-4D8D516CC585}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DA94126C-F64C-49BB-97AD-41F8BE88ED37}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DAA33535-C2C4-4F3F-BFB1-D212E137CDE8}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DC291C4D-6A4E-4012-AF58-067CC77CBEFE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DCBFB5C0-AD54-4083-A13C-476B9F6CA126}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DD128AB0-70F1-466C-B4AD-840EC6AD3ABA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DD3AE9B8-DD70-46C1-8ED8-F977C75ADD44}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DD46B4E2-D99B-45AF-985F-0D5D27654739}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DE0D7C1B-3857-4DB3-8401-F9C5CBDB0608}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DEFC6741-C12A-4EC4-9B11-702EA1642797}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DF142D5F-F3D4-43C4-8ACF-45B03CBA6B43}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DF2D0E6F-F463-4D15-8CC4-D80C0F6347EF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{DFC19A71-8E09-4B15-9DA2-571AB8FF2AF3}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E0A4A088-6567-4D1C-9B9A-2B06F1C72B26}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E0A72B48-45E8-459B-B168-D4AB8EEE9C9A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E0ACB967-FBCE-4F2D-9AA8-26FD7C072C08}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E1831908-D226-4D6F-8476-AE042A016818}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E19D6409-7AC8-44FB-9911-B8A98D2745C1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E2F58745-9A9F-484A-AA2A-CB2BA59B9A16}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E3D94D66-196C-45E7-B15E-85C77909A5C9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E403503D-819E-4C26-937D-02C70F45E2A4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E4B0EC4B-68D8-471A-B719-59F7EDA8E691}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E523BA28-9550-4089-A7A1-29FBAC15A5E1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E537FCE3-05EA-4666-AC1A-C055BA6CE895}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E546CF6D-6368-46A9-A4B7-0C3DF814FA41}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E575E931-A580-4679-8C7D-9CCE2930448D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E58C7C44-3347-452A-8530-58AB53AF15CE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E5EBF5FC-0F26-486F-B156-17EAA4CF258A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E5F1EB22-F206-4896-95FB-71EDC2A39A57}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E611D4EC-6D38-44EE-ACC1-C6293EA855BC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E62389D2-B891-4442-8487-7554E20744ED}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E630BF7A-CA63-48F9-8628-AC66F9395E7F}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E694070F-0CD4-43CA-A481-2B06C93695C0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E6A418E2-CB02-4B42-B0B6-3A112EBF9943}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E6D1F34E-475A-46B6-BBFA-A93069CF3C78}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E6ECA43D-B4A1-42C9-ABB3-76555FD4EB33}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E77F3B91-ACED-4594-8729-E21C813B54F7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E783A68B-D0F9-49D9-9E39-417767AF6144}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E7D409DD-4AF4-45C5-903E-0003DCDF2B89}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E7D5AF49-53CB-41E2-87BF-17886A805B66}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E87D3B51-6310-4656-B0CF-DB609E1A4722}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E8821984-845D-4DE5-8F9E-F0D7399AA00A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E8CCEE8E-914A-4F09-99C2-DF958DDF14BA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E9B226BF-F926-4779-9046-A21696140356}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{E9CFADD8-EA26-44D4-AE3D-74054A1C252B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EA01C450-D3AE-4B6C-B602-42369D72C314}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EADF74A7-D366-4C95-AE85-A560F6E5416C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EB11D128-3A66-4841-979F-52BF8C18E4A0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EBE457F9-A250-4CC0-A184-2887B4DD7E71}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EC64714C-080E-42C7-B237-65748A65F6D4}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{ED1E0CE5-3B60-4CAF-994D-5AEAC018D14B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EE0507AD-1759-4973-A15B-8457D3F5B542}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EE46C85C-87E0-4818-8979-FA6EB2E89E6B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{EEEF47DE-529C-46D4-B186-C797182A00C9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F05BC095-6A4E-4889-97AC-DDEE6127FDFC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F1A4D9FD-77B5-4442-9233-C7AC33273AE1}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F2377D49-B72A-4B58-97D5-1C98D4A72C40}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F264C615-A4BB-4477-BBB2-BF5E82D091EA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F37A43D3-199D-4CCC-A926-B99C4E5DF5CF}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F37B4505-837B-4F45-8E8B-393900A9C88A}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F39739E7-06C9-4C9F-A6F7-26DC6187C40C}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F4B7D9DE-8107-4558-98D9-FB42898CBAB0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F54D25E5-D789-45AF-B6F9-4CFDAD264365}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F68165A8-2C33-47DE-82DD-2C7D6581BEC0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F68DD1E2-9DA4-44BB-B83F-27C7ADD914D0}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F7559D0D-CE50-4321-AEDE-4F27AFED551B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F8C14302-A89E-45AF-97F2-5B985681F3A9}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F8DA9C22-7A28-4141-8D5A-D22A7447E0EC}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F8EEAB94-1426-4F96-A337-04BDB2B4C4F7}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{F9081BE8-F0DD-496F-8AEF-6248A2E7CBFA}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FA4078AF-52AB-463D-A189-C8D2702353AB}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FB8C2CEC-2A3A-4A3A-8CE8-BD1321C45761}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FD1630AB-4D80-45E2-9141-ADCFC2BB2BE5}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FD1BB54E-875D-4B67-9C0D-D56D15ADEE5D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FD5DA219-C978-4349-8DB0-2BDB7FC5899D}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FD936757-03FC-4524-BBB7-847A06BBDA08}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FE914B62-7EDF-4A6D-BF9B-060EF9FC01DE}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FEAE391D-AAD1-42FB-9BDA-548BBA7AD57B}
    Successfully deleted: [Empty Folder] C:\Users\Greg\appdata\local\{FF0159D0-9D25-4388-8420-B3D408C93731}
    Successfully deleted: [Folder] "C:\ProgramData\ask"



    ~~~ FireFox

    Emptied folder: C:\Users\Greg\AppData\Roaming\mozilla\firefox\profiles\hbf4qyq1.default\minidumps [2 files]



    ~~~ Event Viewer Logs were cleared

    Roguekiller
    RogueKiller V8.7.8 _x64_ [Nov 14 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.adlice.com/forum/
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Greg [Admin rights]
    Mode : Remove -- Date : 11/18/2013 06:51:22
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 1 ¤¤¤
    [SUSP PATH] DS3_Tool_Local.exe -- C:\Users\Greg\Desktop\Motionjoy Local 0.7.1001\DS3_Tool_Local.exe [-] -> KILLED [TermProc]

    ¤¤¤ Registry Entries : 4 ¤¤¤
    [HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> DELETED
    [HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> DELETED
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    ¤¤¤ Scheduled tasks : 0 ¤¤¤

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

    ¤¤¤ External Hives: ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts




    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000AADS-00S9B0 ATA Device +++++
    --- User ---
    [MBR] 4a6d9ed7f84c00ff6752d11eb471b2e8
    [BSP] 107190d3d0e2295cb43542c39ec819ef : Windows 7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 476838 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[0]_D_11182013_065122.txt >>
    RKreport[0]_S_11182013_065042.txt



     
    Last edited: Nov 17, 2013
  9. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Good so far xboxdvl2,

    You may not have all the symptoms now but don't think your clean yet.

    Your AV, MSE didn't show up in HJT but it's there now, good job.

    Finish up with RogueKiller and OTL and we'll get anything leftover....


    2oG
     
  10. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Ouch! Shut the front door!

    well, xboxdvl2, I don't think I have ever got a OTL Log that long. :) It will take me some time to go through it.. In the mean time How is it running? Any problems at this point?

    Should be doing better with the exception that I know you are pretty slow. That's because there are a Lot of programs that are starting and running All the time, taking up RAM and resources when they are not needed. As soon as I can get through all of this we can take care of that detail...


    Hang in there and let me know how it's doing.
    2oG
     
  11. xboxdvl2

    xboxdvl2 Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,174
    Likes Received:
    7
    Trophy Points:
    48
    browser is freezing up,i did view a video that is legit and it didnt try to redirect me this time but browser crashes still sometimes.

    i also uninstalled ask toolbar & vuze toolbar from programs before running the scans.

    after posting the logs i went to bed as it was 7am and i'd been up all night.apart from browser freezing up and sometimes crashing no major problems on the pc,let me know what to delete and i will try and delete them.

    i know its a big log and thank you for taking the time to help me.
     
  12. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    please post a fresh HJT Log and I'll pick the ones that don't need to run all the time.

    Then you can look all of the running programs over and, if you don't use them, they can be uninstalled.

    2oG
     
  13. xboxdvl2

    xboxdvl2 Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,174
    Likes Received:
    7
    Trophy Points:
    48
    last time i ran hjthis i ran it as administer so it had permission to make a log file for some reason its not letting me do that now.will try again later might have to reinstall it.
     
  14. xboxdvl2

    xboxdvl2 Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,174
    Likes Received:
    7
    Trophy Points:
    48
    ok i ran it in capability mode and it worked

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 7:31:40 PM, on 22/11/2013
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v10.0 (10.00.9200.16736)
    Boot mode: Normal

    Running processes:
    C:\Windows\vsnpstd3.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
    O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
    O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
    O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - Startup: ACR Launcher.lnk = C:\Program Files (x86)\ACR\AutoClubRev\web\acrlauncher.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 9465 bytes
     
  15. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hi xboxdvl2,
    Happy that you could get HJT going.

    :Stop unneeded start-up entries:

    These are programs that start up when you turn on your computer but don't need to be running all of the time, any of these programs you can click on their icons (or start from the control panel) and start the program when you need it. By stopping these programs you will boot up faster and your computer will work faster.


    • Run HijackThis (rightclick and run as admin)
    • Click on the Scan button
    • Put a check beside all of the items listed below (if present):

    O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

    O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"

    O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"

    O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume

    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" –autorun

    O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')


    Close all open windows and browsers/email, etc...
    • Click on the "Fix Checked" button
    • When completed, close the application.


    That’s about all I am able to do from this end. As a final You may want to go through your installed programs list and uninstall anything that you no longer use.

    In addition to your AntiVirus program, I highly recommend using Malwarebytes Antimalware Pro that has a realtime scanner to block Bad Guys. It’s a one time pay but well worth it. If not then use MBAM Free and run it often.

    Lots of luck and Safe surfing,
    2oG
     

Share This Page