~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.3 (04.10.2017) Operating System: Windows 8 x64 Ran by Paulette (Administrator) on 29-06-17 at 15:57:14,54 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 27 Successfully deleted: C:\ProgramData\mntemp (File) Successfully deleted: C:\ProgramData\pdfforge (Folder) Successfully deleted: C:\ProgramData\productdata (Folder) Successfully deleted: C:\Users\Paulette\AppData\Roaming\Mozilla\Firefox\Profiles\auzog4fj.default-1458071819902\extensions\iobitascsurfingprotection@iobit.com (Folder) Successfully deleted: C:\Users\Paulette\AppData\Roaming\Mozilla\Firefox\Profiles\auzog4fj.default-1458071819902\user.js (File) Successfully deleted: C:\Users\Paulette\AppData\Roaming\productdata (Folder) Successfully deleted: C:\Windows\system32\Tasks\Driver Booster SkipUAC (Paulette) (Task) Successfully deleted: C:\Windows\system32\Tasks\SmartDefrag_Startup (Task) Successfully deleted: C:\Windows\system32\Tasks\Uninstaller_SkipUac_Paulette (Task) Successfully deleted: C:\Windows\Tasks\Uninstaller_SkipUac_Paulette.job (Task) Successfully deleted: C:\Windows\wininit.ini (File) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\35O0FPOJ (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BGGNDIP1 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BHIDLA09 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G4YKWDUP (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NY63DYRS (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q8TMINXF (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QMQO26JP (Temporary Internet Files Folder) Successfully deleted: C:\Users\Paulette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZT2DX2X3 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\35O0FPOJ (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BGGNDIP1 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BHIDLA09 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G4YKWDUP (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NY63DYRS (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q8TMINXF (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QMQO26JP (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZT2DX2X3 (Temporary Internet Files Folder) Deleted the following from C:\Users\Paulette\AppData\Roaming\Mozilla\Firefox\Profiles\auzog4fj.default-1458071819902\prefs.js user_pref(browser.urlbar.suggest.searches, true); user_pref(extensions.xpiState, {\app-profile\:{\iobitascsurfingprotection@iobit.com\:{\d\:\C:\\\\Users\\\\Paulette\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Pro Registry: 5 Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_DC619C9BB5297F59601F58D28E5C2A60 (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{84F23192-A475-4038-B5C0-8584777F2DF4} (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29-06-17 at 15:59:46,89 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~