Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Junkware Removal Tool (JRT) by Malwarebytes
- Version: 7.6.4 (09.28.2015:1)
- OS: Windows 10 Pro x64
- Ran by Nike on Mon 11/16/2015 at 0:16:40.90
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- ~~~ Services
- ~~~ Tasks
- Successfully deleted: [Task] C:\WINDOWS\system32\tasks\update-S-1-5-21-3492584764-1330717596-4027634359-1000
- Successfully deleted: [Task] C:\WINDOWS\system32\tasks\update-sys
- Successfully deleted: [Task] C:\WINDOWS\Tasks\update-S-1-5-21-3492584764-1330717596-4027634359-1000.job
- Successfully deleted: [Task] C:\WINDOWS\Tasks\update-sys.job
- ~~~ Registry Values
- ~~~ Registry Keys
- Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\APN PIP
- Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\AskPartnerNetwork
- Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
- Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
- Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
- Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\windowsmangerprotect
- ~~~ Files
- ~~~ Folders
- Successfully deleted: [Folder] C:\ProgramData\ihprotectupdate
- Successfully deleted: [Folder] C:\ProgramData\mailupdate
- Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
- Successfully deleted: [Folder] C:\ProgramData\windowsmangerprotect
- Successfully deleted: [Folder] C:\Users\Nike\AppData\Roaming\mailupdate
- ~~~ FireFox
- Successfully deleted: [File] C:\Users\Nike\AppData\Roaming\mozilla\firefox\profiles\sqjy0vui.default\invalidprefs.js
- Successfully deleted: [File] C:\Users\Nike\AppData\Roaming\mozilla\firefox\profiles\sqjy0vui.default\searchplugins\delta-homes.xml
- Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\faststartff@gmail.com
- Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\quick_searchff@gmail.com
- Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\searchengine@gmail.com
- Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\sweetsearch@gmail.com
- Successfully deleted the following from C:\Users\Nike\AppData\Roaming\mozilla\firefox\profiles\sqjy0vui.default\prefs.js
- user_pref(browser.newtab.url, chrome://quick_start/content/index.html);
- user_pref(browser.search.defaultenginename, delta-homes);
- user_pref(browser.search.hiddenOneOffs, Yahoo,Bing,Amazon.com,eBay,Twitter,delta-homes);
- user_pref(browser.search.searchengine.alias, delta-homes);
- user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
- user_pref(browser.search.searchengine.iconURL, hxxp://search.delta-homes.com/favicon.ico);
- user_pref(browser.search.searchengine.name, delta-homes);
- user_pref(browser.search.searchengine.ptid, wpm07163);
- user_pref(browser.search.searchengine.uid, SamsungXSSDX840XPROXSeries_S1ATNSAF924447B);
- user_pref(browser.search.searchengine.url, hxxp://search.delta-homes.com/web/?type=ds&ts=1437041000&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07163&uid=SamsungXS
- user_pref(browser.search.selectedEngine, delta-homes);
- user_pref(extensions.quick_start.enable_search1, false);
- user_pref(extensions.quick_start.sd.closeWindowWithLastTab_prev_state, false);
- Emptied folder: C:\Users\Nike\AppData\Roaming\mozilla\firefox\profiles\sqjy0vui.default\minidumps [18 files]
- ~~~ Chrome
- [C:\Users\Nike\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
- [C:\Users\Nike\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
- [C:\Users\Nike\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
- [C:\Users\Nike\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
- []
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Scan was completed on Mon 11/16/2015 at 0:18:12.68
- End of JRT log
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement