~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.5 (04.20.2016) Operating System: Windows (TM) Vista Home Premium x64 Ran by Jason (Administrator) on Sat 04/23/2016 at 14:55:14.10 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 8 Successfully deleted: C:\Users\Jason\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CZF7YAB7 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Jason\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GN8C3IQ4 (Temporary Internet Files Folder) Successfully deleted: C:\Users\Jason\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LNAP909Z (Temporary Internet Files Folder) Successfully deleted: C:\Users\Jason\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VHDQRZNE (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CZF7YAB7 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GN8C3IQ4 (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LNAP909Z (Temporary Internet Files Folder) Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VHDQRZNE (Temporary Internet Files Folder) Deleted the following from C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\netbottb.default\prefs.js user_pref(browser.search.defaultenginename.US, Secure Search); Registry: 5 Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\0178301461419783mcinstcleanup (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL (Registry Value) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 04/23/2016 at 15:01:03.04 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~