win32/patched virus infecting laptop

February 7, 2014 at 21:52:51
Specs: Windows Vista
AVG has detected a virus on my computer that cannot be deleted, called win32/patched. It seems to be infecting the file rpcss.DLL. it is slowing my system down and not letting me do things bc I keep getting the AVG popup.

Any advice on how to fix this?

Thank you

February 7, 2014 at 23:01:37
Download OTL from any of the following links, save & run from your Desktop.
Double click the OTL icon to start the tool. (Note: If you are running on Vista or Windows 7 accept UAC alert)
When the window appears, underneath Output at the top, make sure Standard output is selected.
Select Scan all users
Change Drivers to All
Under the Extra Registry section, check Use SafeList
In the lower right corner, checkmark "LOP Check" and checkmark "Purity Check".
Click Run Scan and let the program run uninterrupted.
When the scan is complete, two text files will be created on your Desktop
OTL.Txt <- this one will be opened
Extras.txt <- this one will be minimized

Upload the logs using this. I upload to for images & for files ( neither need an account ) Give us the link please.
Image Uploader
How to use for files.

February 7, 2014 at 23:09:50
Send me the logs please & then run these.

1: Download & run Unhide
To run Unhide, simply download it to your Desktop and then double-click on the Unhide icon. The program will open a black box and start making the files on your fixed disks visible again. Please note, that this program will not unhide removable drives like flash cards and usb drives as the FakeHDD rogues do not target these types of drives. Once it has finished, the program will display a Windows alert stating that your files have been restored. You should then reboot your computer for all of the settings to go into effect.
When Unhide is complete, it will create a logfile on the Windows Desktop called Unhide.txt.
Copy & Paste the contents of the log in your next post please. Let me know if it doesn't produce a log.

2: Reboot

3: Run ESET Online Scanner, Copy and Paste the contents of the log please. This scan may take a very long while, so please be patient. Maybe start it before going to work or bed.
You may have to download ESET from a good computer, put it on a flash/thumb/pen drive & run it from there, if your comp is unbootable, or won't let you download.
Create a ESET SysRescue CD or USB drive
How do I use my ESET SysRescue CD or USB flash drive to scan and clean my system?
Configure ESET this way & disable your AV.
How to Temporarily Disable your Anti-virus
Which web browsers are compatible with ESET Online Scanner?
Online Scanner not working
Why Would I Ever Need an Online Virus Scanner? I already have an antivirus program installed, isn't that enough?
Once onto a machine, malware can disable antivirus programs, prevent antimalware programs from downloading updates, or prevent a user from running antivirus scans or installing new antivirus software or malware removal tools. At this point even though you are aware the computer is infected, removal is very difficult.
5: Why does the ESET Online Scanner run slowly on my computer?
If you have other antivirus, antispyware or anti-malware programs running on your computer, they may intercept the scan being performed by the ESET Online Scanner and hinder performance. You may wish to disable the real-time protection components of your other security software before running the ESET Online Scanner. Remember to turn them back on after you are finished.
17: How can I view the log file from ESET Online Scanner?
The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program Files\EsetOnlineScanner\log.txt". You can view this file by navigating to the directory and double-clicking on it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start ? Run dialog box from the Start Menu on the Desktop<.
If no threats are found, you will simply see an information window that no threats were found.

February 8, 2014 at 22:32:09
Thank you for response, here are my logs:

Here is Unhide, wil now run the other scan and post those results

Unhide by Lawrence Abrams (Grinler)
Copyright 2008-2014
More Information about Unhide.exe can be found at this link:

Program started at: 02/09/2014 01:35:23 AM
Windows Version: Windows Vista

Please be patient while your files are made visible again.

Processing the C:\ drive
Finished processing the C:\ drive. 279608 files processed.

Processing the D:\ drive
Finished processing the D:\ drive. 0 files processed.

Processing the E:\ drive
Finished processing the E:\ drive. 0 files processed.

The C:\Users\Nicole\AppData\Local\Temp\smtmp\ folder does not exist!!
Unhide cannot restore your missing shortcuts!!
Please see this topic in order to learn how to restore default
Start Menu shortcuts:

Searching for Windows Registry changes made by FakeHDD rogues.
- Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
- Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
No registry changes detected.

Program finished at: 02/09/2014 02:11:14 AM
Execution time: 0 hours(s), 35 minute(s), and 51 seconds(s)

February 8, 2014 at 23:57:06
"Thank you for response, here are my logs:"
Well done, you did that perfectly.
I can see the problems, to get you completely clean, will take 8 or so more steps.

I shall wait for the Unhide & ESET logs first.

February 9, 2014 at 09:20:11
Hello Johnw,

The ESET online scanner said that no threats were found, and I copied and pasted the unhide log above.

Thank you

February 9, 2014 at 12:44:45
" I copied and pasted the unhide log above"
Opp's, I did see it, then forgot, sorry.

Run Defogger & then Combofix.

Please download DeFogger and save it to your Desktop
Once downloaded, double-click on the DeFogger icon to start the tool.
Double click DeFogger to run the tool.
The application window will appear
Click the Disable button to disable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger may ask you to reboot the machine, if it does - click OK
Do not re-enable these drivers until otherwise instructed.
This program can enable and disable CD emulation, often required in removing difficult malware. Some CD Emulation programs use a hidden driver that may be seen as a rootkit or that will interfere with the proper operation of the anti-rootkit scanner.

Download ComboFix to your Desktop & then run. Copy & Paste the contents of the log in your next post please. ComboFix's log should be located at C:\COMBOFIX.TXT.
A guide and tutorial on using ComboFix
Manually restoring the Internet connection
There are circumstances ComboFix will hang, crash or stall at various stages due to malware interference, failure to disable other real-time protection tools or the presence of CD Emulators (Daemon Tools, Alchohol 120%, Astroburn, AnyDVD) so that it does not complete successfully. Also, depending on how badly a system is infected, ComboFix may take longer to complete its routine than it normally does or fail to run properly. While that is not normal behavior, it is not unusual"

If you think it's frozen, look at the computer clock.
If it's running, Combofix is still working.
NOTE: Do not mouseclick combofix's window while it is running. That may cause it to stall.
NOTE: ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

**Please Note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.
The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.
Allow ComboFix to download the Recovery Console.
Accept the End-User License Agreement.
The Recovery Console will be installed.
You will then get this next prompt that asks if you want to continue the malware scan, select yes.
If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
Can't Install an Antivirus - Windows Security Center still detects previous AV
We are almost ready to start ComboFix, but before we do so, we need to take some preventative measures so that there are no conflicts with other programs when running ComboFix. At this point you should do the following:
* Close all open Windows including this one.
* Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix. Instructions on disabling these type of programs can be found in this topic.
Once these two steps have been completed, double-click on the ComboFix icon found on your Desktop.
Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all. The scan could take a while, so please be patient.

February 10, 2014 at 16:36:43
I am trying to run Combofix but like you said it hangs and freezes. I disabled my antivirus and closed all windows and it still hangs. Is there any way to prevent this freezing? I have tried twice already. Thanks!

February 10, 2014 at 16:42:31
Have you run Defogger?

"If you think it's frozen, look at the computer clock.
If it's running, Combofix is still working"
Is the clock still working?

February 10, 2014 at 16:46:06
Yes, I ran defogger first. The clock stops running after about ten minutes of running the combofix "blue box"

February 10, 2014 at 16:49:03
Ok, we now need to try & outsmart the infection.

Note: If Combofix won't run.
1: Try Safe mode. Make sure when the comp reboots, you put it back to Safe mode.
2: Rename Combofix.exe as you download it to winlogon.exe or Combo-Fix.exe or anything you like.
It is very important that save the newly renamed EXE file to your Desktop.
You must rename Combofixe.exe as you download it and not after it is on your computer.
You may have to modify your browser settings if you use Firefox, so you can rename Combofix.exe as you download it. To do that:
Open Firefox
Click Tools -> Options -> Main
Under the downloads section check the button that says "Always ask me where to save files".
Click OK
For Internet Explorer:
Choose to save, not open the file
When prompted - save the file to your Desktop, and rename it winlogon.exe.

Download Combofix to a USB and run Combofix from the USB, just say continue to all the warning messages.

February 13, 2014 at 20:52:12
I've tried several times in both safe mode and normal mode to fully run combofix, but it never gets past the scanning phase. I leave it running overnight and it is in the same spot I left it when I wake up. I tried using a USB drive to run the program as well as saving it as a different name while downloading it, but the problems persist

February 13, 2014 at 21:21:19
Ok, we have to dismantle the infection bit by bit & then come back to using Combofix later.

Uninstall ComboFix. The reason we remove Combofix, is that a new version comes out nearly every day.
Turn off all active protection software.
Push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
Please Copy and Paste the following into the box > ComboFix /Uninstall and click OK.
Start > Run, Copy and Paste > ComboFix /uninstall and click OK.
Start > All Programs > Accessories > Command Prompt, Copy and Paste > ComboFix /uninstall and hit > Enter.
Qoobox is a folder created by Combofix to quarantine any infected files.

February 13, 2014 at 21:21:46
Run RogueKiller
User Guide
Official tutorial
If RogueKiller won't run, open IE & turn off SmartScreen Filter.
Download & SAVE to your Desktop.
Quit all programs that you may have started.
Shutdown your antivirus to avoid any conflicts.
Please disconnect any USB or external drives from the computer before you run this scan!
For Vista or Windows 7/8, right-click and select "Run as Administrator to start"
For Windows XP, double-click to start.
Wait until Prescan has finished ...
Then Click on "Scan" button
Wait until the Status box shows "Scan Finished"
click on "delete"
Wait until the Status box shows "Deleting Finished"
Click on "Report" and Copy & Paste the content of the Notepad into your next reply.
The log should be found in RKreport[1].txt on your Desktop.
Exit/Close RogueKiller.
When completed make sure to re-enable your antivirus.

February 13, 2014 at 22:12:02
RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
Website :
Blog :

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : Nicole [Admin rights]
Mode : Remove -- Date : 02/14/2014 01:10:43
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Scheduled tasks : 2 ¤¤¤
[V1][SUSP PATH] ROC_REG_JAN_DELETE.job : C:\ProgramData\AVG January 2013 Campaign\ROC.exe - /DELETE_FROM_SYSTEM=1 [7] -> DELETED
[V2][SUSP PATH] ROC_REG_JAN_DELETE : C:\ProgramData\AVG January 2013 Campaign\ROC.exe - /DELETE_FROM_SYSTEM=1 [7] -> DELETED

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
[Inline] EAT @explorer.exe (FwDoNothingOnObject) : FirewallAPI.dll -> HOOKED (Unknown @ 0x361AD266)
[Inline] EAT @explorer.exe (FwEnableMemTracing) : FirewallAPI.dll -> HOOKED (Unknown @ 0x361AD266)
[Inline] EAT @explorer.exe (FwSetMemLeakPolicy) : FirewallAPI.dll -> HOOKED (Unknown @ 0x361AD266)

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS542525K9SA00 ATA Device +++++
--- User ---
[MBR] 28776b222d5ed5679d3499811aef2299
[BSP] f7e07d18a4a4a10c3134f240a4c68fb3 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 8283 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 16967680 | Size: 230190 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_D_02142014_011043.txt >>

February 13, 2014 at 22:20:20
Run both of these, in this order.

1: Run AdwCleaner
How to download from Softpedia
Author's site
Please download AdwCleaner by Xplode onto your Desktop.
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Clean.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please Copy & Paste the contents of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

2: Run Junkware Removal Tool
How to download from Softpedia
Download Junkware Removal Tool to your Desktop.
Warning! Once the scan is complete JRT will shut down your browser with NO warning.
Shut down your protection software now to avoid potential conflicts.
Temporarily disable your antivirus and any antispyware real time protection before performing a scan.
Click this link to see a list of security programs that should be disabled and how to disable them.
Run the tool by double-clicking it. If you are using Windows Vista or Windows 7/8, right-click JRT and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
Copy and Paste the contents of the JRT.txt log please.

February 17, 2014 at 19:42:45
# AdwCleaner v3.019 - Report created 17/02/2014 at 22:29:53
# Updated 17/02/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Nicole - NICOLE-PC
# Running from : C:\Users\Nicole\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Users\Nicole\AppData\Local\Conduit
Folder Deleted : C:\Users\Nicole\AppData\Local\PackageAware
Folder Deleted : C:\Users\Nicole\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Nicole\Documents\optimizer pro
Folder Deleted : C:\Users\Nicole\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Folder Deleted : C:\Users\Nicole\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Deleted : C:\Users\Nicole\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnmlhhbehhdmajijfenoldcajelckpmn

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\dnmlhhbehhdmajijfenoldcajelckpmn
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dnmlhhbehhdmajijfenoldcajelckpmn
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3291327
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\bearsharemediabartb
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16448

-\\ Google Chrome v32.0.1700.107

[ File : C:\Users\Nicole\AppData\Local\Google\Chrome\User Data\Default\preferences ]


AdwCleaner[R0].txt - [4324 octets] - [17/02/2014 22:27:16]
AdwCleaner[S0].txt - [4351 octets] - [17/02/2014 22:29:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4411 octets] ##########

February 17, 2014 at 20:05:58
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Nicole on Mon 02/17/2014 at 22:49:03.46

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\lyricsing
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3B0B8EFF-3619-4856-A1EA-F5B3DAF4B5EA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{3B0B8EFF-3619-4856-A1EA-F5B3DAF4B5EA}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D759BDB8-798A-4C79-84B6-E09D248C84EA}

~~~ Files

Successfully deleted: [File] C:\Windows\System32\Tasks\LyricsSing Update
Successfully deleted: [File] C:\Windows\Tasks\LyricsSing Update.job

~~~ Folders

Successfully deleted: [Folder] "C:\Users\Nicole\appdata\local\cre"
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{016F4D73-2F03-4DE7-BAC1-63B85B1666B1}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{01C226DC-7C0F-4FD1-B850-447A6EACC0FA}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0360694C-3B9C-48AB-8EE3-3DCF70765E08}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{05E935C7-FCCB-4AB7-9447-A59363DB2052}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0671AFD3-43D7-4050-B02A-724B05EB1DF2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{06B811C0-40BE-41A0-B813-94C3A2E1B812}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{06DA4551-94E9-4635-A171-8E89B04FACFB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{09E5025F-3ACE-48B3-BF63-E9C061DDA835}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0A9CA56F-B3F1-4DCE-BE1C-D44E3C4519FD}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0AB1F7E8-CED4-4DCF-8362-2EA49E733B21}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0BAB83AD-06BA-454A-B5FD-F0AF573DE8BB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0C0525C1-D48B-44B1-AD4E-04CC7D08850A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0C34E6C3-0A79-43E2-A936-B921FEA25C8D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0C7AD428-48E9-46C6-9435-F163CAC6DE5D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0DC6E3E7-9E37-4E91-BCA1-0A34045FAC19}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0DE14449-1421-4E1D-A00E-69F7E0D9E62F}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0F3A89F7-2C71-4CFD-861E-1BD036F7F6A0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{0F4C9576-E8D9-4FE4-B125-468529C07470}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{118FECBC-6D2E-4763-918F-3DD84B317488}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{11B1699E-670E-42A8-9E19-0A4173B13AE8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{12DD3E17-2FA6-4839-BDB1-4392DC56B925}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{1360B328-AFE3-4568-8519-34C496138782}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{13BFFA45-32A3-4A8D-B6A5-82B5FA36A8AC}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{145AB92A-A5CE-4E61-B851-D4127249C108}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{1555B1C2-A3B1-4BA0-8978-A3FE027BFFEF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{15E8124C-29A9-41C2-9195-D444D6F69BDF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{163E8540-0AE9-4CF7-BD43-54131F24A982}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{17918C53-DF82-4127-A1F5-2572BFE50340}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{179C83C0-8725-4F43-B6C7-C366B1A67677}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{1B63F4ED-7C1F-44FA-9C72-8416E1CD1C0A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{1ED22DF1-1635-41E6-82DB-31DD6EB4345B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{1F366CDE-1D01-4C8B-B261-CDECCF98E5FC}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{21F036CA-04A0-4B52-8E8E-98CEEACA573C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{261BEEBC-8172-4D9C-B850-81CF983E9F9F}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{280EC7D0-3502-410E-89AF-728316387548}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{28C67C18-1F2D-4989-BD83-BFF169112CA1}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{28D77CBE-71DB-4747-A02A-836564767EE8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{293C0E24-78CD-4C82-A7EA-ED9BAE7FEF1C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{2A2D58DE-3B51-4AD7-840D-F006D4A896FD}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{2A7875BC-B8BB-4A91-B219-810293D6DEA9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{2AEB66B3-A62E-4C66-8D96-A9CD5B4B0068}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{2F2F3B85-C917-4EFB-9B4C-1ACF1C198E29}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{30384D0E-41B4-45F2-9ED9-F0B4096561A2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{314D968B-4BE2-4A5F-B6FC-A04C7D6D0EB6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{315E3E51-44EE-4984-BF2E-FF47E64DE0F0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{31B4742C-B75F-4E92-8FEF-33905ABE2219}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{332D7375-2055-4123-B167-FD163570FD46}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{34CDC986-35AA-45D3-AA48-A65EC61DF507}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{35807BA5-5E75-417F-9E14-FB7346B81DC6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{35EAE1CC-B29F-4877-BC18-DA8E167A5729}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{3665D185-2AEA-469F-B314-359C5BC3C6E0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{37268612-4219-4588-A6CC-4FD11905D868}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{3A5E4785-0367-4E3B-8748-7813AE0A3A1B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{3CDB5AE9-489D-4964-A284-49A4152B4473}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{3D81E6C9-0072-4662-8CD4-44EFA7D595FF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{41117373-3CAA-411A-8013-4FA4B39C99C8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4209F82A-6FEF-4CD9-8C94-15AFD0B93FC2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{444FAB57-C70D-4A21-B62D-468E63063338}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4473C2F1-6372-4963-9837-871DC6F38B30}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{48E223E2-184F-4A70-9FCD-F2C544772C8E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{48FEA301-6243-4D89-AE53-8A090F8A5C26}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4947F02B-A55A-427E-8454-B4A45D725EE5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4A77FDF5-5163-43E1-889E-13AD90DA2A00}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4AECD4A4-9C95-4405-867C-0CF8E00544CB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4BD50734-1C52-4CD9-A39A-AC179C1B5A58}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4D02CCEB-E9FE-4542-B515-4F824094C2BA}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4D4B7E36-BB61-456F-B9CE-A77A46448CC0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4E5ED3BC-3644-4AAF-AC40-B0ABB0C7A873}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{4EFDEE87-A62E-420D-A450-1F34975620A0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5006472D-9E8B-41C1-B719-D0B901708AFF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5239BF53-D625-4521-AFD0-4DFC4435D510}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5322562A-4D5D-4DBF-A785-C257F89D7371}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{544D98DC-693D-47BB-9365-F5089CAB08D9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5510E3B2-20FF-46A1-B078-2BCA09DD1781}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{56925C3D-59FC-4A74-B4F9-10E88753F306}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{57B11587-F147-4BCF-B12E-57C7F098DB5C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5852B01B-3EF1-4E8E-83B1-BFD6AC9DE416}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{590C0664-AA5B-4787-A7C1-EA3328F05B31}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5941654C-2774-4795-8725-56AC8759C87C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5B82CBA6-013C-405A-BC7A-DDCA100B05BB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5BD39B7A-8ECD-4EF7-83CA-EA4DFD609CD1}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5C2E5B0B-8B90-48F2-B351-1F2B277998FB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5D4D72DF-2408-41CE-BCE3-DD5371F91902}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5D662205-6A83-4F74-8952-D92451E68677}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5D9B891E-DF6D-4623-8025-D9839E81E85B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5DE6D380-25B2-4BA4-BC4A-D041DB8A7216}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5F164B67-EFA7-480B-B49B-9E038EC4F7DB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5F311A48-C34F-4696-821C-4BBFADD8FEBB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{5FEB0A5C-05F2-47D0-8412-B53D24578FCF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{62193F17-4E86-4C94-92FA-3CBF99A0E174}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{63FA2C82-F4AF-4349-BF24-F531EAF46A81}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{641B2493-D4B4-43B8-A011-D4438483DAD4}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{645DE711-D927-4285-AB36-6CCC6DFC6E84}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{64EAB1C4-61AC-4E8F-9E76-7080539A1432}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{66429BE0-923A-4A47-88B0-322FC2A1E461}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{66B05177-0A8D-4EB3-800D-2134520CB270}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{66BE190E-A6D2-435A-9820-93124D1DAEDC}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{677B28E9-580B-4D05-BC05-5898D454F798}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{6953870B-603E-425C-A1F0-301D988D1399}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{6AD24551-B6D5-468F-9928-81792B171745}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{6CE8550B-E5F1-4BEB-B025-BB80F9412C09}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{6F121053-F04A-4EE2-9F59-854707F030C2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{700D0829-98FC-4695-B9F5-0DE3F46FE8AA}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{708AED67-34A7-479C-B59E-DC35CEB2E1E7}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{71C8A90B-932C-4F60-B9A7-2F0DCA5C0564}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{72263E5F-1813-40F3-B4D1-28A84746C079}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{724AD9CF-4B3B-4383-9B03-9775F54D96AB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7322138C-04A3-4A51-8E15-F984B377C81C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{73EB967E-4CD1-45F3-BAB2-4A1C988118A0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{754ED304-F817-4606-98EE-DBCB7ACA0BA9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{75C28B3C-0771-486A-A2F4-150B640BB44E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7756C09E-8B26-4E03-BD2B-BA822FDEE0D1}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7759388F-38D1-46CF-B671-AB97BCAAA942}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7B66702C-E72F-4837-A86E-940458C8CB28}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7C769BA6-A835-42C6-9C1E-C95444EE024A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7D50B484-4B48-4B29-BDEA-72370D3C1664}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7E96AA19-EF54-4AF8-B2EE-1B028A1F073B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7F6D0FA1-C351-44E7-A8F6-6805ECBBCB3E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{7FEF9466-6668-435B-B951-D155AEA2CA96}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{81A1672F-DB66-4244-8683-A41F28D2D113}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{821CAC31-071A-467E-BD13-0010911AF908}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{850B0450-8976-4D90-B27A-4689FD9F6D8D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{850C8465-8EC4-4A38-8172-2268B6054009}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8542E42A-60F3-488B-9479-0BE14E019ED4}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8570BE1F-3FEB-4A16-812F-B1F11F1863B1}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8625FA0D-61F3-4E0F-8D7A-4B3EC241238C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{87A383BF-D26E-46BE-997E-DD91FDCCA05B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{89B8BEF1-88A8-4951-98E7-70B75B785E1E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8AE1ECEB-B782-4789-9A97-503C87A70018}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8B273EFA-648C-40BD-9B47-702A8526393B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8BD7A133-9A64-4B2C-B77B-42EB94C3F1E0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8D175080-AB71-48B1-BD6C-FE03530A3D5E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8F2574B9-3219-47AC-81B7-D5F5E7DCB434}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8F8579F7-FF68-435F-BFE9-F8CA753607EA}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8F93F339-2D6A-4D0D-9F93-1B22DD99F101}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{8FC83AD1-585E-4C23-93C9-55494AA8F9AF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{900714A6-2336-4DD2-8EC0-CDDE20DDAEA5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{918134C8-6EFF-47A9-A5EB-15B07877CDF6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{91BBD434-AADB-49B4-A687-0F021BBC3B1C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{92048C5E-6304-4601-BF73-476CA951C22F}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{921F85D6-0241-4C8B-8429-1FBD5104E250}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{93FB25DA-0A18-4E12-9BE6-1B5CA943395B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{94125584-8633-4074-A121-124FF46162C8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{943331EC-E881-470D-B29B-D16FC395B809}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{94676E41-13D5-4223-B456-1B3AB7921B08}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{94A3E460-B6DA-4445-AF7F-90886A807256}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{95775319-B9F6-4B19-83E8-88127C7E6EC1}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{982B03BB-40E8-4271-A39B-D8860348E41A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9A3103C3-0406-4DEF-9753-E9A303A4C22C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9ACF9866-1129-476E-8827-9B63FD15AB25}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9BDBE3DE-3FFD-485F-9B94-9D7BFE7DDB1E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9BDC6984-EDF5-4012-A76A-086A1AD0FF78}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9F444E46-505C-4CAD-AA77-28A3763286A3}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9FE61AE3-A0B9-462D-8FC3-17121B58B396}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{9FFE8940-5C6C-4829-A490-A45F716F69D6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A0F9F9F1-5D81-41DD-A145-C330634F55CF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A19174D6-2D62-495B-9474-1C9AF8D6A8F2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A247504C-F639-455D-B1A7-5D421443EE93}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A2CE9980-0A69-4156-80B8-7D1BA6CAD0B7}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A2E871BA-7E22-43E1-9306-7C2E3A0D7B54}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A30FDFA2-F600-4D3F-956C-9C87BBA803F9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A3956EBD-4B45-4062-AC93-7DFB79987811}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A3EFE5DF-32DF-498F-B734-2F59BBA417B2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A45BDDCB-294A-4014-B6F8-45AB19DA0CA5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A53FDE81-C6E4-40C2-81C8-0686E2E07D04}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A7D4C583-AAE1-4830-B04B-C74FBAA10C5D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{A9C55382-630C-4829-BB7E-19740EA56C02}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{AC8006D5-73B2-4825-869E-A9D809B38363}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{ADA421CF-B1D3-406D-B7C4-F826FC8B6599}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{AE10511F-8AA6-4906-B6BD-165A3E3A549E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{AF9F0511-5B60-47A5-9B9A-85205B2BD216}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B09C2387-B840-42D9-A7FD-CD42C9E6F222}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B1A3171B-35B4-4BCE-968A-C5C48BCE49D7}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B1ED39F8-1742-4669-AA6E-F5985DDD2A77}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B1F89629-D07B-4291-84D1-334260D5BC54}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B1FD042E-74F9-4754-906B-11D47BEA36FE}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B29C7C59-B3CE-486B-A820-9DDF1465ED56}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B314F31B-06FF-4744-BBC5-0287C377C0B8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B31EC8C3-2810-4C04-A448-63DB78BC0B7D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B3710D83-FFCF-4F17-8A61-F103F895B416}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B3D6FDFE-E1A8-4CA5-8486-3B096F938285}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B4B582D8-BBC2-447D-8DE1-FAB880FEEC0D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B6047838-970E-4B0C-8EAD-0A453A413F0D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{B91FE055-19A3-48A6-B03E-57AD6F2D6F76}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{BCA502E5-CCAC-4F1A-A0A9-B88C384A244F}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{BCD0F610-C323-4B32-A9F5-542CE72FAD78}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{BF403E27-C703-417C-BAD6-058823BB5050}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{BFC26832-BF03-4F02-BF8E-68A815774A0B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C16BF186-A68A-47D3-969C-DD45358B273F}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C191DD32-4D38-4A66-B928-8D395A3C4C35}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C1B76A78-F2C6-4EA7-A501-7F76DD63E651}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C1DFB84F-B3B6-454B-AE32-27DAA5CF5E85}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C359B47D-E8F7-4AC8-8448-A6479848D2E6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C7C09448-136F-47B7-8A5F-B8A0118237E8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C8CAC71A-15D5-41E8-A9CA-B653CEB04112}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C9035A23-13D9-45B7-8AE0-A9B06540547A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{C93F7CF4-E0FC-423A-AA2F-5B6E93B97A2E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{CDCA1AEA-656F-448C-A9C6-C0F4F0134D78}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{CDFFBEBA-AFCC-4377-9E2D-EAAACAFDD0B0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{CE2A4CDF-CFC4-4849-BAA9-DF7AC127AE71}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{CEC469AB-E293-421E-98DD-A4BD103622D4}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D0B117EF-86B8-4CFB-8FA1-3A45F31A6071}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D110AEA8-17E9-40D9-A88F-CDF40142D2B7}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D17500BC-56E4-46FC-BDEB-E2C6FF347A4E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D3C4D9AF-6F1D-4801-8426-9B68EABBBEE6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D5B1956A-3D86-484B-AE9C-EF1B568B47C8}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D86186AE-F392-4843-B896-62FDA858848C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D89CAA82-EE50-4D84-8A9E-55F196E3062B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{D8D00BAA-BD27-4512-9CF0-7B6A954C956B}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DAA6E7F2-DA33-42A0-9F5F-E27EB22011A9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DACAAD2B-9D0F-4B06-A2D4-B714DAA4413A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DB815D5B-1C4A-4D0A-A1E3-6C99C259BC47}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DCAB691F-1281-436F-9792-BF65781444C3}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DDCDB7F2-1013-493B-8D7E-2B56CACB23A5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DE3F0296-B701-4E7C-B498-0F9801BFC546}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DEF4B3DD-302D-4D06-BAB8-27F654C16FCA}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DFDCFC80-9EA7-4110-B30B-02A0A2868D37}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{DFDFE716-9720-4467-9281-AD47F1EEB434}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E072001A-B2ED-47A3-99DF-E35E7D1AD0D6}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E08AA1FC-5032-4FEC-B1E4-BB679923FAFF}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E0EA7B04-9CF7-43DE-ABF8-2365E3545838}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E2517D59-00BB-4A5D-A2BF-25E01C2FF2F3}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E4691D40-128C-4782-A35F-2F02E26F8CAB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E4B74BC6-841B-434E-8278-4874FA57F28C}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E518E727-E4D7-4764-A3F0-EE267EBF20A7}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E5628C5E-8CAC-49D4-B754-539BA0069CB7}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E6CC5151-3029-4F27-BF54-F715D20685A5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E77FCDB6-EF8E-44F5-9DD6-6DCFDD085D7A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{E8E45527-C6D1-4D6B-850C-0F702BEF654A}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{EA0C969E-4542-48D1-900C-4CEC76FF7BFC}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{ECFF0BC1-1B0A-4882-B61C-241477C9F360}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{ED672558-8434-42B0-AFB3-F2D8BFDE1B75}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{EDFD2050-0499-48C0-A09B-047374E66F1D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{EFCD4976-BDB1-4387-A982-D726FC36FEA5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F05471CB-3BD5-4CC0-B152-DE2BE0D6AD54}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F208989F-7FE0-45A5-87D5-729A3427C1B9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F2EB2E73-BEE8-4734-81A7-22CD82044EA9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F2FF33CB-54B0-44D7-99DA-BCC859F04A01}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F500797D-F963-4266-B93C-ED7C6E8C176D}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F5C0CB85-84B6-43E3-881E-A0370375BF43}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F8F49CC6-1AFE-4621-9518-E0535D2FFC37}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{F9F4F6E0-071C-45B0-854E-F6D04BDFE623}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FAE34B46-1270-40DF-81A4-9EDB0DD213E9}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FB10E595-D495-4266-97CA-C1357A9F8577}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FB5CA79B-6E30-4577-8E01-F472C9B15CFB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FC79CE6B-CC25-4D50-94B4-B2045B27A6E5}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FD4177B7-77E0-46F3-A08B-B9DB7CE200BB}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FD543E08-EFE9-43B6-9170-FCB07E73F5F3}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FD5A3C06-709C-441C-BFD0-33CC4409BEF2}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FD9E63E0-5FA1-4C88-8180-630DE42BE7BD}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FE5EB918-B1AE-4E9E-8E22-C0E45030B5C0}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FEE1A4B4-AEF3-46AC-86CE-B3F22FD44001}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FEF97E16-6F45-4E00-B579-98626318DC9E}
Successfully deleted: [Empty Folder] C:\Users\Nicole\appdata\local\{FF2BDFB3-7B49-4EFF-B8D7-AF0006570ADD}

~~~ Event Viewer Logs were cleared

Scan was completed on Mon 02/17/2014 at 23:00:00.85
End of JRT log

February 18, 2014 at 00:58:39
Please download Rkill from any one of these links and save it to your Desktop. Copy & Paste the contents of the log in your reply.
Now double click on Rkill to run it. If the first one doesn't work try the next one.
This will help remove certain processes and should restore any file associations and your desktop. Note: Your system is still infected as Rkill does not delete files - it merely helps to temporarily disable the infections, allowing us to start the cleansing process.
Do NOT reboot your machine. Each time you reboot, Rkill is disabled and you would have to run it again in order for it to be effective.
RKill Forum - What it does and What it Doesn't - A brief introduction to the program

Run TDSSKiller. Copy & Paste the contents of the log in your next post please.
Anti-rootkit utility TDSSKiller

March 6, 2014 at 14:10:22

I ran Rkill and TDSS. My TDSS log exceeded capacity so I could not post. But here is the link to download

Report •

March 6, 2014 at 14:21:02
Nice work.

Can you post the Rkill log please.

Then run MBAM.

Run Malwarebytes' Anti-Malware ( MBAM ) Free Version. Use Quick scan. Copy and Paste the contents of the log please. Note how to avoid the trial period.
If you can't find the log, do a search for malwarebytes or look in here.
C:\Users\Pete\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
Replace Pete with the User's name.
Make sure you Uncheck > Enable free trial at the End of the install.
If your MBAM log indicates "No action taken". That's usually a result of NOT clicking the Remove Selected button after the scan.
Quick Scan versus Full Scan

March 6, 2014 at 14:31:25
Thanks, RKill Log:

Will run MBAM

March 7, 2014 at 16:22:49
Malwarebytes Anti-Malware

Database version: v2014.03.06.09

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Nicole :: NICOLE-PC [administrator]

3/6/2014 5:34:23 PM
MBAM-log-2014-03-06 (19-18-16).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 225891
Time elapsed: 17 minute(s), 19 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 5
HKCR\AppID\{384997EE-E3BE-49C4-9ECA-C62B7C08128A} (PUP.Optional.DynConIE.A) -> No action taken.
HKCR\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} (PUP.Optional.DynConIE.A) -> No action taken.
HKCU\Software\avsoft (Trojan.Fraudpack) -> No action taken.
HKCU\Software\avsuite (Rogue.AntivirusSuite) -> No action taken.
HKLM\SOFTWARE\Classes\AppID\DynConIE.DLL (PUP.Optional.DynConIE.A) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Bad: ( Good: ( -> No action taken.

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\Users\Nicole\AppData\Roaming\FrostWire\.AppSpecialShare\ (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Nicole\AppData\Roaming\FrostWire\.AppSpecialShare\ (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\Nicole\AppData\Roaming\FrostWire\.AppSpecialShare\ (PUP.Optional.OpenCandy) -> No action taken.
C:\$RECYCLE.BIN\S-1-5-21-603193386-2267134397-3826343559-1000\$R3V0C1M.exe (PUP.Optional.InstallIQ) -> No action taken.
C:\Windows\Tasks\LyricsSing Update.job (PUP.Optional.Lyrics.A) -> No action taken.


March 7, 2014 at 16:54:15
Re my post #20, new log please when deleted.

"If your MBAM log indicates "No action taken". That's usually a result of NOT clicking the Remove Selected button after the scan"

March 8, 2014 at 15:32:12
Malwarebytes Anti-Malware

Database version: v2014.03.06.09

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Nicole :: NICOLE-PC [administrator]

3/8/2014 1:05:11 PM
mbam-log-2014-03-08 (13-05-11).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 225677
Time elapsed: 18 minute(s), 25 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)


March 8, 2014 at 15:44:34
Make sure you uninstalled Combofix, download the latest version & try again.

Report •

