~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by ludo et nath (Administrator) on 17/06/2019 at 13:09:26,25
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 17

Successfully deleted: C:\user.js (File)
Successfully deleted: C:\Users\ludo et nath\AppData\Roaming\alawarentertainment (Folder)
Successfully deleted: C:\WINDOWS\hgfs.sys (File)
Successfully deleted: C:\WINDOWS\prleth.sys (File)
Successfully deleted: C:\WINDOWS\wininit.ini (File)
Successfully deleted: C:\Program Files (x86)\GUT6989.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\RENB37E.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\sho252B.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\sho5BBF.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\sho62B1.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoA4CE.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoB76D.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoC460.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoCA1B.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoD127.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoE766.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\shoFC59.tmp (File)

Deleted the following from C:\Users\ludo et nath\AppData\Roaming\Mozilla\Firefox\Profiles\pmfmk0k4.default\prefs.js
user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
user_pref(browser.search.searchengine.ptid, tugs);
user_pref(browser.search.searchengine.uid, TOSHIBAXMK6465GSX_31A4F583SXX31A4F583S);



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17/06/2019 at 13:16:28,05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~