junkware
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Home Premium x64
Ran by Bob Mills on Mon 01/20/2014 at 21:10:25.46
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] cltmngsvc
Successfully deleted: [Service] cltmngsvc
Successfully stopped: [Service] totalrecipesearch_14service
Successfully deleted: [Service] totalrecipesearch_14service
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1073416035-3056625011-4002085185-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\Bob Mills\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{03F3147C-CEA6-4AAE-B0AE-8D8ABE7A8080}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{2502086B-5A46-4D05-8D5B-A1E77AB8BB32}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{396A4E14-83E7-4941-B0D9-B598E1B97197}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{76F3207C-3A0A-461B-B958-5653C5718243}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{895F3DBD-2484-4A14-A0EA-C3252EBB0FF7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{8C4B563E-52A1-4A10-B700-F8BF1CD7B726}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{96B8A0EF-0D9D-4A92-B548-376DB4BBB58B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{9E5C950C-93F2-46B4-A47E-8450FFF4D841}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A4503EC3-1111-4B62-8F46-0D88508F8A7B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A9C524BF-4044-402A-AA00-8C3B3DA86125}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B38FBAED-DED1-4BA6-BA2E-F2515FD49442}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B5EDE79D-B004-47DD-93F9-152B0D145914}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D0690E53-168C-4632-99B2-5700228F760F}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\totalrecipesearch_14
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A3D54852-4B8E-4FA6-ADD4-69C5B2289688}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BF331F4B-EB6D-44E6-ACB1-ED62299B90A0}
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\ammyy"
Successfully deleted: [Folder] "C:\Users\Bob Mills\appdata\local\searchprotect"
Successfully deleted: [Folder] "C:\Users\Bob Mills\appdata\local\totalrecipesearch_14"
Successfully deleted: [Folder] "C:\Users\Bob Mills\appdata\locallow\totalrecipesearch_14"
Successfully deleted: [Folder] "C:\Program Files (x86)\mypc backup"
Successfully deleted: [Folder] "C:\Program Files (x86)\searchprotect"
Successfully deleted: [Folder] "C:\Program Files (x86)\totalrecipesearch_14"
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{04AC901F-34E4-45D3-8DC0-F0797B078E07}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{04BA116C-8DC1-4F3A-B9F1-6BF0251C8655}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{0FCBDC87-40A5-4D17-9DC2-1EC9E7332E04}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{11AA5A47-6C4A-4050-88BD-39DEFC8498F4}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{16328224-BD6E-48A1-BBEE-B80368CD5C8E}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{1AC2547E-2A8B-4D60-BED9-235F94480416}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{1FD24DCA-633F-40F0-A47D-5CBA8AD9D33D}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{23B2FB59-BFAB-4137-8041-EAADB615ACE8}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{28AC2475-EB92-4CAA-9A4B-FD85254747B3}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{2DDB6E98-2055-428B-AE44-23614ABC7967}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{35EB016E-3706-4A59-8DDD-A8CE01106D6B}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{3D011B3B-147A-4E26-A392-9F4A7ED0992C}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{3F6C1E8E-8B66-4675-A733-3A888CD109BC}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{3F7F1F2A-3900-4D12-8D7B-26B3BFC27F42}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{40001946-6CB2-4181-AD8C-7ED2C46F484D}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{42F0CA1A-8408-4204-A5C0-80D7C464EB50}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{430B5836-A8DE-4EE3-A53C-C9E0960C2BB7}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{47AA2777-97F2-4E37-8B5A-F91F25E1B216}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{48972970-DABB-4006-962D-DBFFDE3CFA04}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{4E491B1C-BBF3-4055-A149-1D8D3CE5B625}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{51B4DF2A-5E79-49E4-8B03-F25E8BC43E1F}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{63DC89B1-2FC5-4221-84ED-3AAF24DC4A2D}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{6754A068-4F3B-4F0E-9DEA-B28C966A1FEC}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{692CAA20-8F38-4621-A667-87AB50F9E5B3}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{750DD19C-50F8-449E-AF3A-98E1F9BDD439}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{853F0716-059A-47F6-99BD-6C440C01D2BF}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{85C4DC85-FBAD-438E-B825-BB1B8002F9CF}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{8762F2CE-AABC-4B0D-B82E-A02B5D4E23A7}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{946F952D-4607-46D2-B214-A3A91FFDF37F}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{95E0E6F8-E1F4-4CD2-9EC8-597740208342}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{9842A0C7-B1FD-4354-99D5-31A1386437CA}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{99D2A436-B542-4172-8997-E7CF922AC0BC}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{9A96B6A3-08D8-48CF-BE6A-A1381C8B8A3D}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{A017484E-83DF-4070-A84E-10765197AD6E}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{A72820A6-5DD7-453B-91DB-8EA98B6804E8}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{ACFE2D25-E2E7-4026-AC10-34456C4FA54B}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{C964811A-60AE-48D9-9F7A-9BD61A19BBED}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{DF69350E-1550-49D9-B9AE-D870A5B24E5C}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{E22F5A86-44DA-4BD3-AC2F-28C60A1FA341}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{EB4FF484-EC5E-4F80-A2F2-40DC3E8E3457}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{FC842EB0-8F88-4AD2-9D4E-6FA7E36DBAB4}
Successfully deleted: [Empty Folder] C:\Users\Bob Mills\appdata\local\{FF26A0A5-8BBB-45ED-954B-E21C2D70A626}
~~~ FireFox
Successfully deleted: [File] C:\Users\Bob Mills\AppData\Roaming\mozilla\firefox\profiles\3xsu1gu1.default-1354774513716\searchplugins\my-web-search.xml
Successfully deleted: [Folder] C:\Users\Bob Mills\AppData\Roaming\mozilla\firefox\profiles\3xsu1gu1.default-1354774513716\extensions\
[email protected]
Successfully deleted: [Folder] C:\Users\Bob Mills\AppData\Roaming\mozilla\firefox\profiles\3xsu1gu1.default-1354774513716\extensions\4zffxtbr@videodownloadconverter_4z.com
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\14ffxtbr@totalrecipesearch_14.com
Successfully deleted the following from C:\Users\Bob Mills\AppData\Roaming\mozilla\firefox\profiles\3xsu1gu1.default-1354774513716\prefs.js
user_pref("browser.search.defaultenginename", "Conduit Search");
user_pref("browser.search.selectedEngine", "Conduit Search");
user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3324790&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP7A4854F6-C5B7-474D-B205-8D5B05530827&SSP
user_pref("extensions.mywebsearch.prevDefaultEngine", "Google");
user_pref("extensions.mywebsearch.prevKwdEnabled", true);
user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=");
user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
user_pref("extensions.toolbar.mindspark._14Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=D50B6777-5333-4FAA-9E3B-B93A94F22730&n=780b6213&ptnrS=YKxdm030YYus&
user_pref("extensions.toolbar.mindspark._14Members_.hp.enabled", false);
user_pref("extensions.toolbar.mindspark._14Members_.hp.user.defined", true);
user_pref("extensions.toolbar.mindspark._14Members_.initialized", true);
user_pref("extensions.toolbar.mindspark._14Members_.installation.contextKey", "");
user_pref("extensions.toolbar.mindspark._14Members_.installation.installDate", "2014011923");
user_pref("extensions.toolbar.mindspark._14Members_.installation.partnerId", "YKxdm030YYus");
user_pref("extensions.toolbar.mindspark._14Members_.installation.partnerSubId", "93571");
user_pref("extensions.toolbar.mindspark._14Members_.installation.success", true);
user_pref("extensions.toolbar.mindspark._14Members_.installation.toolbarId", "D50B6777-5333-4FAA-9E3B-B93A94F22730");
user_pref("extensions.toolbar.mindspark._14Members_.lastActivePing", "1390254648362");
user_pref("extensions.toolbar.mindspark._14Members_.options.defaultSearch", true);
user_pref("extensions.toolbar.mindspark._14Members_.options.homePageEnabled", true);
user_pref("extensions.toolbar.mindspark._14Members_.options.keywordEnabled", true);
user_pref("extensions.toolbar.mindspark._14Members_.options.tabEnabled", true);
user_pref("extensions.toolbar.mindspark._14Members_.weather.location", "29572");
user_pref("extensions.toolbar.mindspark.hp.enabled", false);
user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
user_pref("extensions.toolbar.mindspark.lastInstalled", "
[email protected]");
user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=D50B6777-5333-4FAA-9E3B-B93A94F22730&n=780b6213&ind=2014011923&id=YKxdm030YYus&ptnr
user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3324790&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP7A4854F6-C5B7-474D-B205-8D5B055308
Emptied folder: C:\Users\Bob Mills\AppData\Roaming\mozilla\firefox\profiles\3xsu1gu1.default-1354774513716\minidumps [81 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 01/20/2014 at 21:16:43.81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~