Jump to content

doodle1011

Members
  • Posts

    13
  • Joined

  • Last visited

Reputation

0 Neutral
  1. One more question. Would the pro version of MWAB have caught this so-called White Trader vulnerability? If not, would anything have caught it?
  2. Thank you, kind sir! I really appreciate it. Everything looks fine. But I have a couple questions, if you don't mind: 1. I assume that it was okay to delete the Whitetrader icon, that started all of this. 2. Is there anything in my logs to show where this vulnerability came from? 3. What is this spyware, malware, et al called? 4. Was this a dangerous vulnerability? i.e. do I need to change key passwords, move my life savings (of $4.97) to a Swiss Bank and etc? Thanks again - please keep this thread open for a day or so and I will verify that my system is still running smoothly. Dave
  3. <div>C:\Downloads\JDownloader 0.6.193\JDownloader 0.6.193\downloads\dr6b3an3\dr6b3an3\any-dvd-platinum.exe<span class="Apple-tab-span" style="white-space:pre"> </span>probably a variant of Win32/Injector.ABNB trojan</div> <div>C:\Downloads\JDownloader 0.6.193\JDownloader 0.6.193\downloads\J.River_Media_Center_14\J.River Media Center 14.0.140\patch.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/PSW.Delf.NZH trojan</div> <div>C:\Downloads\JDownloader 0.6.193\JDownloader 0.6.193\downloads\Ojosoft.Total.Video.Converter.V2.6.5.0430-Hardal\Ojosoft.Total.Video.Converter.V2.6.5.0430-Hardal\Ojosoft.Total.Video.Converter.V2.6.5.0430-Hardal\ total-video-converter.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Inject.NDA trojan</div> <div>C:\OEM\Preload\Autorun\APP\Nero 10 Essentials Gateway Edition\ISSetupPrerequisites\{BF80A1C0-C3FF-4B1C-ABEF-22CD4F97A0AB}\Toolbar.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask.A application</div> <div>C:\Users\cd\Documents\Downloads\CrystalDiskInfo4_1_4-en.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div>C:\Users\cd\Documents\Downloads\CrystalDiskMark3_0_1b-en.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div>C:\Users\cd\Documents\Downloads\Free3GPVideoConverter.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask application</div> <div>C:\Users\cd\Documents\Downloads\SUPERsetup.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div>C:\Users\cd\Downloads\Argo_(2012)_720p_BrRip_x264_-_YIFY.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.1ClickDownload.W application</div> <div>C:\Users\cd\Downloads\cnet2_Install-Spades-Free_exe.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/InstallCore.D application</div> <div>C:\Users\cd\Downloads\easy_duplicate_setup.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask.C application</div> <div>C:\Users\cd\Downloads\Install-Spades-Free.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Somoto.A application</div> <div>C:\Users\cd\Downloads\Mike_and_Molly_S03E23_HDTV_x264-LOL_[eztv].exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.1ClickDownload.AJ application</div> <div>C:\Users\cd\Downloads\SetupImgBurn_2.5.7.0.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask application</div> <div>C:\Users\cd\Downloads\winamp563_full_emusic-7plus_en-us.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div> </div>
  4. <p>Here is my ESET Scan log:</p> <p> </p> <div>C:\Downloads\JDownloader 0.6.193\JDownloader 0.6.193\downloads\dr6b3an3\dr6b3an3\any-dvd-platinum.exe<span class="Apple-tab-span" style="white-space:pre"> </span>probably a variant of Win32/Injector.ABNB trojan</div> <div>C:\Downloads\JDownloader 0.6.193\JDownloader 0.6.193\downloads\J.River_Media_Center_14\J.River Media Center 14.0.140\patch.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/PSW.Delf.NZH trojan</div> <div>C:\Downloads\JDownloader 0.6.193\JDownloader 0.6.193\downloads\Ojosoft.Total.Video.Converter.V2.6.5.0430-Hardal\Ojosoft.Total.Video.Converter.V2.6.5.0430-Hardal\Ojosoft.Total.Video.Converter.V2.6.5.0430-Hardal\ total-video-converter.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Inject.NDA trojan</div> <div>C:\OEM\Preload\Autorun\APP\Nero 10 Essentials Gateway Edition\ISSetupPrerequisites\{BF80A1C0-C3FF-4B1C-ABEF-22CD4F97A0AB}\Toolbar.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask.A application</div> <div>C:\Users\cd\Documents\Downloads\CrystalDiskInfo4_1_4-en.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div>C:\Users\cd\Documents\Downloads\CrystalDiskMark3_0_1b-en.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div>C:\Users\cd\Documents\Downloads\Free3GPVideoConverter.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask application</div> <div>C:\Users\cd\Documents\Downloads\SUPERsetup.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div>C:\Users\cd\Downloads\Argo_(2012)_720p_BrRip_x264_-_YIFY.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.1ClickDownload.W application</div> <div>C:\Users\cd\Downloads\cnet2_Install-Spades-Free_exe.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/InstallCore.D application</div> <div>C:\Users\cd\Downloads\easy_duplicate_setup.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask.C application</div> <div>C:\Users\cd\Downloads\Install-Spades-Free.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Somoto.A application</div> <div>C:\Users\cd\Downloads\Mike_and_Molly_S03E23_HDTV_x264-LOL_[eztv].exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/Adware.1ClickDownload.AJ application</div> <div>C:\Users\cd\Downloads\SetupImgBurn_2.5.7.0.exe<span class="Apple-tab-span" style="white-space:pre"> </span>a variant of Win32/Bundled.Toolbar.Ask application</div> <div>C:\Users\cd\Downloads\winamp563_full_emusic-7plus_en-us.exe<span class="Apple-tab-span" style="white-space:pre"> </span>Win32/OpenCandy application</div> <div> </div> <div>Thanks,</div> <div>Dave</div>
  5. Gringo; MBAM: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.06.16.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 cd :: CD-PC [administrator] 6/16/2013 5:13:42 PM mbam-log-2013-06-16 (17-13-42).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 242716 Time elapsed: 7 minute(s), 17 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\cd\AppData\Local\Temp\snsrqtd\sfrnvcw\wow.dll (Backdoor.Bot) -> Quarantined and deleted successfully. (end) Hijackthis: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 5:42:40 PM, on 6/16/2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16490) Boot mode: Normal Running processes: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe C:\Program Files (x86)\Orb Networks\Orb\bin\Orblauncher.exe C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Users\cd\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Users\cd\AppData\Roaming\Google\Google Talk\googletalk.exe C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe C:\Users\cd\AppData\Local\Vivox\HDN\Current\Vivox.HDN.Up.exe C:\Users\cd\AppData\Local\Vivox\BSN\Current\Bobsled-Notifier.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Squeezebox\SqueezeTray.exe C:\PROGRA~2\SQUEEZ~1\server\SQUEEZ~3.EXE C:\Users\cd\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Users\cd\AppData\Local\Vivox\VVS\Current\VivoxVoiceService.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files (x86)\Orb Networks\Orb\bin\Orb.exe C:\Program Files (x86)\Orb Networks\Orb\bin\OrbjetManager.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com/?pc=MAGW R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=MAGW R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Bobsled by T-Mobile - {C8748F11-F4AD-47AF-AB50-C7DF5792096B} - mscoree.dll (file missing) O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing) O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\cd\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [googletalk] C:\Users\cd\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" O4 - HKCU\..\Run: [VivoxHDN] "C:\Users\cd\AppData\Local\Vivox\HDN\Current\Vivox.HDN.Up.exe" /d O4 - HKCU\..\Run: [bobsled Notifier] C:\Users\cd\AppData\Local\Vivox\BSN\Current\Bobsled-Notifier.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Dropbox.lnk = cd\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Logitech Media Server Tray Tool.lnk = C:\Program Files (x86)\Squeezebox\SqueezeTray.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: En&queue current page with BID - file://C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm O8 - Extra context menu item: Enqueue link tar&get with BID - file://C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm O8 - Extra context menu item: Open &link target with BID - file://C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm O8 - Extra context menu item: Open current page with BI&D - file://C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebid.htm O8 - Extra context menu item: Open current page with BID Link E&xplorer - file://C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing) O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing) O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: Bobsled by T-Mobile (Launch button) - {C8748F11-F4AD-47AF-AB50-C7DF5792096B} - mscoree.dll (file missing) (HKCU) O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: KooRaRoo Media Server (KooRaRooMediaServer) - Programming Sunrise - C:\Program Files (x86)\KooRaRoo Media\KooRaRooMediaServer.exe O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~2\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe O23 - Service: TVersity Media Server (TVersityMediaServer) - Unknown owner - C:\ProgramData\TVersity\Media Server\MediaServer.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 15176 bytes Thanks, Dave
  6. Thanks. Will do tomorrow (Sunday). Night. Dave
  7. Gringo; Seems to be running well. After every re-start, I get a notification asking if it's okay for jucheck.exe rto run - I believe that is a Java Updater. Log: ComboFix 13-06-15.01 - cd 06/16/2013 1:11.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5589.3445 [GMT -4:00] Running from: c:\users\cd\Desktop\ComboFix.exe Command switches used :: c:\users\cd\Desktop\CFScript.txt AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Symantec Endpoint Protection *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\cd\AppData\Local\Temp\pdk-cd-3204\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\93e7e3d6030f426844228042348210cf\Service.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\e56c61f7248672819579325af3387035\POSIX.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\cd\AppData\Local\Temp\pdk-cd-3204\perl514.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\0665c25e931c1ac0151b062449e91028\XSAccessor.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\17d0b152e63e6bfe81b4b19588538896\mro.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\19febd96672ffdb7ea244cef36aaa062\Zlib.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\38a10ee333cf1a9afec3f0acdf1bbebc\Scan.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\3b7106dd14676048b10bbb09a990f74c\XS.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\44727051c604ef6b79894b64d4c63832\Expat.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\7f177c338672436e01c4f0bdbcf94491\EV.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\7f2598c08178217a0e2c754f3d568f28\Byte.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\aff7ee779ea184f884ed432c30a58f5d\Scale.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\b6bd87c968599725b8ab2e5c25d3046a\API.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\b979ace6da01e63d651cce9ee2474fdc\Name.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\bc147d83c7c868eeee67082dcf55430c\File.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\c199d3c1960e7aeeecb599487952bed2\HiRes.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\c344fd5536724b2af2e6453833b60203\SHA1.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\c668a322917d32a5ea22894518aa9897\Base64.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\d0bf009923f29116535c26d228271d6d\Scan.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\e2e81dd6b3e5a36f0bdae076393cc11d\icuin46.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\e2e81dd6b3e5a36f0bdae076393cc11d\icuuc46.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\e56c61f7248672819579325af3387035\POSIX.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4712\perl514.dll . . ((((((((((((((((((((((((( Files Created from 2013-05-16 to 2013-06-16 ))))))))))))))))))))))))))))))) . . 2013-06-16 05:25 . 2013-06-16 05:25 -------- d-----w- c:\users\HomeGroupUser$\AppData\Local\temp 2013-06-16 05:25 . 2013-06-16 05:25 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-06-15 04:00 . 2013-06-15 04:00 -------- d-----w- c:\windows\ERUNT 2013-06-15 04:00 . 2013-06-15 04:00 -------- d-----w- C:\JRT 2013-06-12 10:57 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-06-12 10:56 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll 2013-06-12 10:56 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-06-10 15:36 . 2013-06-10 15:37 -------- d-----w- c:\users\cd\AppData\Local\ElevatedDiagnostics 2013-06-08 13:32 . 2013-06-08 13:32 -------- d-----w- c:\users\cd\AppData\Roaming\Malwarebytes 2013-06-08 13:31 . 2013-06-08 13:31 -------- d-----w- c:\programdata\Malwarebytes 2013-06-08 13:31 . 2013-06-08 13:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-06-08 13:31 . 2013-04-04 18:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-06-08 13:31 . 2013-06-08 13:31 -------- d-----w- c:\users\cd\AppData\Local\Programs 2013-06-03 22:31 . 2013-06-03 22:45 -------- d-----w- C:\DVDx 2013-05-31 23:24 . 2013-05-31 23:24 -------- d-----w- c:\users\cd\AppData\Roaming\OverDrive 2013-05-31 23:22 . 2013-05-31 23:22 -------- d-----w- c:\program files (x86)\OverDrive Media Console . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-13 07:02 . 2012-05-25 22:46 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-12 07:46 . 2012-05-30 20:27 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-12 07:46 . 2011-10-26 04:01 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-05-14 14:36 . 2011-03-29 01:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-04-29 04:14 . 2013-04-29 04:14 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin 2013-04-13 05:49 . 2013-05-14 23:14 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-14 23:14 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-14 23:14 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-14 23:14 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-14 23:14 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-14 23:14 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-24 14:07 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 06:01 . 2013-05-14 23:14 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-04-10 06:01 . 2013-05-14 23:14 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-10 03:30 . 2013-05-14 23:14 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-03-19 06:04 . 2013-04-10 05:23 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 05:53 . 2013-05-14 23:14 48640 ----a-w- c:\windows\system32\wwanprotdim.dll 2013-03-19 05:53 . 2013-05-14 23:14 230400 ----a-w- c:\windows\system32\wwansvc.dll 2013-03-19 05:46 . 2013-04-10 05:23 43520 ----a-w- c:\windows\system32\csrsrv.dll 2013-03-19 05:04 . 2013-04-10 05:23 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 05:23 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47 . 2013-04-10 05:23 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll 2013-03-19 03:06 . 2013-04-10 05:23 112640 ----a-w- c:\windows\system32\smss.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\cd\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\cd\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\cd\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-05-21 39408] "Spotify Web Helper"="c:\users\cd\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-06-14 1104384] "googletalk"="c:\users\cd\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2012-08-28 247768] "VivoxHDN"="c:\users\cd\AppData\Local\Vivox\HDN\Current\Vivox.HDN.Up.exe" [2013-02-25 35094416] "Bobsled Notifier"="c:\users\cd\AppData\Local\Vivox\BSN\Current\Bobsled-Notifier.exe" [2013-02-25 1117752] "Spotify"="c:\users\cd\AppData\Roaming\Spotify\Spotify.exe" [2013-06-14 4643328] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-30 336384] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336] "Hotkey Utility"="c:\program files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe" [2011-08-11 627304] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-01-25 115560] "Adobe Photo Downloader"="c:\program files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440] . c:\users\cd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] Dropbox.lnk - c:\users\cd\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336] Logitech Media Server Tray Tool.lnk - c:\program files (x86)\Squeezebox\SqueezeTray.exe [2012-8-22 3051619] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "wave"=DrvTrNTm.dll "mixer"=DrvTrNTm.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe;c:\program files\BitComet\tools\BitCometService.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [x] S2 KooRaRooMediaServer;KooRaRoo Media Server;c:\program files (x86)\KooRaRoo Media\KooRaRooMediaServer.exe;c:\program files (x86)\KooRaRoo Media\KooRaRooMediaServer.exe [x] S2 Live Updater Service;Live Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x] S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x] S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-06-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-30 07:46] . 2012-05-21 c:\windows\Tasks\Gateway Registration - Reminder Recall task.job - c:\program files (x86)\Gateway\Registration\GREG.exe [2011-05-11 11:30] . 2013-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 21:41] . 2013-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 21:41] . 2013-05-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1106374176-3451124849-2038408335-1000Core1ce4e54212763e0.job - c:\users\cd\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-21 22:39] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072] . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://my.yahoo.com/ mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mStart Page = hxxp://www.bing.com/?pc=MAGW mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: En&queue current page with BID - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm IE: Enqueue link tar&get with BID - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm IE: Open &link target with BID - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm IE: Open current page with BI&D - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebid.htm IE: Open current page with BID Link E&xplorer - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\cd\AppData\Roaming\Mozilla\Firefox\Profiles\opfibqbw.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: !HIDDEN! 2012-06-25 12:14; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe c:\program files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\programdata\TVersity\Media Server\MediaServer.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe c:\program files (x86)\Orb Networks\Orb\bin\Orblauncher.exe c:\program files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe . ************************************************************************** . Completion time: 2013-06-16 01:36:50 - machine was rebooted ComboFix-quarantined-files.txt 2013-06-16 05:36 ComboFix2.txt 2013-06-15 17:45 . Pre-Run: 961,139,281,920 bytes free Post-Run: 960,745,172,992 bytes free . - - End Of File - - 074E8C4F97EA9D8EC0FCB8069DA10B43 A36C5E4F47E84449FF07ED3517B43A31 Thanks Dave
  8. You are da man! ComboFix 13-06-15.01 - cd 06/15/2013 13:08:54.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5589.3126 [GMT -4:00] Running from: c:\users\cd\Desktop\ComboFix.exe AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\cd\AppData\Local\Temp\pdk-cd-2700\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\93e7e3d6030f426844228042348210cf\Service.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\e56c61f7248672819579325af3387035\POSIX.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\cd\AppData\Local\Temp\pdk-cd-2700\perl514.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\0665c25e931c1ac0151b062449e91028\XSAccessor.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\17d0b152e63e6bfe81b4b19588538896\mro.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\19febd96672ffdb7ea244cef36aaa062\Zlib.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\2b1fc61b36a6711ea149b18bf3b41500\Parser.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\31638f63e39b38d3e250a9a57cb9d1c5\Cwd.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\32785c19dc6898fbbbf06f3b776edd08\Fcntl.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\38a10ee333cf1a9afec3f0acdf1bbebc\Scan.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\3a7ccbf8181ee5a145227a6dfce3594c\WinError.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\3a8764e0d7c5d453e01d9ad08cf7fb58\IO.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\3b7106dd14676048b10bbb09a990f74c\XS.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\4461f48e31bde5c56b31b973b773de09\List.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\44727051c604ef6b79894b64d4c63832\Expat.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\4f2c03383aab0133b8dc0a3fa2dd92fa\Storable.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\5ffd05b2cbd58528e56519784ca9c869\Hostname.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\60ff464e01c2cd5526dbdad5a125081d\Dumper.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\7ef0d901bf4203fbcf7a0fff0e82aa5f\Encode.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\7f177c338672436e01c4f0bdbcf94491\EV.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\7f2598c08178217a0e2c754f3d568f28\Byte.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\8fedeb86a4a984edfc1fb255d4ea965c\XS.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\961b0d62fa52b1dd29c795a822fbf1cf\DBI.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\aff7ee779ea184f884ed432c30a58f5d\Scale.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\b6bd87c968599725b8ab2e5c25d3046a\API.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\b979ace6da01e63d651cce9ee2474fdc\Name.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\bc147d83c7c868eeee67082dcf55430c\File.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\bd5179a413bc0c4b82eedc22c6cab101\re.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\c199d3c1960e7aeeecb599487952bed2\HiRes.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\c19d5e3dc664d9f4ce700001e2621cee\MD5.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\c344fd5536724b2af2e6453833b60203\SHA1.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\c5cce8d16a1bd48692b421dcf46d3396\Util.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\c668a322917d32a5ea22894518aa9897\Base64.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\cf5fe81e2f5dcbfecfd0495e1648c991\Unicode.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\d0bf009923f29116535c26d228271d6d\Scan.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\d10c2c06ba2044cccc247c4315f5c7d3\Process.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\d1c77e404b5c4b954fa537ed63c8fb7b\File.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\d1e7c33431cd8713f2ce3582829a8b14\Socket.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\dacfd0ab9b5fd029ed8d29e4482b0775\XS.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\de446fdd1ae335c7d2b9e62bb8cdf765\B.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\df1ba73f49c38cbbc7a11c779c3506d2\OLE.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\e2e81dd6b3e5a36f0bdae076393cc11d\icudt46.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\e2e81dd6b3e5a36f0bdae076393cc11d\icuin46.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\e2e81dd6b3e5a36f0bdae076393cc11d\icuuc46.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\e2e81dd6b3e5a36f0bdae076393cc11d\SQLite.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\e56c61f7248672819579325af3387035\POSIX.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\eaeabd54205de2f10c00aea80bbf0d83\Registry.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\eb138ef0e4282611dbf485a302784646\LibYAML.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\f233f63b6654362865c7577442edb9e3\Win32.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\fa9e3c814aa32db2ad5f17bdfbc22746\attributes.dll c:\users\cd\AppData\Local\Temp\pdk-cd-4776\perl514.dll c:\users\cd\Desktop\Internet Explorer.lnk c:\users\cd\Documents\~WRL1674.tmp c:\users\cd\WINDOWS c:\users\HomeGroupUser$\WINDOWS c:\users\Public\VCREDI~3.EXE c:\windows\wininit.ini . . ((((((((((((((((((((((((( Files Created from 2013-05-15 to 2013-06-15 ))))))))))))))))))))))))))))))) . . 2013-06-15 04:00 . 2013-06-15 04:00 -------- d-----w- c:\windows\ERUNT 2013-06-15 04:00 . 2013-06-15 04:00 -------- d-----w- C:\JRT 2013-06-12 10:57 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-06-12 10:56 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll 2013-06-12 10:56 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-06-10 15:36 . 2013-06-10 15:37 -------- d-----w- c:\users\cd\AppData\Local\ElevatedDiagnostics 2013-06-08 13:32 . 2013-06-08 13:32 -------- d-----w- c:\users\cd\AppData\Roaming\Malwarebytes 2013-06-08 13:31 . 2013-06-08 13:31 -------- d-----w- c:\programdata\Malwarebytes 2013-06-08 13:31 . 2013-06-08 13:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-06-08 13:31 . 2013-04-04 18:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-06-08 13:31 . 2013-06-08 13:31 -------- d-----w- c:\users\cd\AppData\Local\Programs 2013-06-03 22:31 . 2013-06-03 22:45 -------- d-----w- C:\DVDx 2013-05-31 23:24 . 2013-05-31 23:24 -------- d-----w- c:\users\cd\AppData\Roaming\OverDrive 2013-05-31 23:22 . 2013-05-31 23:22 -------- d-----w- c:\program files (x86)\OverDrive Media Console . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-13 07:02 . 2012-05-25 22:46 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-12 07:46 . 2012-05-30 20:27 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-12 07:46 . 2011-10-26 04:01 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-05-17 04:05 . 2013-06-13 07:05 17824768 ----a-w- c:\windows\system32\mshtml.dll 2013-05-17 03:27 . 2013-06-13 07:05 10926080 ----a-w- c:\windows\system32\ieframe.dll 2013-05-17 03:09 . 2013-06-13 07:05 2312704 ----a-w- c:\windows\system32\jscript9.dll 2013-05-17 03:02 . 2013-06-13 07:05 1346560 ----a-w- c:\windows\system32\urlmon.dll 2013-05-17 03:02 . 2013-06-13 07:05 1392128 ----a-w- c:\windows\system32\wininet.dll 2013-05-17 03:01 . 2013-06-13 07:05 1494528 ----a-w- c:\windows\system32\inetcpl.cpl 2013-05-17 03:00 . 2013-06-13 07:05 237056 ----a-w- c:\windows\system32\url.dll 2013-05-17 02:58 . 2013-06-13 07:05 85504 ----a-w- c:\windows\system32\jsproxy.dll 2013-05-17 02:56 . 2013-06-13 07:05 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2013-05-17 02:56 . 2013-06-13 07:05 599040 ----a-w- c:\windows\system32\vbscript.dll 2013-05-17 02:55 . 2013-06-13 07:05 816640 ----a-w- c:\windows\system32\jscript.dll 2013-05-17 02:54 . 2013-06-13 07:05 729088 ----a-w- c:\windows\system32\msfeeds.dll 2013-05-17 02:53 . 2013-06-13 07:05 2147840 ----a-w- c:\windows\system32\iertutil.dll 2013-05-17 02:51 . 2013-06-13 07:05 96768 ----a-w- c:\windows\system32\mshtmled.dll 2013-05-17 02:51 . 2013-06-13 07:05 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2013-05-17 02:46 . 2013-06-13 07:05 248320 ----a-w- c:\windows\system32\ieui.dll 2013-05-14 14:36 . 2011-03-29 01:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-04-29 04:14 . 2013-04-29 04:14 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin 2013-04-26 05:51 . 2013-06-12 10:57 751104 ----a-w- c:\windows\system32\win32spl.dll 2013-04-17 06:24 . 2013-06-12 10:57 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-04-13 05:49 . 2013-05-14 23:14 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-14 23:14 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-14 23:14 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-14 23:14 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-14 23:14 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-14 23:14 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-24 14:07 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 06:01 . 2013-05-14 23:14 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-04-10 06:01 . 2013-05-14 23:14 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-10 03:30 . 2013-05-14 23:14 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-03-19 06:04 . 2013-04-10 05:23 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 05:53 . 2013-05-14 23:14 48640 ----a-w- c:\windows\system32\wwanprotdim.dll 2013-03-19 05:53 . 2013-05-14 23:14 230400 ----a-w- c:\windows\system32\wwansvc.dll 2013-03-19 05:46 . 2013-04-10 05:23 43520 ----a-w- c:\windows\system32\csrsrv.dll 2013-03-19 05:04 . 2013-04-10 05:23 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 05:23 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47 . 2013-04-10 05:23 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll 2013-03-19 03:06 . 2013-04-10 05:23 112640 ----a-w- c:\windows\system32\smss.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\cd\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\cd\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\cd\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-05-21 39408] "Spotify Web Helper"="c:\users\cd\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-06-14 1104384] "googletalk"="c:\users\cd\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2012-08-28 247768] "VivoxHDN"="c:\users\cd\AppData\Local\Vivox\HDN\Current\Vivox.HDN.Up.exe" [2013-02-25 35094416] "Bobsled Notifier"="c:\users\cd\AppData\Local\Vivox\BSN\Current\Bobsled-Notifier.exe" [2013-02-25 1117752] "Spotify"="c:\users\cd\AppData\Roaming\Spotify\Spotify.exe" [2013-06-14 4643328] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-30 336384] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336] "Hotkey Utility"="c:\program files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe" [2011-08-11 627304] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-01-25 115560] "Adobe Photo Downloader"="c:\program files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440] . c:\users\cd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] Dropbox.lnk - c:\users\cd\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336] Logitech Media Server Tray Tool.lnk - c:\program files (x86)\Squeezebox\SqueezeTray.exe [2012-8-22 3051619] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "wave"=DrvTrNTm.dll "mixer"=DrvTrNTm.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe;c:\program files\BitComet\tools\BitCometService.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [x] S2 KooRaRooMediaServer;KooRaRoo Media Server;c:\program files (x86)\KooRaRoo Media\KooRaRooMediaServer.exe;c:\program files (x86)\KooRaRoo Media\KooRaRooMediaServer.exe [x] S2 Live Updater Service;Live Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x] S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x] S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-06-15 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-30 07:46] . 2012-05-21 c:\windows\Tasks\Gateway Registration - Reminder Recall task.job - c:\program files (x86)\Gateway\Registration\GREG.exe [2011-05-11 11:30] . 2013-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 21:41] . 2013-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 21:41] . 2013-05-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1106374176-3451124849-2038408335-1000Core1ce4e54212763e0.job - c:\users\cd\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-21 22:39] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072] . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://my.yahoo.com/ mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mStart Page = hxxp://www.bing.com/?pc=MAGW mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: En&queue current page with BID - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm IE: Enqueue link tar&get with BID - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm IE: Open &link target with BID - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm IE: Open current page with BI&D - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebid.htm IE: Open current page with BID Link E&xplorer - file://c:\program files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\cd\AppData\Roaming\Mozilla\Firefox\Profiles\opfibqbw.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: !HIDDEN! 2012-06-25 12:14; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) SafeBoot-Symantec Antvirus Toolbar-Locked - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe c:\program files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\programdata\TVersity\Media Server\MediaServer.exe c:\program files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe c:\program files (x86)\Orb Networks\Orb\bin\Orblauncher.exe c:\program files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe . ************************************************************************** . Completion time: 2013-06-15 13:45:06 - machine was rebooted ComboFix-quarantined-files.txt 2013-06-15 17:45 . Pre-Run: 958,960,369,664 bytes free Post-Run: 961,425,874,944 bytes free . - - End Of File - - 5878040965485B0CFFFD602A40062E3C A36C5E4F47E84449FF07ED3517B43A31
  9. Hi Gringo and Thanks for your help! I ran ComboFix but unfortunately (and a big whoops), I guess that I did not save the log file to my desktop, as I had to restart the computer, due to the "Illegal operation attempted on a registry key that has been marked for deletion" popups. Do I need to rerun the tool? I do not see the wow.dll errors nor do I see that Windows Explorer errors. Should I now manually remove the Whitetrader desktop icon? Dave
  10. Thanks a gazillion! I will do these next steps, sometime tomorrow. Hope that is okay (sick wife). How is the computer now? Do not see that pesky \wow.dll error. The Whitetrader icon is still there but that is probably a manual deletion, at the end, right? And my keyboard driver is not working as the multimedia keyboard's keys usually show up on-screen. Probably an easy fix, later. Good night and Thanks, Dave
  11. Thanks Gringo! Here are the log files: ADWCleaner: # AdwCleaner v2.303 - Logfile created 06/14/2013 at 23:42:58 # Updated 08/06/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : cd - CD-PC # Boot Mode : Normal # Running from : C:\Users\cd\Desktop\AdwCleaner.exe # Option [Delete] ***** [services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\cd\AppData\Local\TempDir ***** [Registry] ***** Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\APN PIP Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\PIP Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\PIP Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] ***** [internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16490 [OK] Registry is clean. -\\ Mozilla Firefox v21.0 (en-US) File : C:\Users\cd\AppData\Roaming\Mozilla\Firefox\Profiles\opfibqbw.default\prefs.js [OK] File is clean. -\\ Google Chrome v27.0.1453.110 File : C:\Users\cd\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[s1].txt - [2356 octets] - [14/06/2013 23:42:58] ########## EOF - C:\AdwCleaner[s1].txt - [2416 octets] ########## JRT: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by cd on Sat 06/15/2013 at 0:00:36.79 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{000E31AA-7B0C-4B0E-869B-C7464956036B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0029DBC2-3F4F-4DAE-A8BE-EAF8C1BCCD0F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{00C55157-33F1-442A-98C3-C9B1059875FE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0150DFD6-32C2-4B82-9E77-F8E9EB75A594} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{01E181C6-ABAC-44B8-9DA5-B6A1DDFE78F6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{02359C4B-458E-4233-84DE-A6BD9C375AE0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{028BDB25-FBFC-426A-B6E2-7E57024102AF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{029D7402-1B0B-46A6-91EC-97BB986E1001} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{02DD636F-8A0C-4C81-8F23-F1F4BE222C18} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0400EE2B-DFE7-4146-9AF1-458C29684D1E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{04B30CD0-EB9A-4737-BE85-485C5D9A0E05} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{04FF0007-BEB3-46FC-B0BF-E24E607BA846} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0521DDDC-442E-49D7-B334-62291501A1B3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{05FAFA0F-5388-4B58-B7E8-15CD6A4AD9EA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{060EDD1B-77AE-42D5-AF06-50C3847AD810} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{060F9209-E1F4-4BD2-B0BE-245EBAAE742E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{069F92E1-06F9-4661-846A-F0D2DAC7B3B3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{06A8B849-298A-4941-8A8C-DCB627088831} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{06AE4EDD-C87E-4EDE-AB6B-A2B258160CD8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{086CC72B-FE09-43B3-BFEB-5A32205128CA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{08C663D9-E3D6-4C1F-811C-076A2EEC5C16} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{08E25B0D-D578-4DF1-AA08-3935D33AE20E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{09F3A1A6-5E99-447A-AF96-C7AEEB84B898} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0A073E03-43FE-4260-9C8A-344DDCFDBEF1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0A0897F6-FCF7-4846-A82F-8DA0C9548632} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0B1A20DA-B2D8-44C7-8062-D0A6114B4A49} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0B265DA7-E762-4786-B2D9-5DBE7DED9F75} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0C593F42-7C01-442F-B5FC-8777FE0BAAB3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0CA4100A-EF9D-468D-8DE1-BFBE1E3578A3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0CB1E568-6DB5-4D47-98D1-DCEDF392C919} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0CCFFAC3-A829-4868-A4F3-B92B4936936B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0D175D4F-FB48-4A25-84C1-E877AA936E52} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0D3D944A-6B3F-46FC-9154-7CB1552CA145} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0DF768E2-3F08-4E60-9B4A-264169B6A298} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0E0B9F2A-4B67-4FA6-9DA5-60AB02FFEF17} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0E58F07F-6D27-43B6-9B1F-3CF12B477ABB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0E989327-96E0-4272-B995-16CD38DEC938} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0F3F09D4-4537-478E-8A1A-EF8171C3147D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{0FFDA203-489A-4D55-AEAB-53A3625F0DE7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{102FAE2E-7428-4B05-9E39-6D714B53E638} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{104A4A71-6667-4A62-9F8B-988AA06560FF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{10B5CF9E-9013-4F98-8C49-74332D9B7EA7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{10BC1547-2355-488F-A4CA-54C8EBF941BC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{113CEA5E-6141-4A54-BA4E-7B10D56E0FCC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{113DBEC2-4C9B-4F22-B26A-1249DB19EE40} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1154AC8B-BFA0-4208-B5F8-3FDA71567FE8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{116769BB-1FEC-4C92-80F9-BD2ACBB98846} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1192A15E-BE99-4F44-B74C-F5E194A202EA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{11B82C6E-A2D2-4CA6-898E-3DB42A2A5136} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{11D32BDA-27A6-4D55-9801-B0E8E6C66E82} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{11EA8462-806E-4999-8A5E-C1CA0894BCED} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{11F7FAB7-AAEB-47EB-B128-C4E28CD16063} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{11FEDED6-9FD2-4D6E-9471-099F03416A41} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{12138DA3-8575-4D9E-A237-11B5130702E2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{12612079-D9F5-4900-87AF-433A735D3FDD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{12760391-A96E-44F7-A704-4545962C91E9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{12A7C6AE-1B54-4ED3-8D07-2C33ABA423E7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{130A150F-E32E-437D-B68D-50D2005FF807} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{13704C77-86C5-4D75-93E3-A718AB387F54} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{14685ED7-DBB3-4814-8E02-7CF753735455} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{14E3C5C4-CA66-40D6-94DB-3E8B5EE8B2A8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{14F4CF25-A915-4B28-87F6-2D024E5CB367} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{154FA003-0861-47BD-B0F9-68C0F3130B83} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1572110D-BAA6-4044-9BC1-438FF8E52C15} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1589BBFD-6F71-4A4F-B550-12DB9A546A7A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{15C23A83-31F2-45A7-92F3-BB19D85492B4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{15C9E888-8375-45C8-8CD0-F105FE891F90} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1679DD36-7112-4213-B26B-C015AFE0D068} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{16EF2DA8-27D6-4358-855F-9059DC3FCF89} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{179D5688-BD4B-489B-B332-26F56DEB2AEC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{17CA49AA-2DFD-4605-A6B9-6F83BFC92DA7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{17D4C273-8450-49C3-9B2A-A46341286784} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{184916A6-E8A6-4D69-B3FB-2226D6A4AD57} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{186BA492-1AA1-4F08-802D-E6E35DFD35E0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{18E90307-3C04-4608-BD44-5385C516A7C4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{192821B4-20C1-4B50-A917-5B77DECB3868} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1943B6CE-29BB-4B6C-8000-34E0A5D2F209} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1A3407F5-CEBC-4FF6-B98E-FF700C31434F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1AD90E57-D215-44CC-A820-93A798F2FABB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1B1DC247-EA4C-402B-B57F-9034C54A89F2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1B3A15AA-2A5B-4D97-AB0D-69F2EDA285E4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1B43F150-33F8-4116-89EC-23446DAE69D7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1B6A409B-938E-487A-88B3-A265ECE156C6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1BBDA8FC-14D2-4AB3-B07E-40DE3C265E64} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1BC9F7BC-E6D8-4F5E-80AF-CABD1ED2F9A9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1C3993E4-DA3E-42F5-9D70-35463A929C4A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1C6DAD29-8418-42F0-AE5A-9338901B938E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1CBFF8B2-F000-4C94-A86E-5E6E83F165E3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1CD96B25-2808-4512-B581-2BB0C9F20E2E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1CE586F0-D5DC-4705-B3C2-0F7F379D3093} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1CF03E33-BD31-48AA-BC65-5F29829D35ED} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1D4AA31B-6198-4389-8143-B77AFEF91899} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1D827217-0CA1-4E72-A03E-1916ED3A7C16} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1DC79513-6625-4091-8E6B-986D65BFFC70} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1DD2A465-5F7D-4688-B33D-9EE06AB9D264} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1DD91A10-8202-4642-BF36-7DBC2708E4C3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1E444121-ECCE-47DF-B4B9-A4A4E4C82614} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1E73636A-B766-4046-8766-85A051D6C854} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1EC1A20F-9755-4D80-B991-C568138D6AEC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{1FD54051-DC93-4EC6-9EE8-F0EB38602A0D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2035C64B-032F-4784-A2D1-1CBC08A6C4A6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{20398E39-4694-41CB-B17F-2B87DB7BDA6F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{20776A71-3BF4-412F-B394-C0DEF9D21843} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{20930E8E-AFC4-4276-B42E-F901DA87C784} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2142EAFB-3405-4E2B-9FC4-D7A66E8A188F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{21CD16B1-A7FA-47BA-8D1C-5EB78FAC3940} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2256247E-FB3F-4A62-BC0B-C79E046FD22E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{23486DCC-9B51-4B34-87BB-2ECA82C0910E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2389D4CA-C222-4339-8678-CB148D789915} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{23C52325-145D-4D9E-95F9-DFA8C96493B2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{23C7048D-F0E7-48E1-BD41-45D54817EE4A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{23DD57CE-22BE-4679-BD68-E44DC0A91548} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{247682DE-0FAF-43DB-ADD8-4F261C42692D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{24861425-3818-4AB6-8A37-E705F310D7B8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{249B6DBE-E9AD-4764-945A-3C6475769BF7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{24B37B8D-17BD-40AE-BCF5-5BDAA2180010} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{263DC3F4-761E-4D24-B36F-47068D9BFCBE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{268119D3-4985-452C-9230-13FFF4569A86} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{271D916F-2FC2-4CD0-B8A1-D94E58CA61FC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2796E17E-8176-46C8-9E74-C6C4549B6E63} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{27F25F94-4199-4076-8F54-B2393F64EA82} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{282455A1-A940-4DD1-8145-4289A826797D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{28678FB7-2217-4AFB-806B-81F7C3D0ACD2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{28E1A36C-3CC2-488C-845F-37927A20BD8D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{29E800AF-F20E-44E9-8C8C-0EC8FA1AAD37} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2A4E5A99-9189-49A1-B246-E3CF6CDCFDB4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2A6EEBB5-FDDA-46DA-92EF-B9D991E21D26} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2A971CCD-CD51-468D-A2B1-E2B20E27E79D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2AF5B129-4B47-4ADC-9975-A70DE549488D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2B5124E9-6DC0-473E-9D80-13FBB2AC8FDB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2B5F5D7B-EF22-4EC8-985D-588B1AB6A844} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2B9FC078-0835-4784-A69D-E63D372C783B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2BB70585-EAF2-4A20-967C-63BC536FF057} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2C321033-BF28-4072-8EA5-B3051F92EDE4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2C8EF36C-EA5A-4D9A-804D-2DF6E0BE3E7B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2CC86FFA-745D-4464-B75A-47E6D793B09F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2CE0603A-9F82-4F1F-81D8-87A2F9CACCD0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2D35230E-7238-419F-93A9-A3BD657E68BF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2D7E74C8-8304-4875-B704-1B921C8A74DA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2E441146-8277-439A-9B82-716C630B00D6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2EF9162B-3CB3-43EF-83CE-514E959463F8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2FB27960-1490-4CFE-86EC-FD46FB9BAD96} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2FCC43E6-A901-4EEF-AAED-BFAF867105E9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{2FF38A5C-BAA6-40A2-BCC7-9C7D2FF685D5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3041230C-840A-4DE4-8D94-1E4261575458} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3081A9B7-73A0-44D6-AE0E-1350FC8E7441} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{30CA46EB-1C34-4519-884E-5BBBC49933C5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{30D7DC4C-5F45-4B4A-99AA-D0D02AF090AF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3129400A-DBE6-4506-A87C-1D0764F5CF6C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3150233D-9BD9-44FC-8111-2840422B5CAC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{317CAB46-D2F1-4FB9-BFE3-1495A1C8E0EF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3214EDD6-AC48-4DA9-94F4-2EAE5248EA70} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{329C0C24-4317-4320-9F5E-61AAC97ACF72} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{32CDECAC-042F-415C-BD8F-E722440652B9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{32CFCC6A-B19D-4C9D-9077-02FB378C1F73} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{33012470-D484-4C3A-9903-5D94CFA43A1D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{337FB353-A1EE-44AF-BF21-5CCCB82B4EAC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{33834376-851A-46C8-AC48-98714FF64F51} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{33938F2D-FC96-47C5-A871-5799698F97F4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{33D62B45-212D-4EF4-AD5A-067C1B3A54F2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{341F831C-2B7A-4A15-908A-7E96CED856C7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{34511D97-4EC1-4238-93CC-9205B668A373} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3491CF3D-C249-451B-A4EB-FBD24C2F81D8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{34A5BB69-DCC5-4C2A-B664-6CA481ECFC94} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{34EEDE9D-A033-439E-8A70-DFF33152C85A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{35209B80-996B-46DD-B030-48B8E47898B0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{352ADC74-9E28-4A43-A945-9D1FAD60808D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{362917D3-EFF9-4E2D-B536-F1BD2AF537B6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3673B086-F974-4C4D-8828-72A7C4435199} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{36B0BF75-7771-4857-8450-8A87255CF692} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{36FD0107-8023-4967-B038-B4C59F5A82B9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3701C0A8-1FF8-44D0-9DB1-1DB351DC0930} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{37949DC2-1002-451A-86C8-5105FDD919EF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{37CC69C6-F66C-4196-953B-C03D2D17ECD9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{37DB4280-3725-487A-B6EF-CB9BA428D405} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{38469D60-4357-4CDA-AFFC-D2D1F4E65113} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{39A4B49A-526F-445C-9EA8-7D74BF7F2C4F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3A26496A-E6B0-410D-A403-2C862188BB3A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3B81F41A-AD1E-4FE6-BA96-93AF36C87067} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3BA01058-B681-49F5-8EFD-BC3CE8597CDB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3BE07C49-F671-413E-AD5C-6FFF6D50F102} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3D35C1CE-2B53-4E08-AE96-0CEA13990F93} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3DF6AE73-2DC6-43F5-B6F1-979B6BB251AA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3DFF23D4-4A8E-4734-975E-CD1015768E81} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3E24836A-F864-45CE-A46F-B9D02D4D3F09} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3E702239-4105-4087-84A0-BDBFA4EC776A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3F21BE08-F095-4FA3-A50D-B307716C6445} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3F3C262B-411A-413C-8A0B-B30E161A6E33} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3F85873E-257C-483A-B004-4EF9E65EA527} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{3FB0074C-3177-4366-A918-2F17A46C5F60} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{404FFEF2-769E-4A74-9398-CDBE60A796BE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4107E3AB-6B5B-4315-8F98-3CE1B65A41B8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{411F8720-C138-42CD-9667-0203D123CF25} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{417FC749-30DB-4A32-9E39-A1791B8D4BBB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{42850C89-F4E7-4D3C-A39D-14D3E2B560E8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{42FA5B16-1AB4-4384-ACE7-19B35A7FE2AB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{439870DF-458F-4AE0-92EE-D9E8F5569957} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{45581B53-9B71-4C22-AFF3-20B13E178FBD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{45C743D4-E413-4C67-9C8E-2E8018DF69F0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{46529D15-CF3B-4316-81EA-4E071C2BCBBF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{46884CF0-32E2-4F5A-B9B8-F34113533C2F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{469C0D17-95C1-4EC1-BCAB-E83EA9D305F0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{46B5E4ED-B629-427D-BF5E-D1907475FB4C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{46ECCD1A-AA31-456D-99D1-89AEE9B81197} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4721CC4C-D04C-4C84-A268-C16490537257} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{47A0C386-6FFC-4D2D-BFD8-0321B1EEA15D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{48478A85-E1B0-48D3-B2F2-2B43B911C620} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{493AA062-6CE4-4B84-B341-884DE8E06B2C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{49F82B8A-2EA0-4236-AB06-C55FB3FAAF52} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4A52C196-4586-4384-8E28-4CA61D018A50} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4A79D82A-7BDC-47A7-966F-8B7D1D9EC949} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4B9E0A1D-8ADE-4E9C-9D4F-D56FAB3B516B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4BAB2D5E-1E5A-43A6-A2E5-FCB16339C713} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4C61695F-5D7E-400F-BF7F-0AD75B5AC0E9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4C7888B7-EAAC-420C-A892-DEC0E62D2B60} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4CA4F33A-7284-43FD-A2F5-74D5F6484A28} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4CF511DF-F9FA-4617-90F9-CADC05E559FF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4DA2B270-37E6-4BA7-9E47-15A39EEA3527} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4DC6648E-A8B8-4952-8C92-028CAB66D77F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4EB0CE12-AE26-4040-BE1A-E398D5A8E2E8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4ECF27B6-8D2F-4CD0-A21B-5ED30D804021} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4F1AAD60-E881-4CAB-B5D2-3CC3B6C350CC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4F2CFF27-AE2E-4A6F-A842-445B6994FD2B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4F526ED9-8664-4B3F-BC63-398BE290CDAA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{4F700D3C-E973-4CDA-BDCD-61479BE5A4A9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{504CBEFC-FC1F-4DE6-9A83-F326309CAFD1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{509570E7-8B9B-49FC-BCEA-ED8E0D9D23FC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{50A18260-D788-4583-AEF9-0152C7C5C84E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{50C0F624-AA78-4114-956A-88C59915BCA5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5115F33E-5A8C-4123-B036-8FE27B86BDC3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{51287202-550C-47EC-921D-CCD4AAE5D246} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{51583B27-8748-490F-9DCB-7175826CCA62} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5198C62B-CBB1-4F28-AE5C-04FD602C98E4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{51EFDBF5-F85E-4EC0-953B-FD242B4F1B3A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{525563E8-5222-4551-ABFC-28995D2AE8C7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{52583B30-8BEE-4D0A-A491-A9B1E34DE78F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5260B69F-1375-4873-8CCF-1E82C694CC26} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{53CD7182-A86B-4145-A794-0C1F29036DB5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{53F7CDD9-F587-4FAC-8E8D-D0A5F1D88F1F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{54368724-1A24-4B5A-A7E7-82ADDEDAC568} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{55045FCA-E59C-4608-9986-C90342AA02D0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{554A6A6E-7E6C-45B5-8FBC-13FC6A904E2C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{556A9BF7-8515-436A-AA12-B25187A18A53} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{557D8CDB-59FB-48A8-8326-754DCBE06089} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{55CA91AC-FEC6-4719-9D3C-005D7C83AF1B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{56253835-415F-426E-B844-3DBC352DB922} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{564A7519-C5E4-4309-B13E-B9683EE6FBA6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{56747795-BD9F-4D0F-83EC-E972BF898CE2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{57B7C460-7694-472E-9669-DE982AEC91C6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5876531B-E308-4C33-A104-9F9884E88B0A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5878464C-5E35-45D8-BE3E-8BFBBE6D1B5B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{58F704E2-3A0D-40F2-A9F8-5118350D1BCE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{59032006-2459-4557-A6C1-6FADBA193966} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5979BFB5-5B69-429D-AA0F-7E4CF5F13590} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5A335EEE-21D5-44F5-8C4E-D7F876D70F85} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5AAA52CB-E3C6-44DE-9E15-D53277786967} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5AB0EF5C-38B9-46C6-9B21-6BEDCDCF7168} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5AE13DE4-BC3C-4823-9CBE-6C8ECF4F4147} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5AF5E900-4217-4773-8506-58B8595B40F0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5B43970B-32F8-4D95-A9F8-E617BBCA149D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5B4A41D4-A4CD-4051-BA28-3076E6BA2081} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5B7C6DF5-5C1F-413B-9D79-CCDC2F223DA7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5B86EF6E-8239-40E8-8BA9-DF72FB0C573D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5BB247E5-9389-4FA1-BA01-B68BE30BAD95} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5BDA3A7D-F84E-4873-8648-9D973EE3799A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5C16706C-C75F-4136-A5D8-4AEEE64E98B3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5C282254-AA44-4905-B62A-B4D51F9A0235} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5D296993-73B7-4EF7-8674-0BA838510B87} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5D43D7FC-6A87-497C-81D3-5EA4CA73EE4E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5D5EC44C-6990-47B1-89D2-FE10F5C93E83} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5D8169F9-5265-4304-9F25-2B4FBEB0FDC1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5D9CE4C9-4F57-4D7B-B88C-EE9634FBDDA6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5E361B9A-B4BE-4E00-9B50-1F51E19FE257} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5E82B2AA-E075-48C5-9F47-E577D7F69D32} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5E9270B8-3CF3-4741-9CD2-BE79994D265E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5EA5EBB2-A9BD-47DC-BEAB-ED35ECC16D48} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5EBA356C-82CD-4BA0-86A2-151EA9D97240} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5EDF7986-A499-4307-8F77-87E9741F2B64} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5EE01458-A096-4AA3-9B58-32288286BB4B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5EF9FACE-B7B1-4985-9627-59DFA03D525C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5F017F68-C922-4426-B071-523430D767CF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5F1CB9D4-2469-4CAE-BD2C-CA705E286141} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{5F3C6A3D-13F4-49E7-BBA5-1577F32E5C98} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6025A387-47AA-4294-AFEB-DB1860BBDA04} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{60C5059E-575E-4782-BACB-261DE3EA2880} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{60F8F5B0-3B4A-4B7C-B4FD-BA619835F054} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{612D6925-5BDE-40D3-A825-7D8F50086C43} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{627DA7FA-0302-4952-806B-2CC7C4DD48D7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6284E674-6074-40D5-A599-DCF26BDEDDC1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{62D85908-4185-4387-9D08-4460F79955AF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{63D0FEF3-6132-4403-A086-53DCDB7549EC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{63D3194F-6E08-4E2C-B72C-CFCF350994EA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{63FA28E6-DE22-4327-8DE3-48B0ACE4A8EF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{644C3145-1548-4D24-9A6F-4350254A7F4C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6453C78E-57BC-4AF4-A644-FAF475EF49D7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{64A56378-33EB-441A-8262-0D93DA2217B2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6512280D-5462-40C7-BD13-DA47BD23A946} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{65DF9199-F4CE-4DFA-A933-D961BE75747A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{663A31DE-DD66-46AB-8644-763BA71F1768} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{666CF897-7BF2-4D5C-9836-32D29D000FA7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{66B23AA8-DB22-403E-A09C-5804F62B7935} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{66EBD147-5578-47AC-9BDF-2B13B0442896} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6759CF6D-5071-4CCE-8731-0D17B99CDBF0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{679A07CA-3044-419E-B194-7A4E5200198C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{67DCFA1D-E7E9-44C9-A26D-41D35DDE1F62} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{687DCF89-1B08-4A9A-BACB-D2870DB061CC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{697A0DE3-CAC2-4317-8BB2-2C15164EDBDA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{697F95DE-1452-4CE0-A45E-D1B65B308726} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{69D51EAF-036F-48D2-9AF3-27574C1C4763} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6ABDE53E-F877-431B-81F3-AD3ABA940662} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6AF0B4E4-33D5-4B5C-9797-7A99D3CF7F1E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6BC11596-07C2-49C6-A212-39310028496D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6CE2ABE6-4418-43A6-92B7-1D276544ADB1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6D259E77-81E9-4C22-85A2-3BEDAF8D390A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6D3A9755-FAD0-4C0F-8AFD-E9D197C74B86} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6D509421-63B4-4FFA-923D-E4FFB5FB3FA0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6E081925-B4E9-4E38-B17D-FE66DF2EE603} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6E0E009E-83D3-4274-99D3-DF70AACCD747} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6E198DF3-7275-4BF5-9C2B-10766369A675} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6E575434-BD9E-48EF-8749-DE8042E8E81C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6E65DB0E-4E88-4B37-BD41-FFA42FC23DAF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6EF6AA76-9BBD-4D59-B16C-09C6804218EE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6F00691F-132A-4D02-A30F-4E63BB9DA26C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6F71E85A-B7A2-4CAC-ABEA-A2D7DA042BE6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6F752613-D0D5-4F6B-A367-38B6B8038439} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{6FE54BBA-DA0A-434F-A86D-D4B77DE077BD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{703F660B-2DA7-4908-B750-1E1A0EF856F2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7092C84E-67A5-45CC-9D0A-AD326AEE742C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{70987907-F1E3-4DE6-8253-25754595127C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{70B1898C-6A15-4DAC-B2F2-1F5AD8D8DC40} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{71D3B538-B494-40F3-9286-02613EF4C0CD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{725B8843-55D7-4FB5-8C37-93A75FF77710} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{726A3BCA-79D7-4DC7-8A5A-C5128A3C553D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{72EC1097-D543-42FE-94D5-84E113CCFB61} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{742746EA-3C08-47AF-A3F4-129581A54B24} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{74311F99-E9CF-4D4A-93E7-ADD29D977FDD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{74475ECD-B7A7-4AF6-B879-8657A392A603} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7464A76D-97DA-479C-AFFE-320673FFFEDE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7482C80D-D122-4938-B0F7-23F6A7EEDB7F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7489315C-CE71-47A4-8FE5-3242035603FA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{74EBE2E7-6D72-4C25-A437-E8DF0C2E87E9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{75416DA2-E460-4B37-9D9E-1D4F7C48C8C0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{75446E9E-5C55-48BF-B028-1B137CEFA745} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{75CB9911-0E3B-4137-B79A-BD3367760A22} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{75D1487E-9785-405D-8FE8-27DAABA4751C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{76A24CCA-3C73-454D-A750-E3D8DAA69742} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{76D62C05-B9F4-4E68-BCA4-09F247C1388D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7758BF06-59A2-443C-B252-3C078CAAC2B4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{775CA3F7-AD33-4C90-9286-07009B2CE6D5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{779F85C0-C2DE-4655-8019-6A815DFA9E40} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{78186516-2D8D-4C40-851A-0DC2D42E47F7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{789C96ED-58E6-48EC-9852-A987F2341CBD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{79010FF2-4237-43A0-86DB-26D00B467054} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{79491958-D914-4FBC-AA30-BAA7A3B16A9F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{79FD4358-6920-48A4-BD02-7745E9EA1798} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7A1B24D4-9483-4680-9FAB-693D4C9FDFF2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7A3C5C3D-5CD0-4188-8818-FC21FFF1159F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7B3A0F9E-ACB8-48DD-8234-7E06EFAD0DFE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7B5FEA60-7C5C-4ABF-98E9-97DE712A5947} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7C0DEC74-51C7-4A48-8C21-CCC0F0F47F3A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7C4F0112-DFEC-44EA-B790-CD06DECDDEF2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7CAA2272-B09E-42FD-A4EF-38B1BBCF0200} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7CAF87B8-B1C8-4F25-9D52-08DEA37ED01C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7CBC86A8-89C5-4B46-BDA6-A0D37CF04EE2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7D079320-F8F4-4D86-B7E1-A59C34319311} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7EA8001B-0B5B-40A7-9088-F52E2DFC8A26} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7F1F0A93-AC70-4C61-AF8A-C89D833DAD4B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7F3B6D6E-B46F-486B-92AC-C11B8DAFB940} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{7F9DBC00-C7AA-4805-98EC-AF14436A525F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{801436FE-501C-4D06-9CBC-BA1EADDA3A94} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{801BE250-3F54-4768-AA8E-67893C0C9D3B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{805A884F-15F1-4FB0-9C8C-1F2637CA83E8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8062CBB4-8917-44E1-B8AE-6760AE41ABCA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{815DC1C2-E57F-46BC-B0D7-86D498F51E6D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{81747FA6-6B20-42C1-8C08-426FB9E687A4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{82BE8D0C-1F6F-4D32-AFA0-402674C7B9D6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{83C46080-8E59-4EDA-9667-107614AA08EF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8438DF82-6752-42A2-9550-ECEBBED2D55C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{843C80A5-7D8E-4131-91DF-61380A7503B3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8461BE84-D7AF-4088-9AA1-0364FB83156E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{848062D8-4E54-4502-BF64-B82F208B52E0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{84862008-D890-4BC3-88E2-1490DCEFD613} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{858789A2-90E1-4678-A35E-F8CF360E893D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8596C975-C62D-41CB-9A27-CBBAF5F3BD47} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{86F959A5-BDE2-41C4-8D26-09C32C9F2F3C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{87B13B32-DB41-47D5-9A4E-9D4483493F6A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{87B1931C-5FA3-47E6-B5E2-EF6C54D15D21} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{88147F42-0CAE-487C-A982-7ACCBE97670D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{884F219D-6954-4FE7-916B-28D3046B0864} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{88680758-F973-4E48-BB16-AACCDA90FE9C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{88AEB4C6-7532-4678-BBDE-3A01CE51D4E6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{88CFD929-4B05-42B8-A373-DD1BE7A1D38D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{88F0F7F4-D098-41FD-934A-0DC82439181E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{89339318-5BE1-43E3-B0E9-6FE6025C21A6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8935BC3B-A006-4CD8-A47D-E54E3C610C6D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8AA4D38E-54AF-4B93-88C0-D48E6B99F86F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8BAC085D-4DFE-4DF7-8A7D-B22DCC3E645A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8BD5513D-E2ED-403C-B56C-5834BAD4DD49} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8C2139DC-7978-4E6F-831A-9D589AED0EE4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8C2F3C82-9E2F-4866-BB1B-3A8DD9D4AA4A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8CA19F5D-31AF-4725-8E68-BEC081B0456E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8D20B5EE-023E-4F7F-9D18-6EDC15B194D6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8E2FBABC-47E6-4041-93F9-16BCF519B56D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8E7F7AA2-9469-4C63-8F8D-C79219E7E2D1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{8F3F5E6F-DCA9-4522-B378-67B0716787AF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{914253C1-8A47-477F-BE9D-129472C876B3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{914A76D7-B9F3-486E-9697-5B46C2C6CA3B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{914FCE1E-CA4C-420C-BBA9-80240F0F1A5A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{91A805A1-6737-43D1-A437-60F189EAFB24} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{91F9DBDD-3D98-4DF9-A7C9-543627D9F839} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{920AC4A2-35BC-4130-AA1A-C3A50D213AF9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{922E7E43-FF4F-45CE-B7BC-8AB181250431} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9236F0D5-97DC-43C1-AE61-2BE456238B56} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9290BD96-73AE-4A27-B04E-98DD00A83923} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{937E2839-CBEF-4D9A-82BC-E2A5288B59D1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{937F1749-CB2C-4006-9BF0-17C34FABA48C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{947D7F0F-C3F2-45D3-935D-43B085788883} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9486F779-F010-4D53-B8F4-1FAD75EB170D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{950C46E5-114D-4DB8-B952-04BBED03BF2D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{958912CA-6B1B-4CE3-AD50-B9A9AA43B01F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9597179A-1B4F-40FC-B149-52AD192A5316} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{95D8191E-CB6A-4822-ACBC-6FA8FA0171FB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9740FDC1-043E-4BD4-B714-5DE2051C9E91} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{975B11A2-A2D6-40C0-88CC-13CC7F628E5D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{980251EE-22D7-4808-BAB6-1A8457E287A2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{981859AD-C0E3-49C0-BAAD-05A4D57CD296} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{981CAD83-4A8D-46B9-B718-4B0D09635904} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{985D4E6F-A1C6-4B55-85EC-EB5050A5AFD5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9904303B-F0F3-4077-96D3-057AB86139CB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{99ADB062-8D95-4038-A813-A78D3B1AFFAC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{99B1F1A0-E2DA-470B-918F-48FDFB79A738} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{99B70322-BB36-4797-B0C4-A0F3EC138222} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9A0F6FBA-5374-460C-987E-AF84C00E8595} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9A485522-79A0-4A32-BF4C-4F2E2B4E1CB7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9A96B09A-AF68-4CAD-95D0-01B25154B83B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9AC8E056-B574-4088-B1BD-DB020A2A5D1B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9AFFC734-2740-44E0-86D3-C937AD180D0C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9BCEF7FB-835E-4B90-A41B-EDEFB5FEC027} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9BD3EBEB-E3BC-4874-BE7A-D7DD84CE144B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9C56BCA8-372F-430B-BCAB-835A2189B072} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9D20CBE0-6129-4DE3-AF53-01BDA1BD7E5E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9D740EB7-23D3-40AC-B9BB-3FA04A965437} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9D802650-7685-4C4D-9B84-0B89E05C1F43} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9DBD3F69-1E89-458F-961D-1B6994E81A26} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9E4E3FF6-CC35-4281-830C-CAE5CDE899DF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9E50FCB4-50E3-4445-B7FF-6DA2D3715F36} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9E5514C9-79A2-4D01-86EB-8F67292C4324} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9F5154A6-40C5-4427-B2DE-70E4F52FC9C6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9FB03EDD-6CC2-49A6-B821-2154767462E9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9FD766D3-27C4-48E7-8307-C5921725AB45} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{9FEB472E-579A-499C-A4D1-40BD27BBEF9E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A0F0AB33-7BD6-4034-95CE-5367B2F85C5A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A17AA705-EA14-41DD-B774-D53EE5B730A2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A1960E18-752F-4F2A-97E5-9EA197C7F252} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A1C25CBB-A797-48C3-BF35-7D1536640CC0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A3864A98-B30B-4D57-831E-AB1D53D12584} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A4528F71-38B7-4DDE-8DFC-1822B8B9E7CE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A472E45C-B5A6-4BB7-A11D-CE484ED6AA4E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A489775B-71F8-43CD-9594-EA356E2E0FC8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A495251E-164E-421D-BD12-61D65D1942C6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A4DBFCB5-08A4-4B8B-B2C3-82D33AADF27B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A4DEF742-DBF3-425D-AD13-1AB56A3E4C02} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A5206EA2-EA77-44B2-9A3D-5F79A0C60C51} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A6949D9A-0219-4151-8AD2-722CA0AAEAA6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A6F33F8F-CF19-4ADB-8E54-EA36249E8CDD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A75FD1D4-EB7C-42A8-BE32-D184ED84B7B0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A7BA1FEA-E2B9-47F8-B0F4-7BE55A48C6DB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A8CA34D5-ABC8-4BAD-BB83-F0205F019F2E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{A940EABF-81F2-4F93-8485-9AD3AC99285C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AA371F25-FB8E-4A52-A60F-2B4FD6AC0A62} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AA8469EB-3D90-4369-99CE-FEEC006A32C7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AA8A9273-DA7C-4E8A-B8E2-7FF16CFB04F2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AAEE22B9-215F-498E-84C5-049A5FFB22BC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AB9525BA-DD63-4A35-AE7F-CE8AB6CAA757} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ABCDBEBF-D694-41F7-B192-6E8F114E264D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AC60D47C-C088-48AE-AF3C-C5B278363E12} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AC9BC217-5D7D-4915-983D-1AEE9CE57238} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ACA00617-552E-452C-AEEF-2A99FCBC690D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ACFE339F-74DF-4E55-87EF-43C0D2FEDC4C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AD59E313-C9C7-4294-AC81-EB7EF11B567A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ADAE054C-64E2-409C-806E-44B6A435170F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ADC975B5-A7CC-4B2A-9109-CAE81777A34D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AFB6F550-277D-46F6-811E-115718A2FCFE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{AFBC8767-FCC5-4BA7-96A8-C61B1F15E967} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B1104323-8179-4B28-8428-510C6B7F8637} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B2365E4E-4E3A-453D-924C-3596C7A57C64} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B40C47F0-ACEE-4900-B5DD-FDD5CE69A3DE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B44A6963-CDC7-45D3-AE1B-EF4350BF5AD1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B5A4DD24-F293-48E4-9B59-776002370137} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B5B7D54F-B037-4547-8C83-8548E0E66160} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B764910D-43B0-4A2E-B937-936E7F43B989} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B7A39A40-BF4E-47C9-825A-9BE7D14DCECE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B809AB44-3AE4-4C8E-AC5D-CC454A288475} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B915F452-4048-42B3-9264-B2EFBF6B954A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{B967F5B0-F8ED-4665-B8E0-2FFF2D437D59} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BAF6C44E-B8BD-4892-9623-15683ED57DD9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BB1A1C89-428D-415C-B20E-645C6BEF953A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BB4DA939-5239-4C34-AB79-A5B7D73FF38F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BB50CF48-C958-4FB2-9EBA-CF80FB18A8DA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BB668868-6FD5-4D1C-AB51-01B8930E5D8D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BBC6300F-9999-43EA-9771-14CB1076EBFC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BBD790AC-62E5-4D82-A62C-1FB86E660C51} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BC05C029-75DE-4B44-AA63-945ACB3331AD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BC923BB6-A57A-4D09-AB49-F2BBCB4B9527} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BCCAB7B4-60D8-42EC-A8D3-CE759F257A64} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BCFF82CB-C476-4E12-86A5-01633E733B2D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BD2AE9F8-9175-4EA2-9F8D-C16C8BB8EA75} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BD591E95-3493-45A3-9E7C-FD97AB29BFA4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BD74B4F4-A308-4DF2-9EAE-DDD57C4CF561} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BD77FEC5-3E55-4499-94D4-AE906A0FC831} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BDFBB7CC-979E-4F7F-B996-EB721DBF76D2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BE6C3768-40D4-47DD-AFFC-D0334A27884C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BF214747-76B7-4BDE-AA00-4306B7F67534} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BF60E3DB-CE7B-4E08-9907-8424E700AEF5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{BF81BEE7-22AF-4595-8D2E-C68A3E6C1958} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C0AF3CB6-5923-4F25-B886-B416ACDAA991} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C292999B-9B9C-4EF8-9776-FDCC7BBC38D8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C3828B42-7D44-4DB8-9D67-9B6BB07542BE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C41B65B1-734D-463A-8144-3CD9ABB968BE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C41CB0FE-DD2F-4B6B-A093-7D619303C0BE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C45347CF-66A8-4D89-A33C-ECF412F6220E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C4733D29-E093-4C6F-A770-664E0443661D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C4774EB5-647A-40D6-96C2-0DF067C1DB51} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C4C771DB-83DE-42B7-B6B5-9FC53C8B450E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C5A41561-02E1-4A10-9AAC-D2512D833D1B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C5DE2ABE-CB66-47B2-B822-00E244B1D50D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C5E751CC-B691-44F2-A59A-CB5F4527659C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C5EE4650-24B7-493E-B30E-005C9CA2EDAB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C676D7EF-D126-4EE9-9BCE-3BEFB31C640E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C73F524D-F8B5-4A39-A876-DD135406652C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C75DC56C-64B5-4D98-99B4-0BBBF3F8748C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C77E6C7C-D8F8-4795-A7F2-2413C8B9AE9A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C7AA31E3-1B38-4658-AA92-CFF3ED5C23D4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C7DE54EC-AAE1-4197-B97C-A5F74D11D832} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C88AF27A-9082-492B-99C7-D2E647B0ECFA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C8FF54ED-B534-45BA-90A6-D5ECC99F5478} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{C9D76D2F-A4B6-4E03-9F22-B67254BBA81A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CA517E6F-C1EE-4E1D-B842-0F970311AC7E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CB004C67-6790-4B2D-8D4A-26452AAFC033} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CB367C4C-6A3E-4D81-A90A-312C39A5D7F6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CB3E8481-8975-4F73-A78E-D8FED24A2EF4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CB6A198B-9756-46F0-83D5-5781EBCFE882} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CB925673-02D6-4BFF-BD16-B2906B31A8F5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CB9CB3F7-6507-437F-B8F3-58260251E1A2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CC83F24F-5597-4C1A-8277-512F7AF3ABD1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CD42B462-3735-4468-86C9-AC8EAB7350C6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CDC822A4-195D-4EB0-9032-0CBC9B584DB9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CE17D3CD-C4A5-4B5B-987C-EFE955422250} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{CF89EC42-90B1-4825-B2BC-D28072165110} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D07B93D9-CCCD-4504-82B9-A8EFBEC46CBD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D0970380-43A4-4899-B661-08C4DEF98F1C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D10E1DE5-61DC-44B7-8A8A-30A7C861A7E6} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D1757385-2798-4D52-BA11-5CFE196074A7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D1C1F84A-9089-449B-BBE4-6CAA45BC8766} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D22425B7-726A-4C59-8607-F3888ECA44FA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D23E9FA1-0C43-4AD3-819E-C19C14DCA267} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D2D76951-12F9-4944-8B25-AD1CF1B7F00D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D2F7CC6C-F4E1-4F91-B7CF-4C2DED69271B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D3CAA506-3E68-4ABA-BD1D-71A5EC371491} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D3FC6C77-A91E-4658-B858-69672D2E58E4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D403CCD4-08DC-46BC-9649-1E80BAACF644} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D4EA3F1C-71D6-4E74-B368-B1850A9CAD13} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D50EC89F-3C04-478D-A899-0302A9F8A06D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D59EE730-42F7-41A4-B0DA-F2AAE48710E8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D6097AC8-6BE7-4364-9017-3F9364C9EACB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D7200742-6FB0-47FB-96B9-6217A13F31A1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D7329683-20A8-449C-BC07-C8F62B05A042} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D7546F26-A2CE-44CF-BA9A-9D9777D10244} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D75BAECA-7FA4-45EB-BA6C-45A97EC45DA5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D8509672-D54B-4D77-833D-953D022DB245} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D8DA4B9A-05ED-49CB-B659-6014008C09C4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D91ABDAE-E7D4-442D-A870-ACA383D1285B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D921C76A-1F63-4D2C-A1AC-0359B009C96A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D9A2DD01-3FA3-478A-98F8-CF48C5458713} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{D9B9CC32-9378-4D70-8A23-5112B877E427} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DA29445C-CD9B-4A26-B4F7-5261BAD7232A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DA76C9F3-2F18-4132-ADDB-146EF13EA832} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DA7A811B-33F3-445A-BB81-189D5070D26F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DAC1004B-E661-4138-BAA7-A0D688975815} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DB1CED3C-3C85-426C-A783-E7AA77E2C339} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DB418EAE-5AB9-4975-ADF2-7E51FF08099A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DB67F84C-8840-4791-B4E8-8117D4A53A10} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DB7ED190-473A-4394-89CE-2E4E96EA52D5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DB879A9E-3B7B-4F7E-AFBE-FF08B56E9292} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DBA1812A-0190-4495-AC45-C1B104957E31} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DBD851FF-88B2-43EA-B98D-6B5FE58C1213} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DC373134-D340-4A9B-8D9A-D04FBE49CF4D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DC3A3DA5-CEC8-4242-85F6-C511D29B03FC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DC667FEB-2351-4449-8725-C2C1D9C9A475} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DC933990-73A8-4263-8203-6B9C34BFCFBA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DD02CFB5-2E38-4BB0-9AF9-5284F8B48E25} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DD1EC61D-99F8-47F8-B233-861F2F898E5D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DD503284-2087-4605-A5E2-613E8F7BA955} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DD55EC50-626A-43D6-A571-9BFAF60596EE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DDAC4A73-E3EC-4A36-ACD0-AA3007C5D987} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DE2BBD35-BC08-4C08-AC91-508A9D8FE111} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DE3DB40F-CC93-473D-8152-822EE2E296BE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DE714827-4F9B-489B-910D-AB77678CF69F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DEBAC657-1765-4B6C-8FC2-0FE72633BB0B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DED887E9-94F3-4B72-ADE2-BFD44734782A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DEEF3C93-5EE1-4A1B-B1E9-2359018A0E46} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DEFC05FE-E22C-40A7-8BD2-409F0F630D56} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DF001A18-F45D-4AE6-90AB-1023EE810CD4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DF770FA6-3393-4D5A-96CF-CE25D9B783D8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{DF790A99-E1BD-4B3E-94B4-4C7471591A09} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E015A56F-8C39-4229-8CFF-2266CF3DC710} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E01A4791-5E3D-4B9B-816C-96C5ADF5D8C8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E036BD34-9DED-4DBD-86EE-4E7ABC13197F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E03D3519-02B8-482A-AC57-8527B0CB4BE0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E11294B6-C19F-48CD-A7DA-C1F74E0CADD5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E13B8034-9A02-4C38-BFA0-DA2A97EC768B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E15617ED-5C0F-45EA-8FE5-F692EAA6190C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E18C80E8-A36E-463D-A3A8-3BFAE22886C7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E1B81F37-6A6B-4963-A9F0-6898419ABF43} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E22222DA-9199-4286-B769-584C8C449DC9} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E26D18D9-0574-4862-8051-2829BCD571CB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E2B44A0E-E461-41FD-A7A5-264FBD035CFE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E38D5AC6-F659-4EDB-8F8A-55DBA46694B1} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E3A2142B-76E8-477F-B6A3-2DAB27FB468B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E44D4766-B73A-4492-BA0D-BF87151C6F42} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E45D308D-755F-4D26-B1E0-EDC60871E0DA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E4862936-550B-47A3-8AA9-72E136E8F259} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E4C73EB0-5A83-41D7-A9BE-B8F1582D6FAB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E5FC41E2-7A39-4FF1-BE7C-A2EC0BC531FE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E688F29B-C16B-496E-9E3B-F0FBED93B824} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E6A736A0-D155-40F7-8A98-CD9CB01D58BC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E6E62DA6-21B4-4055-AC21-7A7D8F6F42CB} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E76363D1-9ECE-4FFE-95F8-19C844D3AC0C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E7668554-BC05-4BC7-B657-031C2800C4E3} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E78CAA07-ACAE-4303-B70A-E20F84B4CA79} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E7FD8900-E9BD-435D-8CC6-65C13CABF92C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E83DCE3C-42A8-4BCE-A7DE-F6EFB7E88331} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E84D732D-F2C2-45EB-9133-6E799CEBB103} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E885D9BF-02BD-4D6A-B7FD-964F1BA57255} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E8CE91D2-9DD1-4368-AE35-4234817E09F2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E8F3C7A0-26BC-4D53-BA48-F9BD65D60A55} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E9329D49-5A95-419A-AE8A-2F7A8C8034E2} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E99ED14D-1B81-4096-A02C-966BAAFE507A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{E9BB958C-A0A0-4CC2-9E7A-30392830BD50} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EA416FC9-3425-44E3-8CBB-35E527F858EC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EA59E33C-2C8A-4BEA-BBF4-702241B02D42} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EAB4FF7E-994F-4FB0-B495-CFBCD4CE6A63} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EB19E659-0C9F-4511-9597-FE882CC64AD0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EC323FAE-F7A0-41F3-8784-AC03CA646E7F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ECF3F1C6-8726-40D9-95EF-79EE91A5A72B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ED0633E1-0C84-4752-95A5-5FFFB9519C7E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{ED9AE33A-CFD2-477A-8AB3-73708766285D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EDC8695C-834B-4292-AED6-726D9A0378B5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EE28A190-B09A-4986-B10D-AD6E5A36AC9D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EE4DE9BC-EF61-40EB-A076-E9D82FB9A1E7} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{EF95EBA5-72DB-4569-88A3-C2D2B9BDCAEE} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F05616FB-4AD6-423E-B4C7-BEA655B2284E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F08B3EC8-66A0-4B94-8CF0-4F3E889DF1FD} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F0B79990-2F7A-438C-B833-983D1C0653E8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F0B8B3AD-E748-49F7-993E-4DC7CF8EF9BC} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F0D06A36-B05E-482A-A51A-923EF0108780} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F0F9D9A1-37D4-42FE-BDDB-CEEF0E3533D0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F0FF271A-0CCC-4735-834B-DDA9C2FC3F70} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F133CCF0-9C18-4590-A8AE-1B4B562C28E0} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F1FCBE89-0E36-462D-AB37-8B88D83D2916} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F21B0AC2-82E2-4B72-BB2D-5170B54950F8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F2632BB4-1EBE-4D81-85D5-F75C80CA2D3A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F365851B-D8EF-4C8B-923F-2A69F3BFFFC5} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F3759A4E-6656-4B3D-8228-DC79FB1DE38B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F609AC26-5F1F-46B3-8E65-5047C30E4B36} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F61A9877-D826-472C-AFAC-1867081E91EA} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F652F5FB-547F-4F5D-AC79-53493C955940} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F77AF701-0F6A-4204-A826-14222D170CC4} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F808889C-D94A-4350-9C1A-F1560D533DAF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F884BF86-872F-4D30-BCBD-2E8EE7ED2AEF} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F8F662CC-0933-467C-A4AD-9AE786EE7E9A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F9585446-BBAA-4C43-8A0F-31D927E53351} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{F95940EE-F59F-4071-A353-A821B045EFC8} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FA30A8C8-D695-4DDF-8569-2EBCB0294C3B} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FA4BABF8-0EE5-4A3B-B170-C26438E3EA6C} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FA6E6FAF-E743-4628-9CC8-F15EDF54B129} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FBD2596B-C8BC-489D-A7BA-1951243B9D34} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FC295396-1CB0-4985-965A-0552C780226D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FC70E719-C980-4911-9964-922EBF19F49E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FCF49D86-352F-4BB5-B6C5-C09F6DE0CF6F} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FDF39CE1-F24E-4DED-967D-6AA7FF5FCF96} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FE305755-543F-4AC3-8F08-6F928E5D6B0D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FE3DB65C-2780-4A0E-A0DB-F796314D100D} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FE9F94CD-B8D0-4F39-9FC5-CF7B60E0571A} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FEAC33BE-7FB3-4E31-A436-40D3B8C0EF8E} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FF71D0D1-C597-4142-8B81-7DA9B44CBA77} Successfully deleted: [Empty Folder] C:\Users\cd\appdata\local\{FFA90786-0907-46F7-8553-EFFE93A366D5} ~~~ FireFox Emptied folder: C:\Users\cd\AppData\Roaming\mozilla\firefox\profiles\opfibqbw.default\minidumps [7 files] ~~~ Chrome Successfully deleted: [Folder] C:\Users\cd\appdata\local\Google\Chrome\User Data\Default\Extensions\aoiidodopnnhiflaflbfeblnojefhigh ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 06/15/2013 at 0:06:12.65 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Thanks again, Gringo. Dave
  12. About a week ago, my wife noticed a desktop icon for White Trader. She wanted to know why I put it out there Told her I didn't. She deleted it and of course it popped back up with a balloon at the bottom, "You have not used this program in a long time." Researched it and heard about all of the Windows Explorer crashes and I started getting those along with error messages about problems starting ...\wow.dll. Getting worried since it snuck in. Here are the logs (hope this is correct): DDS: DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16490 BrowserJavaVersion: 10.5.0 Run by cd at 21:33:20 on 2013-06-14 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5589.3265 [GMT -4:00] . AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Users\cd\AppData\Local\Google\Update\GoogleUpdate.exe C:\Users\cd\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Users\cd\AppData\Roaming\Google\Google Talk\googletalk.exe C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe C:\Users\cd\AppData\Local\Vivox\HDN\Current\Vivox.HDN.Up.exe C:\Users\cd\AppData\Local\Vivox\BSN\Current\Bobsled-Notifier.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Squeezebox\SqueezeTray.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Users\cd\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Orb Networks\Orb\bin\Orblauncher.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\ProgramData\TVersity\Media Server\MediaServer.exe C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\PROGRA~2\SQUEEZ~1\server\SQUEEZ~3.EXE C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\WUDFHost.exe C:\Users\cd\AppData\Local\Vivox\VVS\Current\VivoxVoiceService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\syswow64\rundll32.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Windows\syswow64\svchost.exe -k netsvcs C:\Program Files (x86)\Orb Networks\Orb\bin\Orb.exe C:\Program Files (x86)\Orb Networks\Orb\bin\OrbjetManager.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Windows\explorer.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\cd\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE C:\Windows\splwow64.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://my.yahoo.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop mStart Page = hxxp://www.bing.com/?pc=MAGW mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll mWinlogon: Userinit = userinit.exe, BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Bobsled by T-Mobile: {C8748F11-F4AD-47AF-AB50-C7DF5792096B} - BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Google Update] "C:\Users\cd\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [spotify Web Helper] "C:\Users\cd\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" uRun: [googletalk] C:\Users\cd\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart uRun: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" uRun: [VivoxHDN] "C:\Users\cd\AppData\Local\Vivox\HDN\Current\Vivox.HDN.Up.exe" /d uRun: [bobsled Notifier] C:\Users\cd\AppData\Local\Vivox\BSN\Current\Bobsled-Notifier.exe uRun: [spotify] "C:\Users\cd\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" mRun: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe" mRun: [Adobe Photo Downloader] "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe" StartupFolder: C:\Users\cd\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe StartupFolder: C:\Users\cd\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\cd\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Squeezebox\SqueezeTray.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: En&queue current page with BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm IE: Enqueue link tar&get with BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm IE: Open &link target with BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm IE: Open current page with BI&D - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebid.htm IE: Open current page with BID Link E&xplorer - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll TCP: NameServer = 192.168.1.254 TCP: Interfaces\{57C7909D-6430-4ECC-88B4-B0167E38AA16} : DHCPNameServer = 192.168.1.254 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - <orphaned> SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll x64-mStart Page = hxxp://www.google.com x64-mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop x64-mDefault_Search_URL = hxxp://www.google.com/ie x64-mSearchAssistant = hxxp://www.google.com x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Trusted Zone: trymedia.com x64-Trusted Zone: trymedia.com x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned> x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned> x64-SSODL: WebCheck - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\cd\AppData\Roaming\Mozilla\Firefox\Profiles\opfibqbw.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\cd\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: C:\Users\cd\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll FF - plugin: C:\Users\cd\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: C:\Users\cd\AppData\Roaming\Mozilla\plugins\npo1d.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: !HIDDEN! 2012-06-25 12:14; smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . ============= SERVICES / DRIVERS =============== . R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2011-10-26 79488] R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2011-10-26 40064] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-10-26 204288] R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-5-12 249648] R2 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2011-5-29 36456] R2 Live Updater Service;Live Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2011-10-25 255376] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568] R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-4-1 1822296] R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2012-8-28 92632] R3 amdhub30;AMD USB 3.0 Hub Driver;C:\Windows\System32\drivers\amdhub30.sys [2012-2-19 87168] R3 amdxhc;AMD USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\amdxhc.sys [2012-2-19 188544] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-10-26 231440] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-10-29 138912] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-10-25 533096] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 KooRaRooMediaServer;KooRaRoo Media Server;C:\Program Files (x86)\KooRaRoo Media\KooRaRooMediaServer.exe [2012-9-21 4958968] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-6-7 191752] S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:\Program Files\BitComet\tools\BitCometService.exe -service --> C:\Program Files\BitComet\tools\BitCometService.exe -service [?] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-5-21 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2013-06-14 10:44:31 -------- d-----w- C:\Users\cd\AppData\Local\{8CA19F5D-31AF-4725-8E68-BEC081B0456E} 2013-06-12 13:12:50 -------- d-----w- C:\Users\cd\AppData\Local\{F9585446-BBAA-4C43-8A0F-31D927E53351} 2013-06-12 10:56:53 1887232 ----a-w- C:\Windows\System32\d3d11.dll 2013-06-12 10:56:53 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll 2013-06-12 04:07:59 -------- d-----w- C:\Users\cd\AppData\Local\{947D7F0F-C3F2-45D3-935D-43B085788883} 2013-06-11 14:11:28 -------- d-----w- C:\Users\cd\AppData\Local\{AA8A9273-DA7C-4E8A-B8E2-7FF16CFB04F2} 2013-06-11 01:32:10 -------- d-----w- C:\Users\cd\AppData\Local\{2D7E74C8-8304-4875-B704-1B921C8A74DA} 2013-06-10 15:36:25 -------- d-----w- C:\Users\cd\AppData\Local\ElevatedDiagnostics 2013-06-09 20:49:37 -------- d-----w- C:\Users\cd\AppData\Local\{18E90307-3C04-4608-BD44-5385C516A7C4} 2013-06-09 04:01:13 -------- d-----w- C:\Users\cd\AppData\Local\{5D296993-73B7-4EF7-8674-0BA838510B87} 2013-06-08 13:32:53 -------- d-----w- C:\Users\cd\AppData\Roaming\Malwarebytes 2013-06-08 13:31:46 -------- d-----w- C:\ProgramData\Malwarebytes 2013-06-08 13:31:44 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys 2013-06-08 13:31:44 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-08 13:31:11 -------- d-----w- C:\Users\cd\AppData\Local\Programs 2013-06-08 04:00:42 -------- d-----w- C:\Users\cd\AppData\Local\{F884BF86-872F-4D30-BCBD-2E8EE7ED2AEF} 2013-06-07 11:20:12 -------- d-----w- C:\Users\cd\AppData\Local\{6AF0B4E4-33D5-4B5C-9797-7A99D3CF7F1E} 2013-06-06 21:01:46 -------- d-----w- C:\Users\cd\AppData\Local\{5AF5E900-4217-4773-8506-58B8595B40F0} 2013-06-06 06:51:58 -------- d-----w- C:\Users\cd\AppData\Local\{2A6EEBB5-FDDA-46DA-92EF-B9D991E21D26} 2013-06-05 12:12:04 -------- d-----w- C:\Users\cd\AppData\Local\{B967F5B0-F8ED-4665-B8E0-2FFF2D437D59} 2013-06-04 08:52:08 -------- d-----w- C:\Users\cd\AppData\Local\{09F3A1A6-5E99-447A-AF96-C7AEEB84B898} 2013-06-03 23:55:01 -------- d-----w- C:\DVDxx 2013-06-03 22:31:56 -------- d-----w- C:\DVDx 2013-06-03 14:39:38 -------- d-----w- C:\Users\cd\AppData\Local\{C88AF27A-9082-492B-99C7-D2E647B0ECFA} 2013-06-03 09:31:38 -------- d-----w- C:\Users\cd\AppData\Local\{E8F3C7A0-26BC-4D53-BA48-F9BD65D60A55} 2013-06-02 09:46:01 -------- d-----w- C:\Users\cd\AppData\Local\{DC933990-73A8-4263-8203-6B9C34BFCFBA} 2013-06-01 12:49:00 -------- d-----w- C:\Users\cd\AppData\Local\{B915F452-4048-42B3-9264-B2EFBF6B954A} 2013-06-01 04:31:59 74136 ----a-w- C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll 2013-06-01 04:31:59 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2013-06-01 04:31:59 19352 ----a-w- C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll 2013-06-01 04:31:59 116120 ----a-w- C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe 2013-05-31 23:24:47 -------- d-----w- C:\Users\cd\AppData\Roaming\OverDrive 2013-05-31 23:22:16 -------- d-----w- C:\Program Files (x86)\OverDrive Media Console 2013-05-31 21:37:58 -------- d-----w- C:\Users\cd\AppData\Local\{6BC11596-07C2-49C6-A212-39310028496D} 2013-05-31 04:27:48 -------- d-----w- C:\Users\cd\AppData\Local\{B40C47F0-ACEE-4900-B5DD-FDD5CE69A3DE} 2013-05-30 13:09:34 -------- d-----w- C:\Users\cd\AppData\Local\{62D85908-4185-4387-9D08-4460F79955AF} 2013-05-29 18:56:50 -------- d-----w- C:\Users\cd\AppData\Local\{83C46080-8E59-4EDA-9667-107614AA08EF} 2013-05-29 06:56:15 -------- d-----w- C:\Users\cd\AppData\Local\{1BBDA8FC-14D2-4AB3-B07E-40DE3C265E64} 2013-05-28 05:02:46 -------- d-----w- C:\Users\cd\AppData\Local\{74EBE2E7-6D72-4C25-A437-E8DF0C2E87E9} 2013-05-27 06:11:57 -------- d-----w- C:\Users\cd\AppData\Local\{23C52325-145D-4D9E-95F9-DFA8C96493B2} 2013-05-26 12:23:08 -------- d-----w- C:\Users\cd\AppData\Local\{8062CBB4-8917-44E1-B8AE-6760AE41ABCA} 2013-05-25 22:04:37 -------- d-----w- C:\Users\cd\AppData\Local\{F0F9D9A1-37D4-42FE-BDDB-CEEF0E3533D0} 2013-05-24 21:33:03 -------- d-----w- C:\Users\cd\AppData\Local\{848062D8-4E54-4502-BF64-B82F208B52E0} 2013-05-24 07:01:55 -------- d-----w- C:\Users\cd\AppData\Local\{58F704E2-3A0D-40F2-A9F8-5118350D1BCE} 2013-05-23 12:36:53 -------- d-----w- C:\Users\cd\AppData\Local\{AD59E313-C9C7-4294-AC81-EB7EF11B567A} 2013-05-23 07:50:03 -------- d-----w- C:\Users\cd\AppData\Local\{ACFE339F-74DF-4E55-87EF-43C0D2FEDC4C} 2013-05-22 18:12:27 -------- d-----w- C:\Users\cd\AppData\Local\{612D6925-5BDE-40D3-A825-7D8F50086C43} 2013-05-22 05:16:35 -------- d-----w- C:\Users\cd\AppData\Local\{50C0F624-AA78-4114-956A-88C59915BCA5} 2013-05-21 03:58:31 -------- d-----w- C:\Users\cd\AppData\Local\{55045FCA-E59C-4608-9986-C90342AA02D0} 2013-05-20 05:30:19 -------- d-----w- C:\Users\cd\AppData\Local\{65DF9199-F4CE-4DFA-A933-D961BE75747A} 2013-05-19 01:44:52 -------- d-----w- C:\Users\cd\AppData\Local\{02DD636F-8A0C-4C81-8F23-F1F4BE222C18} 2013-05-17 23:30:40 -------- d-----w- C:\Users\cd\AppData\Local\{8C2F3C82-9E2F-4866-BB1B-3A8DD9D4AA4A} 2013-05-17 04:11:29 -------- d-----w- C:\Users\cd\AppData\Local\{3701C0A8-1FF8-44D0-9DB1-1DB351DC0930} . ==================== Find3M ==================== . 2013-06-12 07:46:11 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-12 07:46:11 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-05-17 03:09:56 2312704 ----a-w- C:\Windows\System32\jscript9.dll 2013-05-17 03:02:29 1392128 ----a-w- C:\Windows\System32\wininet.dll 2013-05-17 03:01:13 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl 2013-05-17 02:56:09 173056 ----a-w- C:\Windows\System32\ieUnatt.exe 2013-05-17 02:56:00 599040 ----a-w- C:\Windows\System32\vbscript.dll 2013-05-17 02:51:27 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2013-05-16 22:39:39 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll 2013-05-16 22:28:26 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll 2013-05-16 22:27:30 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-05-16 22:21:37 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-05-16 22:20:30 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll 2013-05-16 22:16:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll 2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll 2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll 2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll 2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll 2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll 2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll 2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe 2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe 2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll 2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll 2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll 2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll 2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll 2013-04-17 07:02:06 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2013-04-17 06:24:46 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll 2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll 2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys 2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys 2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys 2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe 2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll 2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll 2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll 2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll 2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe . ============= FINISH: 21:34:12.44 =============== Attach: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 5/19/2012 7:38:14 PM System Uptime: 6/14/2013 9:07:45 PM (0 hours ago) . Motherboard: Gateway | | SX2370 Processor: AMD A6-3620 APU with Radeon HD Graphics | P0 | 792/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 1850 GiB total, 860.92 GiB free. D: is CDROM () E: is Removable F: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP106: 6/8/2013 1:01:35 AM - Scheduled Checkpoint RP107: 6/13/2013 3:00:13 AM - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) 100% Free Spades 7.42 3GP to MP3 Converter 4500_Help 64 Bit HP CIO Components Installer 7-Zip 9.22beta Adobe AIR Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Help Center 2.1 Adobe Illustrator CS2 Adobe Photoshop CS2 Adobe Photoshop Elements 5.0 Adobe Reader X (10.1.7) MUI Adobe Stock Photos 1.0 Adobe SVG Viewer 3.0 Agatha Christie - Death on the Nile AMD APP SDK Runtime AMD VISION Engine Control Center Artensoft Photo Mosaic Wizard ATI Catalyst Install Manager Bejeweled 2 Deluxe Bing Bar BitComet 1.35 64-bit Blitz bpd_scan BPDSoftware BPDSoftware_Ini BufferChm Build-a-lot 4 - Power Source Bulk Image Downloader v2.0.0.8 Catalyst Control Center - Branding Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Chronicles of Albian Contrôle ActiveX Windows Live Mesh pour connexions à distance Cradle of Rome 2 CyberLink MediaEspresso CyberLink PowerDVD 10 D3DX10 Destinations DeviceDiscovery DocMgr DocProc Dora's World Adventure Dropbox DVD Flick 1.3.0.7 DVD Shrink 3.2 EasyDuplicateFinder v4.2 eBay Worldwide Evernote v. 4.5.1 Fax Final Drive: Nitro Fooz Kids Fooz Kids Platform Galerie de photos Windows Live Gateway Games Gateway Recovery Management Gateway Registration Gateway ScreenSaver Gateway Updater Google Chrome Google Talk (remove only) Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Governor of Poker 2 Premium Edition GPBaseService2 Hotkey Utility HP Customer Participation Program 13.0 HP Document Manager 2.0 HP Imaging Device Functions 13.0 HP Photosmart Essential 3.5 HP Smart Web Printing 4.51 HP Solution Center 13.0 HP Update HPDiagnosticAlert HPPhotoSmartDiscLabelContent1 HPPhotosmartEssential HPProductAssistant HPSSupply Identity Card ImgBurn Internet TV for Windows Media Center J4500 Java Auto Updater Java 7 Update 5 JDownloader 0.9 Jewel Match 3 Junk Mail filter update Karaoke Builder Player 3.0 KooRaRoo Media LiveUpdate 3.3 (Symantec Corporation) Logitech Media Server 7.7.2 magayo Lotto Malwarebytes Anti-Malware version 1.75.0.1300 MarketResearch Mesh Runtime Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Office 64-bit Components 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared 64-bit MUI (English) 2007 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Mozilla Firefox 21.0 (x86 en-US) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Mystery of Mortlake Mansion Nero BackItUp 10 Nero BackItUp 10 Help (CHM) Nero Control Center 10 Nero ControlCenter 10 Help (CHM) Nero Core Components 10 Nero DiscSpeed 10 Nero DiscSpeed 10 Help (CHM) Nero Express 10 Nero Express 10 Help (CHM) Nero Multimedia Suite 10 Essentials Nero RescueAgent 10 Nero RescueAgent 10 Help (CHM) Nero StartSmart 10 Nero StartSmart 10 Help (CHM) Nero Update NOOK for PC Norton Online Backup OCR Software by I.R.I.S. 13.0 Officejet J4500 Series Orb Orb Mini Controller Orb Runtime libraries OverDrive Media Console Penguins! Plants vs. Zombies - Game of the Year Polar Bowler Polar Golfer ProductContext Realtek Ethernet Controller Driver Realtek High Definition Audio Driver Scan Scat Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition Shop for HP Supplies Skype™ 5.10 SmartWebPrinting SolSuite 2012 v12.1 SolutionCenter Spotify Status Symantec Endpoint Protection Times Reader TomTom HOME TomTom HOME Visual Studio Merge Modules Toolbox Torchlight Total Recorder 7.0 TrayApp TVersity Codec Pack 1.7 TVersity Media Server 2.2 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817327) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update Installer for WildTangent Games App Virtual Villagers 5 - New Believers Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) VLC media player 2.0.5 WebReg Welcome Center WildTangent Games App Winamp Winamp Detector Plug-in Windows Live Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Center Add-in for Flash Windows Media Player Firefox Plugin WinZip 16.5 Xiph.Org Open Codecs 0.85.17777 Yahoo! Toolbar Zuma's Revenge . ==== Event Viewer Messages From Past Week ======== . 6/14/2013 9:10:11 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the KooRaRoo Media Server service to connect. 6/14/2013 9:10:11 PM, Error: Service Control Manager [7000] - The KooRaRoo Media Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 6/13/2013 9:30:49 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service. 6/13/2013 9:25:34 PM, Error: Service Control Manager [7038] - The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 6/13/2013 9:25:34 PM, Error: Service Control Manager [7000] - The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure. 6/13/2013 9:25:34 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 6/13/2013 3:33:31 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MMCSS service. 6/13/2013 3:33:31 AM, Error: Service Control Manager [7000] - The Multimedia Class Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 6/13/2013 3:33:01 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 6/13/2013 3:31:57 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 6/13/2013 3:06:59 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. 6/13/2013 3:06:59 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. . ==== End Of File =========================== A hearty thank you, in advance for any help you may offer. Dave
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.