~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.6 (04.25.2016) Operating System: Windows 7 Ultimate x86 Ran by 2016 (Administrator) on 22/05/2016 at 0:14:55,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 38 Failed to delete: C:\Users\2016\AppData\Roaming\elex-tech (Folder) Failed to delete: C:\Program Files\elex-tech (Folder) Successfully deleted: C:\Program Files\mozilla firefox\defaults\pref\itms.js (File) Successfully deleted: C:\ProgramData\productdata (Folder) Successfully deleted: C:\Users\2016\AppData\Local\crashrpt (Folder) Successfully deleted: C:\Users\2016\Appdata\LocalLow\tsearch (Folder) Successfully deleted: C:\Users\2016\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js (File) Successfully deleted: C:\Users\2016\AppData\Roaming\Mozilla\Firefox\Profiles\l99aypt0.default\user.js (File) Successfully deleted: C:\Users\2016\AppData\Roaming\productdata (Folder) Successfully deleted: C:\Windows\System32\drivers\isafenetfilter.sys (File) Successfully deleted: C:\Windows\System32\Tasks\SmartDefrag_Startup (Task) Successfully deleted: C:\Windows\System32\Tasks\Uninstaller_SkipUac_2016 (Task) Successfully deleted: C:\Windows\System32\Tasks\Update Service for Torrent Search (Task) Successfully deleted: C:\Windows\System32\Tasks\Update Service for Torrent Search2 (Task) Successfully deleted: C:\Windows\Tasks\Update Service for Torrent Search.job (Task) Successfully deleted: C:\Windows\Tasks\Update Service for Torrent Search2.job (Task) Successfully deleted: C:\Program Files\searchestoyesbnd (Folder) Successfully deleted: C:\Program Files\torrent search (Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\006SHKD0 (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1O6MQN0P (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5OG3GZP3 (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83QLFTF8 (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A2TJE3QR (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CJKQSB3P (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FSGB6EFX (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OGJDE6T9 (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R7JA7GPI (Temporary Internet Files Folder) Successfully deleted: C:\Users\2016\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TOPC4MK0 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\006SHKD0 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1O6MQN0P (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5OG3GZP3 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\83QLFTF8 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A2TJE3QR (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CJKQSB3P (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FSGB6EFX (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OGJDE6T9 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R7JA7GPI (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TOPC4MK0 (Temporary Internet Files Folder) Deleted the following from C:\Users\2016\AppData\Roaming\Mozilla\Firefox\Profiles\l99aypt0.default\prefs.js user_pref(browser.newtab.url, hxxp://www.nicesearches.com?type=hp&ts=1461576804&from=86490425&uid=stm3250318as_9vy3vlprxxxx9vy3vlpr&z=492a1f929a6a79a3e3654begdzeq4gbw1m4q2b user_pref(browser.search.searchengine.alias, ); user_pref(browser.search.searchengine.iconURL, hxxp://www.nicesearches.com/favicon.ico?t=1); user_pref(browser.search.searchengine.name, nice ); user_pref(browser.search.searchengine.ref, ); user_pref(browser.search.searchengine.ts, 1461576804); user_pref(browser.search.searchengine.type, ); user_pref(browser.search.searchengine.uid, stm3250318as_9vy3vlprxxxx9vy3vlpr); user_pref(browser.search.searchengine.url, hxxp://www.nicesearches.com/search.php?type=ds&ts=1461576804&from=86490425&uid=stm3250318as_9vy3vlprxxxx9vy3vlpr&z=492a1f929a6a79 user_pref(browser.startup.homepage, hxxp://www.nicesearches.com?type=hp&ts=1461576804&from=86490425&uid=stm3250318as_9vy3vlprxxxx9vy3vlpr&z=492a1f929a6a79a3e3654begdzeq4gbw user_pref(browser.urlbar.suggest.searches, true); Registry: 10 Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnl (Registry Key) Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlBoot (Registry Key) Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlKit (Registry Key) Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlR3 (Registry Key) Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeNetFilter (Registry Key) Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeService (Registry Key) Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlMon (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6401BC8F-9AD0-430B-BF2C-2A34B0E98466} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{AD42CFE2-C0AD-487E-8224-C2AEF09F4CEB} (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 22/05/2016 at 0:17:53,13 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~