~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.4 (07.09.2017) Operating System: Windows 7 Professional x64 Ran by veli (Administrator) on 25/08/2017 at 12:27:05,44 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 24 Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0RQ89HPN (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7QMKQPQU (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DPSKV2VA (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQJCE8J1 (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O6GLT8BE (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TPI9GRU2 (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UPRAGIH4 (Temporary Internet Files Folder) Successfully deleted: C:\Users\veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V9LOK167 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0RQ89HPN (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7QMKQPQU (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DPSKV2VA (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GQJCE8J1 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O6GLT8BE (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TPI9GRU2 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UPRAGIH4 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V9LOK167 (Temporary Internet Files Folder) Deleted the following from C:\Users\veli\AppData\Roaming\Mozilla\Firefox\Profiles\k5e817ll.default\prefs.js user_pref(browser.search.defaultenginename, Поиск@Mail.Ru); user_pref(browser.search.selectedEngine, Поиск@Mail.Ru); user_pref(extensions.homepage@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B1F173EE2-C61F-4550-95BA-B3EE7C16A7DA%7D&install_id=%7BA538A692-DA35-43D8-B user_pref(extensions.homepage@mail.ru.info, {\gp\:\811036\,\product_id\:\{1F173EE2-C61F-4550-95BA-B3EE7C16A7DA}\,\install_id\:\{A538A692-DA35-43D8-BDAE-5F4100B06 user_pref(extensions.homepage@mail.ru.install_id, {A538A692-DA35-43D8-BDAE-5F4100B06DD5}); user_pref(extensions.homepage@mail.ru.lastHomepage, hxxps://www.google.be/); user_pref(extensions.homepage@mail.ru.lastPageType, 1); user_pref(extensions.homepage@mail.ru.metric_state_go_metric, {\lastDayNumber\:1,\lastDayDate\:\2017-08-20T00:00:00.000Z\}); user_pref(extensions.homepage@mail.ru.metric_state_mrds_metric, {\lastDayNumber\:1,\lastDayDate\:\2017-08-20T00:00:00.000Z\}); user_pref(extensions.homepage@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B1F173EE2-C61F-4550-95BA-B3EE7C16A7D user_pref(extensions.homepage@mail.ru.product_id, {1F173EE2-C61F-4550-95BA-B3EE7C16A7DA}); user_pref(extensions.homepage@mail.ru.product_type, ff_xtnhp); user_pref(extensions.homepage@mail.ru.rfr, 811036); user_pref(extensions.search@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B1F476D6D-BAF8-4A2E-8702-310E4ECDA84A%7D&install_id=%7BA538A692-DA35-43D8-BDA user_pref(extensions.search@mail.ru.info, {\gp\:\811037\,\product_id\:\{1F476D6D-BAF8-4A2E-8702-310E4ECDA84A}\,\install_id\:\{A538A692-DA35-43D8-BDAE-5F4100B06DD user_pref(extensions.search@mail.ru.install_id, {A538A692-DA35-43D8-BDAE-5F4100B06DD5}); user_pref(extensions.search@mail.ru.metric_state_go_metric, {\lastDayNumber\:1,\lastDayDate\:\2017-08-20T00:00:00.000Z\}); user_pref(extensions.search@mail.ru.metric_state_mrds_metric, {\lastDayNumber\:1,\lastDayDate\:\2017-08-20T00:00:00.000Z\}); user_pref(extensions.search@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B1F476D6D-BAF8-4A2E-8702-310E4ECDA84A% user_pref(extensions.search@mail.ru.product_id, {1F476D6D-BAF8-4A2E-8702-310E4ECDA84A}); user_pref(extensions.search@mail.ru.product_type, ff_xtndse); user_pref(extensions.search@mail.ru.rfr, 811037); user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B0904A355-3435-4518-AC2E-5466EB44D235%7D&install_id=% user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.info, {\gp\:\811038\,\product_id\:\{0904A355-3435-4518-AC2E-5466EB44D235}\,\install_id\:\{A538A692-DA user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B0904A355-3435 user_pref(keyword.URL, hxxp://go.mail.ru/distib/ep/?fr=ntg&product_id=%7BA49DE056-AB3B-4C97-9A5E-2991F4A65553%7D&gp=811037); Registry: 1 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 25/08/2017 at 12:28:43,64 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~