~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.4 (03.14.2016) Operating System: Microsoft Windows XP x86 Ran by User (Administrator) on Mon 04/11/2016 at 22:06:56.14 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 16 Successfully deleted: C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\play games.lnk (Shortcut) Successfully deleted: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\mq3tdcno.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} (Folder) Successfully deleted: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\mq3tdcno.default\searchplugins\aimsearch.xml (File) Successfully deleted: C:\Documents and Settings\User\Application Data\viewpoint (Folder) Successfully deleted: C:\Program Files\mozilla firefox\defaults\pref\itms.js (File) Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\AKL3CS8D (Temporary Internet Files Folder) Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\J26ID96S (Temporary Internet Files Folder) Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\PS9XEMOQ (Temporary Internet Files Folder) Successfully deleted: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\V0AB5XCQ (Temporary Internet Files Folder) Successfully deleted: C:\Program Files\viewpoint (Folder) Successfully deleted: C:\WINDOWS\prefetch\GOOGLETOOLBARMANAGER_A6282D74-00F3E429.pf (File) Successfully deleted: C:\WINDOWS\prefetch\GOOGLETOOLBARNOTIFIER.EXE-0047A1C5.pf (File) Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\AKL3CS8D (Temporary Internet Files Folder) Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J26ID96S (Temporary Internet Files Folder) Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PS9XEMOQ (Temporary Internet Files Folder) Successfully deleted: C:\WINDOWS\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\V0AB5XCQ (Temporary Internet Files Folder) Deleted the following from C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\mq3tdcno.default\prefs.js user_pref(aol_toolbar.buttons.layout, web_mail_btn;aim_send_IM_btn;aim_this_page_btn;aim_go_away_default_btn;aim_share_feed_btn;video_btn;music_btn;mq_dir_btn;games_btn;tmz user_pref(aol_toolbar.firsttime.showwindow, false); user_pref(aol_toolbar.install.lastName, AIM Toolbar); user_pref(aol_toolbar.install.lastVersion, 5.1.1.0); user_pref(aol_toolbar.metrics.activestampdate, 5); user_pref(aol_toolbar.metrics.activestampmonth, 3); user_pref(aol_toolbar.metrics.activestampyear, 2016); user_pref(aol_toolbar.metrics.originalDate, 23); user_pref(aol_toolbar.metrics.originalHours, 23); user_pref(aol_toolbar.metrics.originalMinutes, 52); user_pref(aol_toolbar.metrics.originalMonth, 4); user_pref(aol_toolbar.metrics.originalSeconds, 39); user_pref(aol_toolbar.metrics.originalYear, 2008); user_pref(aol_toolbar.search.focusnewtab, false); user_pref(aol_toolbar.search.newtab, false); user_pref(aol_toolbar.search.populateoncomplete, false); user_pref(aol_toolbar.search.savehistory, true); user_pref(aol_toolbar.search.searchtype, web); user_pref(aol_toolbar.searchHook.keepSearchSettings, false); user_pref(aol_toolbar.upgrade.showwindow, false); Registry: 6 Successfully deleted: HKLM\Software\MozillaPlugins\@viewpoint.com/vmp (Registry Key) Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\Viewpoint Manager Service (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} (Registry Value) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Mon 04/11/2016 at 22:18:30.87 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~