~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.5.6 (08.10.2015:1) OS: Windows 10 Pro x64 Ran by Brice on 12/08/2015 at 15:00:18,76 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully deleted: [Service] comyninu [Reboot required] Successfully deleted: [Service] gopibeko [Reboot required] Successfully deleted: [Service] hyverumu [Reboot required] Successfully deleted: [Service] kihiburo [Reboot required] Successfully deleted: [Service] Update Coupon Time [Reboot required] Successfully deleted: [Service] Util Coupon Time [Reboot required] ~~~ Tasks ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\boxore client Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010055 Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mbot_fr_014010055 Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1F91A9A1-01BA-4c81-863D-3BA0751E1419} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{51782D96-19B8-4FD5-9CAF-FD766BF0C5F4} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update Coupon Time Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util Coupon Time ~~~ Files Successfully deleted: [File] C:\Users\Brice\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_engaigpbgdjjmanonjcjkcmomgibneba_0.localstorage Successfully deleted: [File] C:\Users\Brice\Appdata\Local\google\chrome\user data\default\local storage\chrome-extension_engaigpbgdjjmanonjcjkcmomgibneba_0.localstorage-journal Successfully deleted: [File] C:\Users\Brice\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.re-markable00.re-markable.net_0.localstorage Successfully deleted: [File] C:\Users\Brice\Appdata\Local\google\chrome\user data\default\local storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal Successfully deleted: [File] C:\Users\Public\Desktop\play games.lnk Successfully disinfected: [Shortcut] C:\ProgramData\Microsoft\windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ~~~ Folders Failed to delete: [Folder] C:\Users\Brice\Appdata\Local\2ABE0F80-1439071738-81E1-2161-10BF4820143D Successfully deleted: [Folder] C:\Program Files (x86)\boxore Successfully deleted: [Folder] C:\Program Files (x86)\coupon time Successfully deleted: [Folder] C:\ProgramData\tomorrowgames Successfully deleted: [Folder] C:\Users\Brice\Appdata\Local\boxore Successfully deleted: [Folder] C:\Users\Brice\Appdata\Local\stormalerts Successfully deleted: [Folder] C:\Users\Brice\AppData\Roaming\cpuminer Successfully deleted: [Folder] C:\ProgramData\Service1104 Successfully deleted: [Folder] C:\Users\Brice\Appdata\Local\22934 ~~~ Chrome Successfully deleted: [Folder] C:\Users\Brice\Appdata\Local\Google\Chrome\User Data\Default\Extensions\engaigpbgdjjmanonjcjkcmomgibneba [C:\Users\Brice\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\Brice\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: engaigpbgdjjmanonjcjkcmomgibneba [C:\Users\Brice\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\Brice\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [ engaigpbgdjjmanonjcjkcmomgibneba ] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12/08/2015 at 15:02:25,43 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~