~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.1 (02.11.2017) Operating System: Windows 7 Professional x64 Ran by tlinkowski (Administrator) on 2017-03-08 at 11:28:04.70 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 27 Failed to delete: C:\ProgramData\pdfforge (Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\pdfforge (Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Roaming\Mozilla\Firefox\Profiles\75ryxdhg.default\user.js (File) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6438HY9E (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9RBYKSKK (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AZ3L94IT (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K090VD96 (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PA5DNDH9 (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PMRS0U9G (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QRKLVLBY (Temporary Internet Files Folder) Successfully deleted: C:\Users\ArcticNet\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9ZSY718 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6438HY9E (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9RBYKSKK (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AZ3L94IT (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K090VD96 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PA5DNDH9 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PMRS0U9G (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QRKLVLBY (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9ZSY718 (Temporary Internet Files Folder) Deleted the following from C:\Users\ArcticNet\AppData\Roaming\Mozilla\Firefox\Profiles\75ryxdhg.default\prefs.js user_pref(extensions.@safesearchscoutee.sdk.baseURI, resource://safesearchscoutee/); user_pref(extensions.@safesearchscoutee.sdk.domain, safesearchscoutee); user_pref(extensions.@safesearchscoutee.sdk.load.reason, startup); user_pref(extensions.@safesearchscoutee.sdk.rootURI, jar:file:///C:/Users/ArcticNet/AppData/Roaming/Mozilla/Firefox/Profiles/75ryxdhg.default/extensions/@safesearchscoutee. user_pref(extensions.@safesearchscoutee.sdk.version, 0.2.1); user_pref(extensions.xpiState, {\app-profile\:{\@hoxx-vpn\:{\d\:\C:\\\\Users\\\\ArcticNet\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\75ryxdhg.default Registry: 4 Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\fcaeae8a (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 2017-03-08 at 11:29:14.74 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~