~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Lorraine on Sun 05/25/2014 at 22:05:54.01 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] cltmngsvc Successfully deleted: [Service] cltmngsvc ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\browsersafeguard Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\browserconnection.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\dnsbho.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\esrv.exe Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\pc speed maximizer Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\searchqutoolbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetupv1.exe Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dnsbho.bho Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dnsbho.bho.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\datamngrui_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\datamngrui_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetupv1_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetupv1_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\searchqumediabar_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\searchqumediabar_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\setupdatamngr_searchqu_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\setupdatamngr_searchqu_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskScheduler_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\UpdateTask_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\UpdateTask_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\UpdateTask_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\UpdateTask_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{30040334-E8C6-4D7F-97AA-2423C4CF87CD} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f} ~~~ Files Successfully deleted: [File] "C:\Windows\Tasks\driverupdate startup.job" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess" Successfully deleted: [Folder] "C:\Users\Lorraine\AppData\Roaming\funmoods" Successfully deleted: [Folder] "C:\Users\Lorraine\AppData\Roaming\pc speed maximizer" Successfully deleted: [Folder] "C:\Users\Lorraine\appdata\locallow\datamngr" Successfully deleted: [Folder] "C:\Users\Lorraine\appdata\locallow\searchquband" Successfully deleted: [Folder] "C:\Users\Lorraine\appdata\locallow\searchqutoolbar" Successfully deleted: [Folder] "C:\Program Files (x86)\browsersafeguard" Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro" Failed to delete: [Folder] "C:\Program Files (x86)\pc speed maximizer" Failed to delete: [Folder] "C:\Program Files (x86)\searchprotect" Successfully deleted: [Folder] "C:\Users\Lorraine\documents\optimizer pro" Successfully deleted: [Empty Folder] C:\Users\Lorraine\appdata\local\{81DF3E01-37DA-4011-A171-A7A4621D512F} Successfully deleted: [Empty Folder] C:\Users\Lorraine\appdata\local\{9BEB9FDB-54AC-46B3-86CB-2376D39D8E25} Successfully deleted: [Folder] "C:\ProgramData\ask" Successfully deleted: [Folder] "C:\Program Files (x86)\askpartnernetwork" ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted: [File] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\user.js Successfully deleted: [File] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\searchplugins\askcom.xml Successfully deleted: [File] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\searchplugins\askcomsearch.xml Successfully deleted: [File] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\searchplugins\my-web-search.xml Successfully deleted: [File] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\searchplugins\mysearchdial.xml Successfully deleted: [File] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\searchplugins\search_results.xml Successfully deleted: [Folder] C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\searchqutoolbar Successfully deleted the following from C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\prefs.js user_pref("extensions.crossrider.bic", "144e0448c564df4a3e5d509cae699a2b"); user_pref("extensions.funmoods.SimilarSitesStorage-pid2", "78a338b23cad2d17"); user_pref("extensions.funmoods.admin", false); user_pref("extensions.funmoods.aflt", "axl"); user_pref("extensions.funmoods.brwsrsrc", "ietlbr"); user_pref("extensions.funmoods.cntry", "US"); user_pref("extensions.funmoods.cv", "cv5"); user_pref("extensions.funmoods.dfltLng", "EN"); user_pref("extensions.funmoods.dfltSrch", false); user_pref("extensions.funmoods.dfltlng", "EN"); user_pref("extensions.funmoods.dfltsrch", "false"); user_pref("extensions.funmoods.excTlbr", false); user_pref("extensions.funmoods.fmupdtFirst", false); user_pref("extensions.funmoods.hdrMd5", "30ECFC5BEFE80DE92D29CBAB0DEBCEDA"); user_pref("extensions.funmoods.hmpg", false); user_pref("extensions.funmoods.hrdid", "9accfaea00000000000074e50b97eb19"); user_pref("extensions.funmoods.id", "9accfaea00000000000074e50b97eb19"); user_pref("extensions.funmoods.instlDay", "15402"); user_pref("extensions.funmoods.instlRef", ""); user_pref("extensions.funmoods.instlday", "15402"); user_pref("extensions.funmoods.instlref", ""); user_pref("extensions.funmoods.isDcmntCmplt", false); user_pref("extensions.funmoods.lastVrsnTs", "1.5.11.1621:58:34"); user_pref("extensions.funmoods.logicsMngrDailyReportTime", "30-06-2012"); user_pref("extensions.funmoods.newTab", false); user_pref("extensions.funmoods.newtab", "false"); user_pref("extensions.funmoods.newtaburl", ""); user_pref("extensions.funmoods.noFFXTlbr", false); user_pref("extensions.funmoods.prdct", "funmoods"); user_pref("extensions.funmoods.propectorlck", 98469377); user_pref("extensions.funmoods.prtnrId", "funmoods"); user_pref("extensions.funmoods.prtnrid", "funmoods"); user_pref("extensions.funmoods.sg", "none"); user_pref("extensions.funmoods.smplGrp", "none"); user_pref("extensions.funmoods.smplgrp", "none"); user_pref("extensions.funmoods.srch", ""); user_pref("extensions.funmoods.srchprvdr", ""); user_pref("extensions.funmoods.tlbrId", "base"); user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=axl&q="); user_pref("extensions.funmoods.tlbrid", "base"); user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://start.funmoods.com/results.php?f=3&a=axl&q="); user_pref("extensions.funmoods.vrsn", "1.5.11.16"); user_pref("extensions.funmoods.vrsnTs", "1.5.11.1621:58:34"); user_pref("extensions.funmoods.vrsni", "1.5.11.16"); user_pref("extensions.funmoods.vrsnts", "1.5.11.1621:58:34"); user_pref("extensions.funmoods_i.aflt", "axl"); user_pref("extensions.funmoods_i.dfltLng", ""); user_pref("extensions.funmoods_i.excTlbr", false); user_pref("extensions.funmoods_i.id", "9accfaea00000000000074e50b97eb19"); user_pref("extensions.funmoods_i.instlDay", "15402"); user_pref("extensions.funmoods_i.instlRef", ""); user_pref("extensions.funmoods_i.newTab", false); user_pref("extensions.funmoods_i.prdct", "funmoods"); user_pref("extensions.funmoods_i.prtnrId", "funmoods"); user_pref("extensions.funmoods_i.smplGrp", "none"); user_pref("extensions.funmoods_i.tlbrId", "base"); user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=axl&q="); user_pref("extensions.funmoods_i.vrsn", "1.5.11.16"); user_pref("extensions.funmoods_i.vrsnTs", "1.5.11.1621:58:34"); user_pref("extensions.funmoods_i.vrsni", "1.5.11.16"); user_pref("extensions.mysearchdial.AL", 2); user_pref("extensions.mysearchdial.aflt", "dnldstr_14_12_ff"); user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyBzzzzyEtA0C0F0BtAyCtBzz0F0A0E0AtN0D0Tzu0SzztCtDtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2S user_pref("extensions.mysearchdial.cr", "1275648355"); user_pref("extensions.mysearchdial.dfltLng", ""); user_pref("extensions.mysearchdial.dfltSrch", true); user_pref("extensions.mysearchdial.dnsErr", true); user_pref("extensions.mysearchdial.excTlbr", false); user_pref("extensions.mysearchdial.hmpg", true); user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr_14_12_ff&cd=2XzuyEtN2Y1L1QzuyBzzzzyEtA0C0F0BtAyCtBzz0F0A0E0AtN0D0Tzu0SzztCtDtN1L2Xzu user_pref("extensions.mysearchdial.id", "78843CFB3628FAEA"); user_pref("extensions.mysearchdial.instlDay", "16149"); user_pref("extensions.mysearchdial.instlRef", "140305_a"); user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr_14_12_ff&cd=2XzuyEtN2Y1L1QzuyBzzzzyEtA0C0F0BtAyCtBzz0F0A0E0AtN0D0Tzu0SzztCtDtN1L2XzutB user_pref("extensions.mysearchdial.lastVrsnTs", ""); user_pref("extensions.mysearchdial.newTabUrl", "about:blank"); user_pref("extensions.mysearchdial.prdct", "mysearchdial"); user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); user_pref("extensions.mysearchdial.tlbrId", "base"); user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dnldstr_14_12_ff&cd=2XzuyEtN2Y1L1QzuyBzzzzyEtA0C0F0BtAyCtBzz0F0A0E0AtN0D0Tzu0SzztCtDtN1L user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"); user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"); user_pref("extensions.mysearchdial_i.newTab", false); user_pref("extensions.mysearchdial_i.smplGrp", "none"); user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.09:10:30"); user_pref("extensions.toolbar.mindspark._39Members_.hp.user.defined", true); user_pref("extensions.toolbar.mindspark._39Members_.initialized", true); user_pref("extensions.toolbar.mindspark._39Members_.installation.installDate", "2012052800"); user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerId", "UXxdm011YYus"); user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerSubId", "maps4pc"); user_pref("extensions.toolbar.mindspark._39Members_.installation.success", true); user_pref("extensions.toolbar.mindspark._39Members_.installation.toolbarId", "8D76B767-1552-4DAA-94B9-C757C715A64E"); user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1395331148321"); user_pref("extensions.toolbar.mindspark._39Members_.options.defaultSearch", false); user_pref("extensions.toolbar.mindspark._39Members_.options.homePageEnabled", false); user_pref("extensions.toolbar.mindspark._39Members_.options.tabEnabled", false); user_pref("extensions.toolbar.mindspark._39Members_.weather.location", "85001"); user_pref("extensions.toolbar.mindspark._64Members_.initialized", true); user_pref("extensions.toolbar.mindspark._64Members_.installation.installDate", "2012031923"); user_pref("extensions.toolbar.mindspark._64Members_.installation.partnerId", "XPxdm044YYus"); user_pref("extensions.toolbar.mindspark._64Members_.installation.partnerSubId", "CO7H6P3T9K4CFcMbQgodCU83MA"); user_pref("extensions.toolbar.mindspark._64Members_.installation.success", true); user_pref("extensions.toolbar.mindspark._64Members_.installation.toolbarId", "5C937F04-768E-4526-AA84-4849DCE1344D"); user_pref("extensions.toolbar.mindspark._64Members_.lastActivePing", "1332224255041"); user_pref("extensions.toolbar.mindspark._64Members_.options.defaultSearch", true); user_pref("extensions.toolbar.mindspark._64Members_.options.homePageEnabled", true); user_pref("extensions.toolbar.mindspark._64Members_.options.tabEnabled", false); user_pref("extensions.toolbar.mindspark._64Members_.weather.location", "85001"); user_pref("extensions.toolbar.mindspark.lastInstalled", "mapsgalaxy@mindspark.com"); Emptied folder: C:\Users\Lorraine\AppData\Roaming\mozilla\firefox\profiles\uv4j5qfq.default\minidumps [169 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sun 05/25/2014 at 22:16:56.27 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~