~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.6.4 (09.28.2015:1) OS: Windows 7 Home Premium x64 Ran by yu on 12/10/2015 at 10:55:06,66 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully deleted: [Service] pcsuucdrv [Reboot required] ~~~ Tasks ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update FindRight ~~~ Files Successfully deleted: [File] C:\Users\yu\Appdata\Local\nsh1A95.tmp Successfully deleted: [File] C:\Users\yu\Appdata\Local\nsi2D95.tmp Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.audienceinsights.net_0.localstorage Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.audienceinsights.net_0.localstorage-journal Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.boostsaves.com_0.localstorage Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.boostsaves.com_0.localstorage-journal Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.publikeco00.publikeco.com_0.localstorage Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.publikeco00.publikeco.com_0.localstorage-journal Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxps_static.boostsaves.com_0.localstorage Successfully deleted: [File] C:\Users\yu\Appdata\Local\google\chrome\user data\default\local storage\hxxps_static.boostsaves.com_0.localstorage-journal Successfully deleted: [File] C:\Windows\SysWOW64\sho196E.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho1E4E.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho1EDE.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho222E.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho3778.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho3C1C.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho4104.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho4ACB.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho4DB6.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho5474.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho548F.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho582E.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho5C0A.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho6236.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho6326.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho6C6.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho716B.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho7994.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho81FF.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho8AC5.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho8B3C.tmp Successfully deleted: [File] C:\Windows\SysWOW64\sho97E5.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoA0B.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoA24E.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoA2AB.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoB505.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoB5DE.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoC63B.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoC9FB.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoCADE.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoDCA3.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoED16.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoF878.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoFC5F.tmp Successfully deleted: [File] C:\Windows\SysWOW64\shoFF19.tmp ~~~ Folders Successfully deleted: [Folder] C:\ProgramData\productdata Successfully deleted: [Folder] C:\Users\yu\Appdata\Local\ggempire Successfully deleted: [Folder] C:\Users\yu\AppData\Roaming\productdata Successfully deleted: [Folder] C:\Users\yu\AppData\Roaming\wyupdate au Successfully deleted: [Folder] C:\Users\yu\Start Menu\Programs\browser manager Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin ~~~ Chrome Successfully deleted: [Folder] C:\Users\yu\Appdata\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [C:\Users\yu\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\yu\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: gpdjojdkbbmdfjfahjcgigfpmkopogic [C:\Users\yu\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\yu\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [ gebbadcnkcgcfgpbmcdleckpejgopimf, gpdjojdkbbmdfjfahjcgigfpmkopogic ] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12/10/2015 at 11:00:28,28 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~