لله يسعدكم طفيت الانترنت وقفت الحامي مؤقت وطلع لي تقرير
هل الامور على مايرام ؟
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.4.3 (07.11.2015:1)
OS: Windows 8.1 Pro x64
Ran by ê¬ں©ï on Sun 07/12/2015 at 2:33:05.30
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Failed to delete: [Service] isafekrnl
Failed to delete: [Service] isafekrnlboot
Failed to delete: [Service] isafekrnlkit
Failed to delete: [Service] isafekrnlr3
Failed to delete: [Service] isafenetfilter
Failed to delete: [Service] isafeservice
Successfully deleted: [Service] backupstack [Reboot required]
Successfully deleted: [Service] bassvc [Reboot required]
Successfully deleted: [Service] bprotectex [Reboot required]
Successfully deleted: [Service] isafekrnlmon [Reboot required]
Successfully deleted: [Service] pcfapiutil [Reboot required]
Successfully deleted: [Service] sbmntr [Reboot required]
Successfully deleted: [Service] sparksvc [Reboot required]
Successfully deleted: [Service] sparkupdater [Reboot required]
Successfully deleted: [Service] youtubeacceleratorservice [Reboot required]
~~~ Tasks
Successfully deleted: [Task] C:\Windows\system32\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-1
Successfully deleted: [Task] C:\Windows\system32\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-11
Successfully deleted: [Task] C:\Windows\system32\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-2
Successfully deleted: [Task] C:\Windows\system32\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-5
Successfully deleted: [Task] C:\Windows\system32\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-1
Successfully deleted: [Task] C:\Windows\system32\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-11
Successfully deleted: [Task] C:\Windows\system32\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-2
Successfully deleted: [Task] C:\Windows\system32\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-5
Successfully deleted: [Task] C:\Windows\system32\tasks\71634a7f-512d-471b-9785-ca3df8a729a1-5
Successfully deleted: [Task] C:\Windows\system32\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-1
Successfully deleted: [Task] C:\Windows\system32\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-11
Successfully deleted: [Task] C:\Windows\system32\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-2
Successfully deleted: [Task] C:\Windows\system32\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-5
Successfully deleted: [Task] C:\Windows\system32\tasks\compare_for_fun_notification_service
Successfully deleted: [Task] C:\Windows\system32\tasks\compare_for_fun_updating_service
Successfully deleted: [Task] C:\Windows\system32\tasks\globalUpdateUpdateTaskMachineCore
Successfully deleted: [Task] C:\Windows\system32\tasks\globalUpdateUpdateTaskMachineUA
Successfully deleted: [Task] C:\Windows\system32\tasks\ShopperPro
Successfully deleted: [Task] C:\Windows\system32\tasks\ShopperPro
Successfully deleted: [Task] C:\Windows\system32\tasks\ShopperProJSUpd
Successfully deleted: [Task] C:\Windows\system32\tasks\SMupdate1
Successfully deleted: [Task] C:\Windows\system32\tasks\SMupdate1
Successfully deleted: [Task] C:\Windows\system32\tasks\SparkUpdater
Successfully deleted: [Task] C:\Windows\system32\tasks\SPBIW_UpdateTask_Time_323039313135303939312d5737325a786c5a3237344541
Successfully deleted: [Task] C:\Windows\system32\tasks\SPBIW_UpdateTask_Time_323039313135303939312d6c5b5a345b4132452d5a346c
Successfully deleted: [Task] C:\Windows\system32\tasks\SPDriver
Successfully deleted: [Task] C:\Windows\system32\tasks\summer_games_notification_service
Successfully deleted: [Task] C:\Windows\system32\tasks\summer_games_updating_service
Successfully deleted: [Task] C:\Windows\system32\tasks\UNELEVATE_18022
Successfully deleted: [Task] C:\Windows\system32\tasks\YTDownloader
Successfully deleted: [Task] C:\Windows\system32\tasks\YTDownloaderUpd
Successfully deleted: [Task] C:\Windows\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-1.job
Successfully deleted: [Task] C:\Windows\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-11.job
Successfully deleted: [Task] C:\Windows\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-2.job
Successfully deleted: [Task] C:\Windows\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-5.job
Successfully deleted: [Task] C:\Windows\tasks\07342299-ab27-4b82-aca9-0f1418da4caa-5_user.job
Successfully deleted: [Task] C:\Windows\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-1.job
Successfully deleted: [Task] C:\Windows\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-11.job
Successfully deleted: [Task] C:\Windows\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-2.job
Successfully deleted: [Task] C:\Windows\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-5.job
Successfully deleted: [Task] C:\Windows\tasks\35b639cb-ebc3-48af-baab-06a7fa1044e3-5_user.job
Successfully deleted: [Task] C:\Windows\tasks\55bb3565-b1d7-4a6f-9574-e5b0df03743f-3.job
Successfully deleted: [Task] C:\Windows\tasks\71634a7f-512d-471b-9785-ca3df8a729a1-5.job
Successfully deleted: [Task] C:\Windows\tasks\71634a7f-512d-471b-9785-ca3df8a729a1-5_user.job
Successfully deleted: [Task] C:\Windows\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-1.job
Successfully deleted: [Task] C:\Windows\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-11.job
Successfully deleted: [Task] C:\Windows\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-2.job
Successfully deleted: [Task] C:\Windows\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-5.job
Successfully deleted: [Task] C:\Windows\tasks\744bb4e0-bcd4-41b1-92c8-0acee1ce1341-5_user.job
Successfully deleted: [Task] C:\Windows\tasks\compare_for_fun_notification_service.job
Successfully deleted: [Task] C:\Windows\tasks\compare_for_fun_updating_service.job
Successfully deleted: [Task] C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
Successfully deleted: [Task] C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
Successfully deleted: [Task] C:\Windows\tasks\summer_games_notification_service.job
Successfully deleted: [Task] C:\Windows\tasks\summer_games_updating_service.job
~~~ Registry Values
~~~ Registry Keys
Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8D0A551C-28E1-4B1F-993A-A12FA998A12F}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063311.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063311.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063311.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063311.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655325585}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655335511}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666326685}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666336611}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Toolbar.CT1561552
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440544134490}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440544334460}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644324485}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644334411}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655325585}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655335511}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666326685}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666336611}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440544134490}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440544334460}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644324485}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644334411}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611321185}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611331111}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063311.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063311.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063311.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063311.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655325585}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655335511}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666326685}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666336611}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT1561552
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440544134490}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440544334460}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644324485}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644334411}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655325585}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655335511}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666326685}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666336611}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440544134490}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440544334460}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644324485}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644334411}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\iepluginservices
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\windowsmangerprotect
~~~ Files
Successfully deleted: [File] C:\ProgramData\duplicaterecord.js
Successfully deleted: [File] C:\Windows\system32\drivers\isafenetfilter.sys
Successfully deleted: [File] C:\ProgramData\microsoft\windows\start menu\yac.lnk
Successfully deleted: [File] C:\users\public\desktop\yac.lnk
Successfully deleted: [File] C:\Users\ê¬ں©ï\appdata\local\google\chrome\user data\default\local storage\chrome-extension_cigiagpbkapepgklncnajbakkpkopmam_0.localstorage
Successfully deleted: [File] C:\Users\ê¬ں©ï\appdata\local\google\chrome\user data\default\local storage\hxxps_
Successfully deleted: [File] C:\Users\ê¬ں©ï\AppData\Roaming\microsoft\internet explorer\quick launch\hao123.lnk
Successfully deleted: [File] C:\Users\ê¬ں©ï\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mypc backup.lnk
Successfully deleted: [File] C:\Users\ê¬ں©ï\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\torntvdownloader.lnk
Successfully deleted: [File] C:\Users\ê¬ں©ï\desktop\pc app store.lnk
Successfully deleted: [File] C:\Users\ê¬ں©ï\desktop\sync folder.lnk
~~~ Folders
Failed to delete: [Folder] C:\Program Files (x86)\elex-tech
Failed to delete: [Folder] C:\Program Files (x86)\pc faster
Failed to delete: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\elex-tech
Successfully deleted: [Folder] C:\Program Files (x86)\askpartnernetwork
Successfully deleted: [Folder] C:\Program Files (x86)\getprivate
Successfully deleted: [Folder] C:\Program Files (x86)\globalupdate
Successfully deleted: [Folder] C:\Program Files (x86)\mypc backup
Successfully deleted: [Folder] C:\Program Files (x86)\pc app store
Successfully deleted: [Folder] C:\Program Files (x86)\shopperpro
Successfully deleted: [Folder] C:\Program Files (x86)\suptab
Successfully deleted: [Folder] C:\Program Files (x86)\tbccint
Successfully deleted: [Folder] C:\Program Files (x86)\ytdownloader
Successfully deleted: [Folder] C:\Program Files (x86)\zona
Successfully deleted: [Folder] C:\Program Files\Common Files\shopperpro
Successfully deleted: [Folder] C:\Program Files\fileviewpro
Successfully deleted: [Folder] C:\ProgramData\apn
Successfully deleted: [Folder] C:\ProgramData\dsearchlink
Successfully deleted: [Folder] C:\ProgramData\iepluginservices
Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\yac
Successfully deleted: [Folder] C:\ProgramData\pc faster
Successfully deleted: [Folder] C:\ProgramData\shopperpro
Successfully deleted: [Folder] C:\ProgramData\tbccint
Successfully deleted: [Folder] C:\users\public\documents\guid
Successfully deleted: [Folder] C:\users\public\documents\pc faster
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\browserhelper
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\crashrpt
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\fileviewpro
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\globalupdate
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\installer
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\tbccint
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\local\yandex
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\locallow\pricegong
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\locallow\tbccint
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\appdata\locallow\yandex
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\getprivate
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\microsoft\windows\start menu\programs\mypc backup
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\microsoft\windows\start menu\programs\torntv.com
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\microsoft\windows\start menu\programs\yandex
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\opencandy
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\pc app store
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\pc faster
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\solvusoft
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\tencent
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\torntv.com
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\webssearches
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\yandex
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\zona
~~~ FireFox
Successfully deleted: [File] C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\my-prefs.js [Pointed to file]
Successfully deleted: [File] C:\Program Files (x86)\mozilla firefox\my.cfg
Failed to delete: [File] C:\Users\ê¬ں©ï\AppData\Roaming\mozilla\firefox\profiles\v3z69znf.default\searchplugins\v9.xml
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\mozilla\firefox\profiles\v3z69znf.default\extensions\
a338c5448f724f94af2f11@cc4cdd6788a64e7ca7d83cb2cd.com
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\mozilla\firefox\profiles\v3z69znf.default\extensions\
e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com
Successfully deleted: [Folder] C:\Users\ê¬ں©ï\AppData\Roaming\mozilla\firefox\profiles\v3z69znf.default\extensions\staged
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@staging.google.com/globalupdate update;version=10
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@staging.google.com/globalupdate update;version=4
Successfully deleted the following from C:\Users\ê¬ں©ï\AppData\Roaming\mozilla\firefox\profiles\v3z69znf.default\prefs.js
user_pref(browser.search.searchengine.alias, );
user_pref(browser.search.searchengine.iconURL, hxxp://
user_pref(browser.search.searchengine.name, YAC Safe Search );
user_pref(browser.search.searchengine.ref, );
user_pref(browser.search.searchengine.ts, 1436487910);
user_pref(browser.search.searchengine.type, ds);
user_pref(browser.search.searchengine.uid, sandiskxsd5sf2128g1014e_122597402145);
user_pref(browser.search.searchengine.url, hxxp://search.yac.mx/web/?q={searchTerms}&type=ds&from=yac&uid=sandiskxsd5sf2128g1014e_122597402145&ts=1436487910);
user_pref(browser.startup.homepage, hxxp://sa.hao123.com/?tn=fa_pro_hp_01_hao123_sa);
Emptied folder: C:\Users\ê¬ں©ï\AppData\Roaming\mozilla\firefox\profiles\v3z69znf.default\minidumps [4 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bdephonbpjofbmmhhlhiegdokbhhccch
[C:\Users\ê¬ں©ï\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\ê¬ں©ï\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\ê¬ں©ï\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\ê¬ں©ï\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 07/12/2015 at 2:42:31.94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~