~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.4 (07.09.2017) Operating System: Windows 7 Ultimate x86 Ran by NetinfoTALI (Administrator) on 18/11/2017 at 10:44:42,72 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 47 Failed to delete: C:\Program Files\ExstRRaSaviNgs (Folder) Failed to delete: C:\Program Files\RoboSaavEr (Folder) Failed to delete: C:\ProgramData\aakknnijeopenodbacjamonfkcbkbhha (Folder) Failed to delete: C:\Users\NetinfoTALI\AppData\Roaming\mystartsearch (Folder) Successfully deleted: C:\Program Files\DeaalEoxpress (Folder) Successfully deleted: C:\Program Files\DealExpreess (Folder) Successfully deleted: C:\Program Files\ExstrASavinGs (Folder) Successfully deleted: C:\Program Files\FuNDeals (Folder) Successfully deleted: C:\Program Files\Mozilla Firefox\searchplugins\mystartsearch.xml (File) Successfully deleted: C:\Program Files\RobOSaver (Folder) Successfully deleted: C:\Program Files\RoesPectSale (Folder) Successfully deleted: C:\ProgramData\13313360497832468117 (Folder) Successfully deleted: C:\ProgramData\apn (Folder) Successfully deleted: C:\ProgramData\mntemp (File) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\fileviewpro (Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ogminpmldncgcmokldnmmapddoccmhfl_0.localstorage (File) Successfully deleted: C:\Users\NetinfoTALI\Appdata\LocalLow\iac (Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Roaming\opencandy (Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Roaming\solvusoft (Folder) Successfully deleted: C:\Windows\System32\Tasks\APSnotifierPP1 (Task) Successfully deleted: C:\Windows\System32\Tasks\APSnotifierPP2 (Task) Successfully deleted: C:\Windows\System32\Tasks\APSnotifierPP3 (Task) Successfully deleted: C:\Windows\System32\Tasks\Bidaily Synchronize Task[8da6] (Task) Successfully deleted: C:\Windows\Tasks\APSnotifierPP1.job (Task) Successfully deleted: C:\Windows\Tasks\APSnotifierPP2.job (Task) Successfully deleted: C:\Windows\Tasks\APSnotifierPP3.job (Task) Successfully deleted: C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job (Task) Successfully deleted: C:\Program Files\couponight (Folder) Successfully deleted: C:\Program Files\incognitofilter (Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\466BV6BA (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6CO6Y53E (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G4AS4JJI (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMEHOCM6 (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HU549TOT (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NJ6F93N7 (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9EBITNJ (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S1PO98R8 (Temporary Internet Files Folder) Successfully deleted: C:\Users\NetinfoTALI\AppData\Roaming\appdataFr2.bin (File) Successfully deleted: C:\Users\NetinfoTALI\AppData\Roaming\appdataFr25.bin (File) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\466BV6BA (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6CO6Y53E (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G4AS4JJI (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMEHOCM6 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HU549TOT (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NJ6F93N7 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9EBITNJ (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S1PO98R8 (Temporary Internet Files Folder) Deleted the following from C:\Users\NetinfoTALI\AppData\Roaming\Mozilla\Firefox\Profiles\euoi3nlz.default\prefs.js user_pref(browser.newtab.url, chrome://quick_start/content/index.html); user_pref(browser.search.selectedEngine, mystartsearch); user_pref(extensions.0EBoDowtbQxOO1UX.scode, (function(){try{if(window.location.href.indexOf(\qdnGrjC8rTY7pdsHrTn5qTU5qa\)>-1){return;}}catch(e){}try{var d=[[\www.ewoss. user_pref(extensions.1tdkjpF0gcdYnb0N.scode, (function(){try{if(window.location.href.indexOf(\qdnGrjC8rTY7pdsHrTn5qTU5qa\)>-1){return;}}catch(e){}try{var d=[[\www.ewoss. user_pref(extensions.AYTkAffiftkP9n0q.scode, (function(){try{if(window.location.href.indexOf(\qdnGrjC8rTY7pdsHrTn5qTU5qa\)>-1){return;}}catch(e){}try{var d=[[\www.ewoss. user_pref(extensions.AZEhqwFfga0VGuJX.scode, (function(){try{if(window.location.href.indexOf(\qdnGrjC8rTY7pdsHrTn5qTU5qa\)>-1){return;}}catch(e){}try{var d=[[\www.ewoss. user_pref(extensions.Y7UXQFZTFx0qk8QO.scode, (function(){try{if(window.location.href.indexOf(\qdnGrjC8rTY7pdsHrTn5qTU5qa\)>-1){return;}}catch(e){}try{var d=[[\www.ewoss. user_pref(extensions.quick_start.enable_search1, false); user_pref(extensions.quick_start.sd.closeWindowWithLastTab_prev_state, false); Registry: 8 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{a0892e19-6051-4ae6-9a5f-91542a166b2b} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{a0892e19-6051-4ae6-9a5f-91542a166b2b} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL (Registry Value) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Main\\Search Page (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18/11/2017 at 10:47:53,10 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~