~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.7 (07.03.2016) Operating System: Windows 8.1 Pro with Media Center x64 Ran by patrick (Administrator) on lun. 22/ao–t/2016 at 19:29:39,31 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 11 Successfully deleted: C:\ProgramData\reviversoft (Folder) Successfully deleted: C:\Users\patrick\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\help.lnk (Shortcut) Successfully deleted: C:\Users\patrick\AppData\Roaming\Mozilla\Firefox\Profiles\c3j41lc7.default-1422720943753\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\custombuttons\google.com_blog_search.xml (File) Successfully deleted: C:\Users\patrick\AppData\Roaming\Mozilla\Firefox\Profiles\gsrwkb3n.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\custombuttons\google.com_blog_search.xml (File) Successfully deleted: C:\WINDOWS\prefetch\GOOGLETOOLBARMANAGER_F3B2E431-EA321F90.pf (File) Successfully deleted: C:\WINDOWS\prefetch\GOOGLETOOLBARNOTIFIER.EXE-969E73DB.pf (File) Successfully deleted: C:\WINDOWS\prefetch\GOOGLETOOLBARUSER_32.EXE-66EEE4D2.pf (File) Successfully deleted: C:\WINDOWS\SysWOW64\REN4DE1.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\RENBF48.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\RENC0A0.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\RENF71B.tmp (File) Registry: 2 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{85A60A59-D3D8-468F-B598-FB4393789EF4} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on lun. 22/ao–t/2016 at 19:32:54,22 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~