cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Ultimate x64
Ran by AHM (Administrator) on 24/08/2017 at 11:46:22,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 48

Failed to delete: C:\Users\AHM\AppData\Roaming\microleaves (Folder)
Successfully deleted: C:\ProgramData\9a60bc73-12d1-1 (Folder)
Successfully deleted: C:\ProgramData\9a60bc73-39e7-0 (Folder)
Successfully deleted: C:\ProgramData\drivercure (Folder)
Successfully deleted: C:\ProgramData\microleaves (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\edbmobghbfpobjijpbkahojamahhjhgo (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkemddiljapcmhicklfpcbpfffahfbja (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\edbmobghbfpobjijpbkahojamahhjhgo (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mallpejgeafdahhflmliiahjdpgbegpk (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mallpejgeafdahhflmliiahjdpgbegpk_0.localstorage-journal (File)
Successfully deleted: C:\Users\AHM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mallpejgeafdahhflmliiahjdpgbegpk_0.localstorage (File)
Successfully deleted: C:\Users\AHM\AppData\Roaming\drivercure (Folder)
Successfully deleted: C:\Users\AHM\AppData\Roaming\flvplayer (Folder)
Successfully deleted: C:\Users\AHM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\qqplayer.lnk (Shortcut)
Successfully deleted: C:\Users\AHM\AppData\Roaming\Mozilla\Firefox\Profiles\s71s1nh4.default\user.js (File)
Successfully deleted: C:\Users\AHM\Desktop\qqplayer.lnk (Shortcut)
Successfully deleted: C:\Users\Public\Desktop\flvplayer.lnk (Shortcut)
Successfully deleted: C:\Windows\SysWOW64\findit.xml (File)
Successfully deleted: C:\Program Files (x86)\microleaves (Folder)
Successfully deleted: C:\Program Files (x86)\tencent (Folder)
Successfully deleted: C:\Program Files (x86)\tnt2 (Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\10Q8701U (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\37WRTR4Z (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\590Q5E1A (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7HA37NZR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZUQJFHL (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EYVKL943 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYTVCKEA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MLRRKJFC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q81CGDGF (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SC6CX9QR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBM64FUB (Temporary Internet Files Folder)
Successfully deleted: C:\Users\AHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ULSOON60 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\10Q8701U (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\37WRTR4Z (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\590Q5E1A (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7HA37NZR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZUQJFHL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EYVKL943 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYTVCKEA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MLRRKJFC (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q81CGDGF (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SC6CX9QR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBM64FUB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ULSOON60 (Temporary Internet Files Folder)

Deleted the following from C:\Users\AHM\AppData\Roaming\Mozilla\Firefox\Profiles\s71s1nh4.default\prefs.js
user_pref(browser.newtabpage.pinned, [{\url\:\hxxp://www.yandex.ru/?from=dist_vz&win=222&clid=2256436-002\,\title\:\Яндекс\},{\url\:\hxxps://auto.ru/?from=
user_pref(browser.startup.homepage, hxxp://search.us.com/?guid={42688065-7424-41A2-A497-F6C6181E2684});
user_pref(extensions.eshield.SearchEngineDescription, Use search.us.com for better results);
user_pref(extensions.eshield.SearchEngineIcon, hxxp://search.us.com/serp/img/bullet_www.gif);
user_pref(extensions.eshield.SearchEngineName, Search.us.com);
user_pref(extensions.eshield.SearchEngineUrl, hxxp://search.us.com/serp?guid={42688065-7424-41A2-A497-F6C6181E2684}&k={searchTerms});
user_pref(extensions.sovetnik.yandex.statistics.clid.21, 2256438-002);
user_pref(extensions.tnt.engine.alias, Search.us.com);
user_pref(extensions.tnt.engine.desc, Use search.us.com for better results);
user_pref(extensions.tnt.engine.iconURL, hxxp://search.us.com/serp/img/bullet_www.gif);
user_pref(extensions.tnt.engine.name, Search.us.com);
user_pref(extensions.tnt.engine.url, hxxp://search.us.com/serp?guid={42688065-7424-41A2-A497-F6C6181E2684}&k={searchTerms});
user_pref(extensions.tnt.newtaburl, hxxp://search.us.com/?guid={42688065-7424-41A2-A497-F6C6181E2684});
user_pref(extensions.yasearch@yandex.ru.defender.homepage.protected, hxxp://www.yandex.ru/?win=222&clid=2256428-002);
user_pref(keyword.URL, hxxp://search.us.com/serp?guid={42688065-7424-41A2-A497-F6C6181E2684}&k=);
user_pref(plugin.state.npconduitfirefoxplugin, 0);
user_pref(yasearch.defence.homepage.protected, hxxp://www.yandex.ru/?win=222&clid=2256428-002);



Registry: 16

Successfully deleted: HKLM\Software\Google\Chrome\Extensions\edbmobghbfpobjijpbkahojamahhjhgo (Registry Key)
Successfully deleted: HKLM\Software\Google\Chrome\Extensions\lkemddiljapcmhicklfpcbpfffahfbja (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\PanService (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\SearchAssistant (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchUrl\\Default (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0F691622-A297-4902-8B70-669E5A5C04DD} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page (Registry Value)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page (Registry Value)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl\\Default (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24/08/2017 at 11:49:51,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Publicité


Signaler le contenu de ce document

Publicité