~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Professional x64
Ran by jrmnr on Mon 12/09/2013 at 15:26:26.87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
TBHostSupport REG_SZ "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\jrmnr\AppData\Local\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\lyricsing
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4AC4A837-8B8C-4016-A36F-3CBF083DC03C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CAFC2AF4-2AB7-4E4E-BBAC-DFFBB7497D3B}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\jrmnr\appdata\local\cre"
Successfully deleted: [Folder] "C:\ai_recyclebin"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Successfully deleted: [File] C:\Users\jrmnr\AppData\Roaming\mozilla\firefox\profiles\nei0cks9.default\searchplugins\privitize.xml
Successfully deleted the following from C:\Users\jrmnr\AppData\Roaming\mozilla\firefox\profiles\nei0cks9.default\prefs.js
user_pref("extensions.defaulttab.installdate", 1376679256);
user_pref("extensions.defaulttab.lastUsed", 1376680430);
user_pref("extensions.privitize.admin", false);
user_pref("extensions.privitize.aflt", "5");
user_pref("extensions.privitize.appId", "{301966DF-A84B-4255-AAB9-574B5CE237E4}");
user_pref("extensions.privitize.autoRvrt", "false");
user_pref("extensions.privitize.cntry", "US");
user_pref("extensions.privitize.dfltLng", "");
user_pref("extensions.privitize.dfltSrch", true);
user_pref("extensions.privitize.dnsErr", true);
user_pref("extensions.privitize.dpkLst", "1169821598,3855095921,302281469,2400444324,3654782829,1334533236,3874294282,3866767559,3224935090,3754950497,1766448872,2740670312,10
user_pref("extensions.privitize.excTlbr", false);
user_pref("extensions.privitize.ffxUnstlRst", false);
user_pref("extensions.privitize.hdrMd5", "1476812F6451A3CD82E34AA7F087FB4C");
user_pref("extensions.privitize.hmpg", true);
user_pref("extensions.privitize.hmpgUrl", "hxxp://searchou.com/?id=80ca95690000000000000024e82a637b&affilt=5");
user_pref("extensions.privitize.id", "80ca95690000000000000024e82a637b");
user_pref("extensions.privitize.instlDay", "15858");
user_pref("extensions.privitize.instlRef", "");
user_pref("extensions.privitize.kw_url", "hxxp://searchou.com/?q={searchTerms}&id=80ca95690000000000000024e82a637b&affilt=5");
user_pref("extensions.privitize.lastVrsnTs", "1.8.21.614:13:17");
user_pref("extensions.privitize.newTab", true);
user_pref("extensions.privitize.newTabUrl", "hxxp://searchou.com/?id=80ca95690000000000000024e82a637b&affilt=5");
user_pref("extensions.privitize.prdct", "privitize");
user_pref("extensions.privitize.prtnrId", "privitize");
user_pref("extensions.privitize.rvrt", "false");
user_pref("extensions.privitize.sg", "none");
user_pref("extensions.privitize.smplGrp", "none");
user_pref("extensions.privitize.tlbrId", "base");
user_pref("extensions.privitize.tlbrSrchUrl", "hxxp://searchou.com/?id=80ca95690000000000000024e82a637b&affilt=5&q=");
user_pref("extensions.privitize.vrsn", "1.8.21.6");
user_pref("extensions.privitize.vrsnTs", "1.8.21.614:13:17");
user_pref("extensions.privitize.vrsni", "1.8.21.6");
Emptied folder: C:\Users\jrmnr\AppData\Roaming\mozilla\firefox\profiles\nei0cks9.default\minidumps [362 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 12/09/2013 at 15:35:19.63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~