Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

rundll32 runs at startup with no command line, user name or description


  • Please log in to reply
43 replies to this topic

#1 AbsolutelyFreeWeb

AbsolutelyFreeWeb

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 23 November 2014 - 05:27 AM

Background: My computer has had viruses lately. it started with poweliks which is known to exploit rundll and powershell. I succeeded to remove it using eset and also manually going through all knows infection points. Yesterday, something else began, running lots of hidden and encrypted browsers inside emieuserlist. I'm not sure if that was a virus or normal way of IE11 enterprise mode. But I spotted dllhost again and killed all those processes and ran sophos and trend micro house call.

 

Situation now: I'm left with a rundll that starts without command line, user name or description at startup. I cannot find how it is started using msconfig. right clicking on it from task manager and choosing properties does nothing. right clicking and choosing create dump file gives an access denied error.

 

What I have done: I downloaded sysinternals procdump and made a dump of it (which task manager could not do). But don't have enough experience of win debugging to actually understand what it does. 

 

Request: I need someone that can analyze win programs and dumps and malware to help me see how this rundll is started and what exactly it is up to.

 

system info: windows 7 enterprise 64-bit


Edited by AbsolutelyFreeWeb, 23 November 2014 - 06:07 AM.


BC AdBot (Login to Remove)

 


#2 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 04:21 AM

I also ran kaspersky, with nothing serious reported.
Another symptom is, the computer takes a lot time after login and before desktop is shown, several minutes of just a blue screen with a mouse pointer...



#3 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:08 PM

Posted 27 November 2014 - 05:16 AM

Hello -

Did you follow the ESET removal instructions from here, or did you just Google it.

 

First : This Symantec Poweliks tool is to double check removal.

As well as the ESET tool to clean up Poweliks, please follow the directions from this >> Trojan.Poweliks Removal Tool | Symantec.
Directions are on site and listed here, and the tool is simple to use.

NOTE : Selecting "Run as administrator" will result in an incomplete repair. You must be logged in to the Administrator account and all other users must be logged out in order for the tool to work correctly.
Follow these steps to download and run the tool:

  • Download FixPoweliks64.exe for 64-bit computers and FixPoweliks32.exe for 32-bit computers.
  • Save the file to a convenient location, such as your Windows desktop.
  • If you are sure that you are downloading this tool from the Security Response website, you can skip this step. If you are not sure, or are a network administrator and need to authenticate the files before deployment, follow the steps in the Digital Signature section before proceeding with step 4.
  • Close all the running programs.
  • If you are running Windows XP, turn off System Restore. For instructions on how to turn off System Restore, read your Windows documentation.
  • Double-click the FixPoweliks64.exe or the FixPoweliks32.exe file to start the removal tool.
  • Click I Accept to accept the EULA, then click Start to begin the process and allow the tool to run.
  • When the tool has finished running, you will see a message prompting you to check the logfile for results.

     

  • The removal tool writes a summary of its operation to a logfile named FixPoweliks64.log or FixPoweliks32.log with results similar to the following:

     

    • List of terminated processes
    • List of removed registry values


#4 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:08 PM

Posted 27 November 2014 - 05:50 AM

Another symptom is, the computer takes a lot time after login and before desktop is shown, several minutes of just a blue screen with a mouse pointer...

I have noticed my Windows 7 is similar recently, so I choose to run these tools -

 

 

Step 2 - General Investigation -

Please post a snapshot with Speccy for more system details -
How to Publish a snapshot with Speccy <<-- Full Directions Here (only Copy / Paste the link)

 

Download Screen317 Security Check from Here or Here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt
  • Please Copy/Paste the contents of that document.
  • Note 1:: If any security program requests permission to access the Internet, allow it to
  • Note 2. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message, (or similar) restart computer and Security Check should run

 

 

Please download MiniToolBox  to desktop to run it.
Checkmark the following boxes:

  • List content of Hosts
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
Click Go and Copy / Paste the result. (result.txt)

 

 

Minor clean-up

Please download RKill by Grinler to desktop and run it
A black DOS box will appear for a short time and then disappear.
This is normal and indicates the tool ran successfully.
At most the tool will usually run for about 2 minutes
Please Copy / Paste the small log back here.

 
Do not reboot your computer until you complete the next step.


 NOW :

  • Download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
     * Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button (only once)
  • AdwCleaner will begin...be patient as the scan may take some time to complete. Watch the Green bar at the top.
  • After the scan has finished, click on the Report button only once for accuracy.
  • A report (AdwCleaner[R0].txt) will open in Notepad for your review.
  • Check the listed removals and see if you are OK with them.
  • If you have questions, post the Report log back here.

 Next

  • Click on the Clean button only once for accuracy
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK finally to allow AdwCleaner to Restart the computer and complete the removal process.
  • After rebooting, a log report (AdwCleaner[S0].txt) will open automatically.
    Copy and Paste the contents of that log in your next reply.

Note: With most Adware / Junkware / PUPs it is strongly recommended to deal with it like a legitimate program and uninstall from Programs and Features or Add/Remove Programs in the Control Panel. In many cases, using the uninstaller of the adware not only removes the adware more effectively, but it also restores any changed configuration. After uninstallation, then you can run specialized tools like AdwCleaner and JRT to fix any remaining entries they may find.

Next -
Please download Junkware Removal Tool to your desktop.

  • Temporarily Disable your Antivirus now to avoid potential conflicts.

     

    Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

Sophos Virus Removal Tool

  • Please download Sophos Virus Removal Tool and save the file to your Desktop.
  • Temporarily Disable your Antivirus
  • Right-Click the icon and select, Run as administrator to run the programme.
  • Click Next.
  • Select I accept the terms in this license agreement, then click Next twice.
  • Click Install.
  • Click Finish to launch the program
  • Once the virus database has been updated click Start scanning.
  • If threats are found click Details, followed by View log file.
  • Copy the contents of the log and paste in your next reply.
  • Close the Notepad document, close the Threat Details screen, and click Start cleanup.
  • Click Exit to close the program.
  • Re-enable your anti-virus software.

 

Thank You -



#5 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 10:45 AM

I had found the eset tool using google, and its name is ESETPoweliksCleaner. It's a small 183 KB file. takes a seond to run.

 

step 1 result- FixPoweliks64.log. the log file was found on desktop afterwards:

 

 

Trojan.Poweliks has not been found on the system



#6 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 10:52 AM

step 2 - speccy- it is showing two dllhosts. however I don't see them in task manager....
 
also notice the rundll entries. why would a tool like this not write more information, like the command line info of the processes?
 
 
And here is the screen317 results
 

Results of screen317's Security Check version 0.99.91 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Sophos Anti-Virus  
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 JavaFX 2.1.1   
 Java 7 Update 71 
 Adobe Reader 10.1.5 Adobe Reader out of Date! 
 Google Chrome 38.0.2125.111 Google Chrome out of date! 
````````Process Check: objlist.exe by Laurent```````` 
 Sophos Sophos Anti-Virus SavService.exe 
 Sophos Sophos Anti-Virus SAVAdminService.exe 
 Sophos Sophos Anti-Virus Web Control swc_service.exe
 Sophos Sophos Anti-Virus Web Intelligence swi_service.exe
 Downloads antivirus bleepingcomputer\securityCheck\SecurityCheck.exe
 Kaspersky Lab Kaspersky Security Scan 2.0 kss.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

 
OK, so about the dllhosts, they dissapear as soon as I open task manager. I got a glimpse with printscreen and there are two, and they have both the commandline:
 

c:\windows\systen32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

 
others with same experience:
 
http://www.bleepingcomputer.com/forums/t/205691/strange-behavior-with-dllhostexe/
 
https://forum.avast.com/index.php?topic=87740.0

Edited by Budapest, 30 November 2014 - 05:32 PM.


#7 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 11:10 AM

MiniToolBox by Farbar  Version: 21-07-2014
Ran by (administrator) on 27-11-2014 at 17:05:57
Running from "C:\Users\????\Downloads\antivirus\bleepingcomputer\minitoolbox"
Microsoft Windows 7 Enterprise  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
#64.182.208.247  www.alisocreekdental.com
========================= Event log errors: ===============================
Application errors:
==================
Error: (11/27/2014 09:18:01 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:59 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:31 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:29 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:07 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:05 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:31 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:16 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:15 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:15 AM) (Source: MSOLAP$LocalCube) (User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
System errors:
=============
Error: (11/27/2014 04:26:26 PM) (Source: TermService) (User: )
Description: The terminal server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: The specified domain either does not exist or could not be contacted.
.
Error: (11/27/2014 04:23:56 PM) (Source: TermService) (User: )
Description: The terminal server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: The specified domain either does not exist or could not be contacted.
.
Error: (11/27/2014 01:00:07 PM) (Source: NETLOGON) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain ???? due to the following:
%%1311
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
 
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Error: (11/27/2014 11:01:23 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (11/27/2014 11:01:23 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (11/27/2014 09:05:39 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{24FF4FDC-1D9F-4195-8C79-0DA39248FF48}{B292921D-AF50-400C-9B75-0C57A7F29BA1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
Error: (11/27/2014 09:04:01 AM) (Source: TermService) (User: )
Description: The terminal server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: The specified domain either does not exist or could not be contacted.
.
Error: (11/27/2014 09:03:16 AM) (Source: Service Control Manager) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error:
%%1069
Error: (11/27/2014 09:03:16 AM) (Source: Service Control Manager) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error:
%%1330
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
Error: (11/27/2014 09:01:14 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cdrom
Microsoft Office Sessions:
=========================
Error: (11/27/2014 09:18:01 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:59 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:31 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:29 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:07 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:17:05 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:31 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:16 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:15 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
Error: (11/27/2014 09:16:15 AM) (Source: MSOLAP$LocalCube)(User: )
Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
CodeIntegrity Errors:
===================================
  Date: 2012-07-05 09:51:49.144
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-05 09:00:24.327
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-05 08:44:05.290
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-04 16:30:11.781
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-04 16:02:34.624
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-04 15:59:39.978
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-04 15:44:40.968
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-04 15:36:38.208
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
  Date: 2012-07-04 14:56:43.400
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
=========================== Installed Programs ============================
5star Gomoku (HKLM-x32\...\5star Gomoku) (Version:  - )
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Reader X (10.1.5) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.5 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Apple-programstöd (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Application Verifier (x64) (HKLM\...\{89026002-A893-42D9-9E20-6829B844735E}) (Version: 4.1.1078 - Microsoft Corporation)
BankID säkerhetsprogram (HKLM-x32\...\{2D6973ED-BBF2-434E-993C-37E05087B8C8}) (Version: 5.1.3.2 - Finansiell ID-Teknik BID AB)
Blaine's Blends (Translucency and Compositing) (HKLM\...\{2C094D44-8F5E-4F7F-83AE-719B486E7672}) (Version: 2.0.1 - Blaine's Movie Maker Blog)
Blaine's Film Looks Effects (HKLM\...\{95BCCCA2-447E-4F8F-A4C5-49D5700BE627}) (Version: 1.0.1 - Blaine's Movie Maker Blog)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.1.3184 - CDBurnerXP)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Citrix Online Launcher (HKLM-x32\...\{75B8A55E-0762-4676-AAC0-6FDF025B034B}) (Version: 1.0.220 - Citrix)
Citrix XenApp Plugin für gehostete Anwendungen (HKLM-x32\...\{C1CCF2E9-4851-4783-8076-D9C3F7DDD487}) (Version: 11.0.150.5357 - Citrix Systems, Inc.)
Conexant 20672 SmartAudio HD (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.32.23.5 - Conexant)
Configuration Manager Client (x32 Version: 4.00.6487.2000 - Microsoft Corporation) Hidden
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Debugging Tools for Windows (x64) (HKLM\...\{DBFC6AAE-DCCB-4C23-B01C-3EDDDC03298B}) (Version: 6.12.2.633 - Microsoft Corporation)
Definition Update for Microsoft Office 2010 (KB2899521) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E48DACEA-5789-4CC5-8584-2E268C560131}) (Version:  - Microsoft)
Definition Update for Microsoft Office 2010 (KB2899521) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{E48DACEA-5789-4CC5-8584-2E268C560131}) (Version:  - Microsoft)
Definition Update for Microsoft Office 2010 (KB2899521) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{E48DACEA-5789-4CC5-8584-2E268C560131}) (Version:  - Microsoft)
Documentation (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
Elevated Installer (x32 Version: 3.2.4.0 - Garmin Ltd or its subsidiaries) Hidden
Energispararen (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}) (Version: 6.32 - )
Express Thumbnail Creator 1.8 (HKLM-x32\...\{6B63CA29-5D4B-4F48-8819-AEFEC1940E2D}_is1) (Version:  - Neowise Software, Inc.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FileZilla Client 3.9.0.5 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse)
Fotogalleriet (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Garmin BaseCamp (HKLM-x32\...\{8114290E-D0F6-4CC8-BD3D-F40278CD01EA}) (Version: 4.3.1 - Garmin Ltd or its subsidiaries)
Garmin City Navigator North America NT 2015.10 (HKLM-x32\...\{FCDB42FC-A70B-4041-877F-D73E16DE4345}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{95fb9355-9884-416e-b377-5339fc7ef31a}) (Version: 3.2.4.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.4.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.4.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin MapInstall (HKLM-x32\...\{F0D44E64-51EE-4888-A1FD-F13108B75A43}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries)
Garmin MapSource (HKLM-x32\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin Training Center (HKLM-x32\...\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
GitHub (HKCU\...\5f7eb300e2ea4ebf) (Version: 1.2.1.6 - GitHub, Inc.)
GMapTool 0.8.186a (HKLM-x32\...\{1873789F-59D5-4002-8A2F-60A827B78F98}_is1) (Version:  - AP)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Talk Plugin (HKLM-x32\...\{0C5C1177-94C5-3EFB-A8BE-3F6AF1AF887F}) (Version: 5.38.6.0 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
GoToMeeting 5.4.0.1083 (HKCU\...\GoToMeeting) (Version: 5.4.0.1083 - CitrixOnline)
HexEdit Pro (HKLM-x32\...\HexEdit Pro) (Version:  - ECSoftware)
HexEdit Pro (x32 Version: 4.0 - Expert Commercial Software Pty Ltd) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2875 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
IslandTopoV2 for MapSource (HKLM-x32\...\IslandTopoV2_is1) (Version:  - )
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java Auto Updater (x32 Version: 2.1.71.14 - Oracle, Inc.) Hidden
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kaspersky Security Scan (HKLM-x32\...\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C4}) (Version: 12.0.1.881 - Kaspersky Lab)
Kaspersky Security Scan (x32 Version: 12.0.1.881 - Kaspersky Lab) Hidden
K-Lite Codec Pack 10.2.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.2.0 - )
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 1.11 - )
Lenovo Patch Utility (HKLM-x32\...\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}) (Version: 1.3.0.9 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (HKLM\...\{0369F866-2CE0-4EB9-B426-88FA122C6E82}) (Version: 1.3.0.9 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (Version: 1.4.0.4 - Lenovo Group Limited) Hidden
Lenovo System Interface Driver (HKLM\...\LENOVO.SMIIF) (Version: 1.05 - )
MicroDicom 0.7.8 (HKLM-x32\...\MicroDicom) (Version: 0.7.8 - MicroDicom)
Microsoft  File Transfer Manager (HKLM-x32\...\{4C8169AB-B6C1-413B-81B6-73B77127D82F}) (Version: 5.00.34 - Microsoft)
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Dynamics NAV 2009 Classic (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Dynamics NAV 2009 Outlook Add-in (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Dynamics NAV 2009 R2 (HKLM-x32\...\DynamicsNav60) (Version: 6.0.32012.0 - Microsoft Corporation)
Microsoft Dynamics NAV 2009 RoleTailored Client (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Dynamics NAV 2009 Service (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Dynamics NAV 6.0 Setup (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Dynamics NAV 6-0 Database for SQL Server (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Dynamics NAV Components for Microsoft SQL Server (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Language Pack 2010 - Swedish/svenska (HKLM-x32\...\Office14.OMUI.sv-se) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office O MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project Professional 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Finnish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Swedish) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office X MUI (Swedish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Project Professional 2010 (HKLM-x32\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Report Viewer 2012 Runtime (HKLM-x32\...\{DFDB4411-54A2-41CE-AB89-CE54C176A69D}) (Version: 11.1.3436.0 - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2008 (KB971119) (HKLM-x32\...\Microsoft Report Viewer Redistributable 2008 (KB971119)) (Version:  - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2008 (KB971119) (x32 Version: 9.0.30731 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (HKLM-x32\...\Microsoft SQL Server 2005) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2005 Express Edition (x32 Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server Native Client (HKLM\...\{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (HKLM-x32\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{B636C9B9-A3F2-4DCE-ADCC-72E095018385}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Windows Performance Toolkit (HKLM\...\{E7F9E526-2324-437B-A609-E8C5309465CB}) (Version: 4.8.0 - Microsoft Corporation)
Microsoft Windows SDK .NET Framework Tools (30514) (Version: 7.1.30514 - Microsoft) Hidden
Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Common Utilities (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Headers and Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Samples (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK Intellisense and Reference Assemblies (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK MSHelp (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft Visio Professional 2010 (HKLM-x32\...\Office14.VISIOR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++  Compilers 2010 Standard - enu - x64 (HKLM\...\{88387B3B-B110-392F-B919-1A15B48F21D4}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++  Compilers 2010 Standard - enu - x86 (HKLM-x32\...\{370187B9-6964-38D0-851F-6C4898B0C2B1}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker 6.0 for Windows 7 (64-bit) (HKLM\...\{A7395F20-2B22-4CB8-8510-B452C0F47E02}) (Version: 6.0.0 - Microsoft Corporation)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
NVIDIA 3D Vision Driver 307.45 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 307.45 - NVIDIA Corporation)
NVIDIA Control Panel 307.45 (Version: 307.45 - NVIDIA Corporation) Hidden
NVIDIA Graphics Driver 307.45 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.45 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.85.551 - NVIDIA Corporation) Hidden
NVIDIA nView 136.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 136.53 - NVIDIA Corporation)
NVIDIA Optimus 1.10.8 (Version: 1.10.8 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.0745 - NVIDIA Corporation) Hidden
NVIDIA Update Components (Version: 1.10.8 - NVIDIA Corporation) Hidden
On Screen Display (HKLM\...\OnScreenDisplay) (Version: 6.60.03 - )
ooVoo (HKLM-x32\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.3022 - ooVoo LLC.)
OpenVPN 2.2.2 (HKLM-x32\...\OpenVPN) (Version: 2.2.2 - )
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Photo Gallery (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
PM FASTrack CAPM v3 (HKLM\...\PM FASTrack CAPM v3-v3002) (Version: 3.0.0.2 - RMC Project Management, Inc.)
PM FASTrack PMP v8 (HKLM\...\PM FASTrack PMP v8-v8005) (Version: 8.0.0.5 - RMC Project Management, Inc.)
PNG PSD Viewer (HKLM-x32\...\PNG PSD Viewer1.0) (Version: 1.0 - Wenovo.com)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RealDownloader (x32 Version: 17.0.14.26 - RealNetworks) Hidden
RealDownloader (x32 Version: 17.0.14.8 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.14 - RealNetworks)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Replay Music 5 (HKLM-x32\...\ReplayMusic5.05) (Version: 5.05 - Applian Technologies Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-041D-0000-0000000FF1CE}_Office14.OMUI.sv-se_{A05EAE18-293F-465F-802B-F5DE9465495C}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
ShaderTFX version 1.1 (HKLM\...\ShaderTFX_is1) (Version:  - )
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
Snagit 11 (HKLM-x32\...\{F8E3C768-71F3-11E1-9DF7-70804824019B}) (Version: 11.0.1 - TechSmith Corporation)
SonicWALL SSL-VPN NetExtender (HKLM-x32\...\SonicWALL SSL-VPN NetExtender) (Version: 3.5.111 - SonicWALL, Inc.)
Sophos Anti-Virus (HKLM-x32\...\{4320988A-7DE0-478D-A38B-CE9509BCE320}) (Version: 10.3.1 - Sophos Limited)
Sophos AutoUpdate (HKLM-x32\...\{15C418EB-7675-42be-B2B3-281952DA014D}) (Version: 2.9.0.344 - Sophos Limited)
Sophos Remote Management System (HKLM-x32\...\{FED1005D-CBC8-45D5-A288-FFC7BB304121}) (Version: 3.4.1 - Sophos Limited)
Spotify (HKCU\...\Spotify) (Version: 0.9.1.57.ge7405149 - Spotify AB)
Swedish Module for Microsoft Dynamics NAV Classic Client (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Swedish Module for Microsoft Dynamics NAV Documentation (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Swedish Module for Microsoft Dynamics NAV Outlook Add-In (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Swedish Module for Microsoft Dynamics NAV Role Tailored Client (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
Swedish Module for Microsoft Dynamics NAV Server (x32 Version: 6.0.32012.0 - Microsoft Corporation) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Requirements Lab for Intel (64-bit) (HKLM\...\{6AEC3114-709D-4CFF-9296-ECE23ED19F97}) (Version: 4.5.11.0 - Husdawg, LLC)
ThinkPad FullScreen Magnifier (HKLM\...\ThinkPad FullScreen Magnifier) (Version: 2.40 - )
ThinkPad Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.65.05.20 - )
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.1.1.0 - )
ThinkPad UltraNav-guiden (HKLM-x32\...\{17CBC505-D1AE-459D-B445-3D2000A85842}) (Version: 2.13.0 - Lenovo)
ThinkVantage Aktivt skyddssystem (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.75 - Lenovo)
ThinkVantage Fingerprint Software (HKLM\...\{C2938C94-239C-4156-B245-C5406A4F3E93}) (Version: 5.9.5.7038 - Authentec Inc.)
Transmission-Qt (HKLM\...\Transmission-Qt) (Version: 2.84 - Transmission)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Excel 2010 (KB2889935) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{153CD843-3EDC-412C-95B1-F36237DF8415}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A4F91D60-654C-4892-BFD3-0D41ADA649B6}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{0B7744D2-1FDD-4843-9987-7CE11B79F370}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.sv-se_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PRJPROR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-041D-0000-0000000FF1CE}_Office14.OMUI.sv-se_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{8158D96B-083A-4FE4-8587-B5D0F49FE4B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{8158D96B-083A-4FE4-8587-B5D0F49FE4B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{8158D96B-083A-4FE4-8587-B5D0F49FE4B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{8158D96B-083A-4FE4-8587-B5D0F49FE4B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{8158D96B-083A-4FE4-8587-B5D0F49FE4B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{8158D96B-083A-4FE4-8587-B5D0F49FE4B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PRJPROR_{794A0574-4E2F-4D58-B2A0-D7460ACDC85C}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{794A0574-4E2F-4D58-B2A0-D7460ACDC85C}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.VISIOR_{794A0574-4E2F-4D58-B2A0-D7460ACDC85C}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.OMUI.sv-se_{60C9499F-B532-4206-AB19-F88C3A7684D5}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PRJPROR_{C1954E2B-1672-4E5C-B564-F8CB2D08345B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{C1954E2B-1672-4E5C-B564-F8CB2D08345B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{C1954E2B-1672-4E5C-B564-F8CB2D08345B}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{DCE104A1-1875-4469-A83D-A5BFA6C4640F}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-041D-0000-0000000FF1CE}_Office14.OMUI.sv-se_{6D7DEB21-7536-421F-9A37-D599F5D7920B}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{334AA0A1-2BB1-4D74-B66A-2B2C4D9C2C87}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-041D-0000-0000000FF1CE}_Office14.OMUI.sv-se_{EC04A626-7160-4E90-BD93-4226EFBDB5F9}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2878251) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{521F54B6-E2E5-462D-946E-8161830DDF18}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-0054-0409-0000-0000000FF1CE}_Office14.VISIOR_{A5659197-BDB5-467F-A71A-1B817DDD7BDD}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Communications Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Media Encoder 9 Series x64 Edition (HKLM\...\Windows Media Encoder 9) (Version:  - )
Windows Media Encoder 9 Series x64 Edition (Version: 10.0.0.3809 - Microsoft Corporation) Hidden
Windows SDK IntellisenseNFX (x32 Version: 7.1.30514 - Microsoft) Hidden
WinHTTrack Website Copier 3.47-27 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.47.27 - HTTrack)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Visio Add-In for WBS Modeler (HKLM-x32\...\{F9D3C457-E9BB-42FD-8782-21CBA84A136B}) (Version: 2.0.1003 - TCSL)
========================= Memory info: ===================================
Percentage of memory in use: 45%
Total physical RAM: 8075.21 MB
Available physical RAM: 4416.21 MB
Total Pagefile: 16148.59 MB
Available Pagefile: 12039.05 MB
Total Virtual: 4095.88 MB
Available Virtual: 3973.29 MB
========================= Partitions: =====================================
1 Drive c: (HDD) (Fixed) (Total:465.76 GB) (Free:337.79 GB) NTFS
2 Drive d: (Backups) (Fixed) (Total:465.63 GB) (Free:298.02 GB) NTFS
========================= Users: ========================================
User accounts for \\?????
Administrator            Guest                    Sophos????    
UpdatusUser             
**** End of log ****


Edited by Budapest, 30 November 2014 - 05:41 PM.


#8 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 11:31 AM

Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 11/27/2014 05:28:08 PM in x64 mode.
Windows Version: Windows 7 Enterprise Service Pack 1
Checking for Windows services to stop:
 * No malware services found to stop.
Checking for processes to terminate:
 * C:\Windows\system32\crypserv.exe (PID: 1476) [WD-HEUR]
 * C:\Users\????\Downloads\antivirus\bleepingcomputer\securityCheck\SecurityCheck.exe (PID: 18520) [UP-HEUR]
 * C:\Users\????\Downloads\antivirus\bleepingcomputer\securityCheck\SecurityCheck.exe (PID: 4564) [UP-HEUR]
3 proccesses terminated!
Checking Registry for malware related settings:
 * No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
 * No issues found.
Checking Windows Service Integrity:
 * No issues found.
Searching for Missing Digital Signatures:
 * No issues found.
Checking HOSTS File:
 * No issues found.
Program finished at: 11/27/2014 05:29:25 PM
Execution time: 0 hours(s), 1 minute(s), and 16 seconds(s)


Edited by Budapest, 30 November 2014 - 05:34 PM.


#9 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 11:39 AM

adwcleaner, before restart
 

# AdwCleaner v4.102 - Report created 27/11/2014 at 17:34:02
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 7 Enterprise Service Pack 1 (64 bits)
# Username : ????5612 - ????
# Running from : C:\Users\????5612\Downloads\antivirus\adwcleaner\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000000-0000-6002-C000-0200F5DFFF46}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Google Chrome v39.0.2171.71
*************************
AdwCleaner[R0].txt - [3356 octets] - [27/11/2014 17:34:02]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3416 octets] ##########


there were two false positives, one office 2010 key, and one microsoft application key, here is the log after restart:
 

# AdwCleaner v4.102 - Report created 27/11/2014 at 18:29:11
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 7 Enterprise Service Pack 1 (64 bits)
# Username : ????
# Running from : C:\Users\????5612\Downloads\antivirus\adwcleaner\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
File Deleted : C:\Users\????5612\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
[x] Not Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Key Deleted : HKCU\Software\Softonic
[x] Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000000-0000-6002-C000-0200F5DFFF46}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Google Chrome v39.0.2171.71
*************************
AdwCleaner[R0].txt - [3500 octets] - [27/11/2014 17:34:02]
AdwCleaner[S0].txt - [1204 octets] - [27/11/2014 18:29:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1264 octets] ##########


Edited by Budapest, 30 November 2014 - 05:41 PM.


#10 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 12:36 PM

and this is junkware removal:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 7 Enterprise x64
Ran by ????5612 on 2014-11-27 at 19:05:53,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders
Successfully deleted: [Folder] "C:\Users\????5612\appdata\local\apn"
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{01C7D659-D73B-43AA-87C6-850B7023C72B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{02B9EF2F-9594-4EDE-80F7-E90BDDD5A5F7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{061F929B-2BFD-4900-8DD1-4801FB89BEDA}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{07326E13-9BB2-42A3-986A-608F112BB606}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0835D86A-7FB2-4CD1-AC65-FC24733A68F5}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{087CEF02-437F-464E-81CC-6A5E39B42E5D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{09855DD4-6078-4B99-B454-A9DB1791FC1E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0A1A245E-01BC-4737-86D1-3BDE07C84569}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0A529DCD-8906-41E2-A5C9-9D92E1A8E5F3}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0A69890A-5B80-4863-86D1-2B972DC6DC93}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0AB2924E-9B37-4BC3-841C-BB38C4AB427D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0C22BC66-F72C-40E9-9D3B-123D12313644}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{0E281EAD-1FDD-4DB4-9FB2-B37288F9CE7A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{11679ED5-1DE2-4422-8AD1-C4F4EEA5092B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{11D3C0EF-540B-4B80-BEC4-83812ED1CA5D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{12989A1F-6C87-4295-83D6-668C214DB515}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{132C1456-0010-43D1-9714-EF44D0C354AF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1710E282-B376-45A7-90ED-E6BF8AA31EA9}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{17F28AC7-A516-4369-8C42-5FF9D05874B8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{186894E7-AB42-4C4C-9DCC-4DE933AD2B27}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{18810431-DEDE-4657-98F4-89E694F92E0A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{18C25CC8-B6F8-454E-A56A-88E3F4CAE920}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{192D135B-8F2E-4F68-8AFB-3932E2017BB3}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{19363DD1-9187-4E4E-B5E6-FDCD47AAF9FB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1B6245D5-8B88-4D12-B4CA-2B91AA62BCBC}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1C4FA535-4697-4DAB-A7AA-E0FEB0FE2A79}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1CCA9C90-E808-4102-9548-613C0CB7FCEA}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1D54ABCB-5974-4B26-938B-FF6CF8FF4C9B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1DAE77BF-51EE-490A-A480-0D3DD25DD1EE}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1E343754-5A55-470C-BA40-D6D4DD2D63D7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{1E8EDCAF-EAC6-4B90-A792-7484E90A929B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2068FB9C-534B-4759-82F2-DE71F235E2D0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{22FF568E-F3E7-4640-8762-9F8EDDACB901}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2420FE2B-82B2-4897-951F-8A5BE7233AF2}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{24BFBF31-A631-42C1-8C1F-5EA198EA6E66}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{252F9F2C-DBBA-4F26-B308-4960ED6B833E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{25C6D31E-74DF-48CE-8CC6-0C2D88A9C284}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{264AE569-2AE4-4937-AE79-C4EB884A53C8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2665624C-7AAF-43D5-BB98-1540A58AE02E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{26954F6D-44E8-4933-97F6-DF65E0112DE5}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{270DEAD6-7393-4EE4-AB41-F40379E4F1BE}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{273343B0-734F-4C1E-960B-0D2F471EE3AD}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{286E0453-A8A7-4D78-974C-2E0174F1A446}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{287B53E3-C20A-42F8-B741-C7A655F62D3B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{295AA3EF-6494-458B-B8C4-AF83FA4541D8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2BBD49FC-9722-41DB-9D11-2068A26E53FD}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2BC5697E-5280-4B97-9B93-F43214CC7900}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2D921E1E-1E40-4A70-8780-E4B5713FA58F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2DB0444C-2DAE-483F-8F27-28D4B3D9B671}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2DDB738B-BC13-47A0-A085-1F9EA3407B0B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{2DDE9494-293A-4884-B8FC-2C1F0AB02919}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3060FD74-380C-4E8E-BAD4-668FC4ED2601}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{307E7613-5A67-4DF5-BFB8-8E93826244BF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{314D06C6-CD28-4332-B630-A10D10C2D159}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{32A2E648-BCE6-4D2C-8992-42E74DF0C45A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3408AE04-B09A-4931-8940-C2DE213E9DB7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3445537A-7AA1-47DF-B19B-7CD0BC6381D8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{348504AA-15C3-4756-9E1E-5ECF52638BC1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{34D37F95-95F6-4C9E-BC32-F581390D5765}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{356BBD1A-2583-4C6C-B038-8D65C07F51FD}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{35FF6F98-AB38-4327-9EE3-4FBAD3A6B4B9}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{36778A52-29A2-43F4-8A2A-8F83F2C37539}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{36B873D9-AC19-434C-B6DD-83442E6B908F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{385EB354-9D63-4B78-8400-77D48BBFCA43}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{39E61760-2857-496A-91B3-51C094F75D57}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3B5F122A-B92C-44A6-9070-7C4478B3AE05}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3DB4966A-3C7B-468B-A6BB-02C0B9B2AEF6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3E33C50A-4A3E-4AFF-A633-27F08BDC6F20}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3E8BC32F-22AF-47A2-9D8F-6FFE47CE2CE5}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3E917394-5AA2-4853-9EFD-4D9E2E6BD374}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3EAD4BDB-926E-4BB6-BF85-B5F21C605ADE}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{3FB03C07-A0A1-4D3D-A28A-7DDFC432D1E0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{40FAB8B4-3AD3-485A-8E0B-7415AACE639D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4198369B-B15E-4128-B3CD-950101305AB7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{41D8690B-66AE-42F6-9B32-133AD1054431}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4382FAD1-8F78-4C9F-9C96-DB7C82A421E6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{43E927C1-83C6-423D-98D0-2EE0B1ED8EA5}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{45793196-CB4C-465A-8D06-B8B519872DE1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{45A9496A-1CB2-4023-B771-D311CFAF37F8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{47476B43-807D-4F69-ADAE-AD78D2E45AC4}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{47B68356-59AA-48D1-B40C-6B4E95B22046}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4828EE75-EC06-4311-9FA3-5740F78EDFDC}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4B52D85B-14BE-4566-A76F-60365913A7F3}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4C7B9715-DE30-4303-B000-BECAE2710CC4}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4DE32BB4-0ECA-4549-B32E-F8B5149087B4}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{4EFEB933-C9F8-48B2-A3B4-1AE7C0FA4C45}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{53F8CC08-3C31-4A2A-8699-FE383F34F66A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{555B13E2-F3C5-4A78-80BF-83D12EAC4502}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{557A51B7-E10B-4368-8765-C66ADBD4C207}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{56D444EE-E414-4A67-967F-7E0DFD25C497}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{58A85A4F-9231-4AF5-9358-8BD3D6E641DF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{58ABB4C7-2BDE-4FEA-98E2-54DE25702B9A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{59438774-E494-4D48-8EF9-BD2AC88F2843}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{59B41DB5-50A8-42FA-80CB-2ED92DD60C6F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{5AF6A388-B95E-4D26-AE2F-2ACF31293E05}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{5BCF0C88-C9C1-40D0-8ACC-E3859FD7B275}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{5BD361E5-552C-42AF-8B24-A75D6F988EA8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{5DD6A6D0-7A68-43D2-80F3-4C88AF7324CF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{5E9546B6-DDC8-48DA-86F3-4818BC13D4B1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6048F754-64C5-4E35-8F43-D2C0B0766CCE}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{623B57F7-17C7-4561-96F6-A36E409D6404}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6406738E-8974-4DBF-BD1F-1B2DAB18965F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{64B1B4E0-C563-4D9D-BCEF-E8E259D53DA6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{64B84854-E3E4-4066-B6D3-8C96F0BEF3C1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{64D7B954-FAF5-4E93-98D2-AA0A52F44006}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6519D634-CEE1-4135-9D0C-19E79ADD59DF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{65E63CA6-B01D-4B63-8CA9-EE5323EA6E76}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{69B1F6FB-0492-4B60-B7BB-5A03E85B157D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6C0FDB9E-FBF6-4DAA-96C4-9BFCC3F3DF39}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6DD47F67-27F5-4C4B-9AE4-0008DBC576A4}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6E2D1DA0-B4BE-431B-934C-2649D06289D5}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6F5730E9-7C3F-406A-985A-5DA38131858F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{6FE01B2B-9FA4-4AE1-A15F-8E1861C9A088}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{709E9B74-C3F3-42F6-9190-26A76A1F317E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{712BAA35-1C81-4F09-A3B6-B5A4D5B120E0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{723818F7-8A74-4DBB-ABA5-975A551A897E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{72549CBF-AD26-492D-9D8C-60BD100285E5}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{73C80305-6D6B-41C5-87B2-D47969AF185A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{748B2411-2F01-41CD-9F88-6225ED3E1AA2}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{75ADF3A5-95CF-45AA-93DF-D0CE6475B231}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{75B427C6-4A96-40B1-A4A0-AB34E01DFDEF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{76B06C9E-D2D6-406B-ADE3-6399A28B8A7C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{76B93AFD-0219-47DA-84BC-7155649DE880}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{77B6D465-9176-44B4-9D50-ADC7F4ECA8F4}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{78F9F982-2A5C-4039-93BA-4510DEDC22E6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7A00C554-B32C-4EA0-9221-83BA34CA15BE}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7B71E6DC-523A-46A6-A1B8-F2C40E955B70}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7BC04F65-5183-4A3C-B629-8C6F94E3B878}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7C04AB46-55AF-4C57-ACD9-14CFE333C9C1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7D41A106-A67A-4441-9115-96BFFB450C4B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7D92C5B3-5537-4398-8317-4F49DD786EF4}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7E7D614F-48A5-494A-9016-1F006227DED0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{7FED21EC-8BE0-4137-989A-F6912B961127}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{8152C08A-7FF4-47A6-A229-680BDBD76EC8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{81A62B0E-4E08-409A-B702-D52656F84898}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{83238FA1-B260-45B7-9F70-C3F61DCF0D3C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{83ECF659-5B83-4AF7-81F6-A31BE00D5CA7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{84BC0C77-A239-424A-9CAC-67FF8ABAC610}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{8560EC64-0AAB-4567-AD08-1139B4B359D6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{86BFF1D5-436B-4BBC-9A2E-075D136963A0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{87C193E3-A0DE-4F44-931B-6D4BBBA948A8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{88215874-CBA0-4DFA-9314-E79EE89A2280}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{89EA6364-241C-4788-A28C-5BDA29254A5F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{8CD89E30-08AA-4381-B118-17C326AF0593}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{8D1369C2-5386-4C91-A9C2-462971638C1F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{8D808654-929C-4883-A083-E4326B024CAB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{8F74A71F-4F97-4D64-A0C2-5172E4714A22}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{91B51D83-0A8C-48AA-888C-72076A13130E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{91FBF3B6-D59D-4C05-8987-8CBB2B1FB73B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{9674E622-964E-48E1-81E6-E82C627107A1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{971BB899-83E9-4BE9-8512-8CCCD1716207}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{973B8F52-C864-46BA-9E1A-4D453BAACBC0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{97D4783B-7F92-4920-A7A5-818E01C39308}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{987C0A46-9B04-4A11-AA6F-60C125F72B24}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{98DDE85B-D7B2-49BB-B0BB-49B58631048A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{98E59E8F-F16C-41F9-91C3-B550CC5A93EB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{98ED2B84-9A28-4235-BB9E-248F8F25538E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{9A9D894E-CF6D-48DB-8946-3EAA75DBAEC6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{9B50AE42-E95A-413B-8117-8F4074831525}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{9FA57983-B9F7-4882-8DA5-D216C6A95072}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{A0CCA844-51A1-40C0-8C8A-CD75D39E839A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{A56A3CA1-BBFB-45AE-9BE6-C4D24CAF42FA}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{A635DED5-6CC7-4E5C-A945-1C897BB245DD}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{A69A7257-02E2-44CE-9885-3054801372AD}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{A9EEFDD2-ABEE-4129-881A-A4AFE2C665DD}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{AA5FB14A-AB1D-4DCF-9122-8246B38CC0C1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{AB0D8C98-D671-48E5-B461-26885B20588C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{AC0D6826-B766-4E0E-BD1A-88393D14480C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{AE438084-F2CD-4765-B96F-B324D70AAD20}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{AF074A5B-357C-496E-A23C-34C908CB2317}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{AFD69A32-F1C3-4B61-8BEA-0566E20642E6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B161F163-F383-467D-BF4E-E89674212FA2}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B364ED59-154A-4BE6-B8AF-8F322C080277}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B44E5C5B-F101-444F-9836-9DB871BEB13D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B47EEAC3-C43B-4E1B-82A2-EC1D92EB1930}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B4978560-1896-4DC1-9206-5DE3F9635328}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B4D37937-A0F8-443C-BD97-704D7E993B43}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B57E9067-B0BA-4907-9472-F152C21D2D2D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B5E64949-4B49-4D55-8D24-3CECF259208E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B64729F8-6B9C-4EC8-9C87-0E1001C0BAE9}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B7EE9B73-02C1-46D6-98F1-C6EC48C70E4C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B8030C05-ED39-4C59-846F-1A9A074A7ADC}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B8803B5D-7B44-4C98-AA9E-B444322061A9}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{B98F0DE1-DE5B-44E1-B9E2-BBB33F81B258}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{BB4DFAF0-65F6-4EA7-B253-C66D59A3BA40}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{BBB64D57-B6DE-45F7-8EA0-26C4A330C6F6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{BD3F6F81-1A60-4AE3-A967-60946DC5AB87}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{BF624DB6-CF67-4CC4-8AEC-DAE06C36FB06}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C1097E10-0B70-4E00-B677-DB6BF0A9A53A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C12F60B8-AB1D-4CC7-859D-92E8223C3A47}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C13CA7E8-D401-4B61-88C5-8A1F48E947DB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C3E0D797-3217-48D2-87FE-35179852A8E7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C473B5BF-E3D1-406E-895E-769ACBF835FF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C4EDB84C-279D-4828-B4A0-C06836FD7BB8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C743CB48-AA8A-460F-9123-129AC37812B2}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C76DA8EC-5F18-4C64-8396-63C4A4EC51AB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C77A3BF0-E426-4045-95BC-2C3475EEC4AB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C7CA4AD5-AB2A-490B-AFE2-957C62A2997C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{C8EE8D27-0BC4-4282-9414-42706AFDEA0C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{CCD22961-6569-42A9-88AD-D4943A54D163}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{CD4A83FD-C886-457A-9783-2D74D23B0777}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{CFB41605-6B52-47CF-AF39-4EB016DD7418}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{CFFDE0FD-4DD0-446B-A3A3-F52E3B4888A7}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D04589EE-7F87-431F-85F8-A7AC743A9539}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D09747C5-046F-4A72-A8D2-73E00384A741}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D1FACB39-8E1D-49D2-83B0-7BDBF0F26CE1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D204EB7F-57B7-4688-A1DA-5306105F4A21}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D40EF997-86B0-4F86-B277-98A184C9327C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D4E3408A-424D-46C8-BFAB-B4278ABD681F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D596F8D7-6AD1-4073-985C-1386C72E5DDA}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D599EE3C-C899-4F7F-9458-BF061E3D2116}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D79DE752-9904-48B7-A613-4E85DC71371B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D809795E-D828-4C7A-82E2-1BFF3972D783}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D940C53A-9435-4519-8723-E215FE504542}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{D9C17F2F-5D80-4BC8-86E0-37032D71005A}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DA684579-EBA7-4B32-967F-0A0CB0F4368E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DADE5FA8-7B0C-4B48-9E81-C371A55355CC}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DBBC51E1-3BD9-4BAD-91B1-14BF3DFADB3F}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DBE0FBF8-CA8E-4F86-B002-AE7F3C1C6BA8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DC54D647-6BC8-45ED-954F-B720AB1626F8}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DC6B0E9C-0CFD-4639-B52B-069E47BE21D6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{DE873AAB-A4E3-4914-9AD9-6E7A8AAC2770}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E14D3485-BDEF-4521-ACF4-4D59F07624A9}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E2E89E81-0F3B-47CE-A7DE-309BBF7ECB50}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E342CEBE-9BCE-4255-AD6E-EFFBF1108A0C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E365E34B-6825-488C-BFFC-D8E795EFF548}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E3B325E7-50A8-4792-B73F-F70A7D89DAB0}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E502C9B7-E447-435B-8982-EA2EA1599A38}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E5BB83C5-CE75-47DE-B0AA-EE9BF9B2387B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E6D4D28F-96F9-4787-95C9-46D93D2C5629}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E7213CD2-20D2-46D3-A0AE-15C5A978462B}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E73EE3EE-4A1C-4D4A-A164-F02B7DDB42CE}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E894FD8D-7D9D-45BE-AD00-C1FD8FFF16D1}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{E8D508D3-FC24-4D57-B8A3-DEABB628428E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{EACEC2A4-D520-40EB-AC36-036186229C60}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{EC9B8EF0-015D-41BB-B7E1-F74A9A0FEF8C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{EF978F11-7C99-4BB9-90EB-F0CC83CFCB2C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F12BE233-31EF-4EE5-B0D7-04976D973B0C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F46A57A9-A023-43D8-AE49-ABF5EF5D4B3C}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F479F080-280C-473F-B268-00A30DCEC5D9}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F52EAB3E-6440-49F2-890B-34E94CBECC23}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F565185E-BCEF-469C-93E2-259A37F78DF6}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F64C3E7A-8B2D-403E-9F85-F6D836960734}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F7FD94C9-9B19-4084-B94A-92590320F313}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F83C115D-D92A-4690-80B2-A3556AEC86CF}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{F8B68776-BF55-488E-8D26-FB440FA94557}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{FA89584D-E715-4BFB-B723-980F1D399F40}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{FB6A7866-C789-4A98-9A1D-5BA41E004BDB}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{FBA65B9A-F80D-4C3F-BB87-6C64FF012C3E}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{FBAC5281-614C-498C-B84D-1DA4A307BE8D}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{FF8A9949-A104-454D-8923-A4A028C08A86}
Successfully deleted: [Empty Folder] C:\Users\????5612\appdata\local\{FFC03DD2-D53B-4E38-BE4F-67BC6687E567}

~~~ Chrome
Dumping contents of C:\Users\????5612\appdata\local\Google\Chrome\User Data\Default\Default
C:\Users\????5612\appdata\local\Google\Chrome\User Data\Default\Default\aadjdhgedjdggddegfdedigcdededegf
C:\Users\????5612\appdata\local\Google\Chrome\User Data\Default\Default\aadjdhgedjdggddegfdedigcdededegf\manifest.json
Successfully deleted: [Folder] C:\Users\????5612\appdata\local\Google\Chrome\User Data\Default\Default [Default Extension 1.0]

~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2014-11-27 at 19:08:57,48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Edited by Budapest, 30 November 2014 - 05:37 PM.


#11 AbsolutelyFreeWeb

AbsolutelyFreeWeb
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:08:08 AM

Posted 27 November 2014 - 01:29 PM

My main antivirus is sophos, so I suspect the sophos virus removal will not get any hits at all. I'm running it just for completeness. As you can see all programs think it's clean. Yet we have at least a suspicious rundll, and very lengthy login that is not caused by amount of programs being started. It is a mystery. Perhaps we should, 1. check startup programs in more detail. 2. investigate errors during startup 3. solve the rundll mystery. Further comments appreciated, thank you.

 

EDIT: Sophos results: Your computer is clean. Number of threats found: 0


Edited by AbsolutelyFreeWeb, 27 November 2014 - 02:46 PM.


#12 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:08 PM

Posted 27 November 2014 - 06:48 PM

Thank you and I will break this into a few posts, if needed.

Please do not enclose posts in Quote or Code just for easier reading - Thanks.

 

Trojan.Poweliks has not been found on the system (thank you, as this is a 2nd check)
Both HDDs read OK ...........
HITACHI HTS727550A9E364 HDD (Main HDD)
Status: Good
Temperature: 35 °C
HGST HTS725050A7E635 OP (Second HDD)
Manufacturer: Hitachi
Product Family: Unknown ??
 

2 other site links to show dllhost.exe *32 processes running
Symantec and Poweliks << Window Task Manager reveal many copies of the dllhost.exe *32 processes running. This can also be related to a past episode of Powliks .......... (several sources if requested)
Multiple "dllhost.exe *32" and now "Poweliks << Just another example of why I asked for the second Poweliks scan
NOTE : dllhost.exe is the genuine file of Microsoft Windows operating system. Check if the dllhost.exe is running from C:\Windows\system32 directory.
You can use to use Process Hacker instead of TaskManager, as it would give you more insight of the processes and the dll files running on the system.Process Hacker:>> http://processhacker.sourceforge.net/

If dllhost.exe is located in a subfolder of "C:\Documents and Settings", the security rating is 66% dangerous. The file size is 417,792 bytes (67% of all occurrences), 393,216 bytes and 5 more variants. There is no information about the author of the file. It is not a Windows core file. The program starts upon Windows startup (see Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). The program has no visible window. Dllhost.exe is able to monitor applications and manipulate other programs.
General information.
If dllhost.exe is located in a subfolder of C:\Windows, the security rating is 18% dangerous (generallyOK). The file size is 7,168 bytes (76% of all occurrences), 58,325 bytes. The program is not visible. It is a trustworthy file from Microsoft. Dllhost.exe is able to hide itself and monitor applications.
If dllhost.exe is located in the folder C:\Windows, the security rating is 75% dangerous. The file size is 762,368 bytes (38% of all occurrences), 956,928 bytes and 7 more variants.
If dllhost.exe is located in a subfolder of C:\Windows\System32, the security rating is 81% dangerous. The file size is 10,240 bytes (63% of all occurrences), 114,688 bytes, 370,688 bytes or 13,312 bytes.
If dllhost.exe is located in a subfolder of "C:\Program Files", the security rating is 48% dangerous. The file size is 393,216 bytes (20% of all occurrences), 624,128 bytes and 6 more variants.
If dllhost.exe is located in a subfolder of "C:\Program Files\Common Files", the security rating is 58% dangerous. The file size is 656,384 bytes.

RKill is nice and clean -

 

AdwCleaner only removed ask.com as is normal. (Two false positives), which is why we normally ask to post a scan log if not sure.

 

J.R.T. found many (typical) >> Successfully deleted: [Empty Folder]

 

We can scan with ESET Online if you wish, as it is said to be more "Heuristic" than some others.

 

A few more items to go back over first, and then another post, or answers to your questions.


Edited by noknojon, 27 November 2014 - 06:50 PM.


#13 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:08 PM

Posted 27 November 2014 - 07:44 PM

step 2 - speccy- it is showing two dllhosts. however I don't see them in task manager....

also notice the rundll entries. why would a tool like this not write more information

Some tools only report a certain amount of information and that is all............

 

Speccy is programmed by others who think that this is enough information.



#14 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:08 PM

Posted 27 November 2014 - 08:16 PM

For Error: Description: Message-handling subsystem: The message manager for the 1053 locale cannot be found.
All I can find is to clean out temp files / cache

JRT tool removed a lot of Empty Folders (that is what Poweliks infection can create)

 

Please download Temp File Cleaner by Old Timer to desktop
Usage Instructions

1.Download TFC from the download link above and save the file on your desktop.
2.Close ALL running applications as TFC will terminate them before attempting to clean up the temporary files.
3.Double-click on the TFC icon.
4.When the program opens, click on the Start button.  TFC will terminate the Explorer process and all running applications and then begin the process of cleaning out all of your temp folders.
5.When done, press OK > Exit, and reboot your computer and finish the cleanup

No log is given or expected.

 

Minor updates >>
The Chrome team is delighted to announce Chrome 39.0.2171.65 as latest stable version.
Adobe Reader is now in X1 (version 11)
 

Please reboot after these and see if the problem still exists .....



#15 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:08 PM

Posted 27 November 2014 - 09:36 PM

The 2 links you posted were both related to legal sources and are meant to be there ..........

Results for {e10f6c3a-f1ae-4adc-aa9d-2fe65525666e}
That is a legitimate function... Related to the user profile
Found in Windows Vista registry
Registered class: PSIProfileNotify
Inproc sever: C:\Windows\system32\USERENV.dll (product: Microsoft® Windows® Operating System,version 6.0.6000.16386)
Registered interface: IProfileNotify
Subkey of registry key HKLM\SOFTWARE\Classes\AppID

 

 

strange thing I have is a rundll32.exe process that wants to dial-out to MS periodically.
REPLY =
That address resolves to MS - do you have windows updates set to auto ?
Also windows does a defrag in the background if you have it set up, plus the various housekeeping tasks all done seamlessly without you noticing

 

There is usually a reason for most of these items unless they show up in your Errors.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users