~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.2 (03.10.2017) Operating System: Windows 7 Home Premium x64 Ran by Alain (Administrator) on 2017-03-28 at 13:39:26,02 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 19 Successfully deleted: C:\Windows\wininit.ini (File) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\754E1QIN (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BTR0OICE (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JIDYZ5XO (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Users\Alain\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MZXFOWN5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\754E1QIN (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BTR0OICE (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JIDYZ5XO (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MZXFOWN5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\SysWOW64\REN6A94.tmp (File) Successfully deleted: C:\Windows\SysWOW64\RENE30E.tmp (File) Deleted the following from C:\Users\Alain\AppData\Roaming\Mozilla\Firefox\Profiles\0ada32ca.default\prefs.js user_pref(avira.safe_search.installed, [\safesearchplus\]); user_pref(browser.uiCustomization.state, {\placements\:{\PanelUI-contents\:[\edit-controls\,\zoom-controls\,\new-window-button\,\privatebrowsing-button\,\save- user_pref(extensions.safesearch.MP_DISTINCT_ID, \33ac3a921cf4d08cca3be7d158d3a90e5db903f5\); user_pref(extensions.safesearch.install, 1445742145934); user_pref(extensions.safesearch.search_offer_disabled, true); user_pref(extensions.xpiState, {\app-profile\:{\abs@avira.com\:{\d\:\C:\\\\Users\\\\Alain\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\0ada32ca.default Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 2017-03-28 at 13:41:37,61 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~