~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.4 (07.09.2017) Operating System: Windows 10 Pro x64 Ran by Chris (Administrator) on 17/07/2017 at 18:09:27,03 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 63 Failed to delete: C:\Program Files (x86)\microleaves (Folder) Failed to delete: C:\Program Files (x86)\microleaves\online application (Folder) Successfully deleted: C:\ProgramData\microleaves (Folder) Successfully deleted: C:\ProgramData\thunder network (Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{0EFCD696-5210-4993-9569-2189AEE3C6C1} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{22512D64-193B-49C4-9963-AFD95B9F5C3A} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{2A1785F6-1442-4E8E-8AA0-001B741A0D92} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{2B77D8CE-1386-4ED0-9745-5F692E5BBC66} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{342F93C3-6213-45B8-94DB-3410CFF9F5E3} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{3BE2EC65-E668-4E1B-AF96-221D71AC3A52} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{51BA721A-193A-4F4D-9D6B-8D748C6C553F} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{55B5898E-3D18-47F3-8D51-087EB4B76689} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{7E056397-4F82-4436-B6CC-CC3738859665} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{86F5C7C1-5647-47E3-8767-D5AD9E269456} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{9BFF34BD-4B47-4EFD-9A74-A3FFA84731A8} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{9F9129DB-73AF-4BF2-8EC0-7CDDA0625AB3} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{B3ABDC2C-9692-42B6-99BD-94DCC15633BC} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\{C7AEF0FE-D1AB-474C-8680-A51B8A0A086F} (Empty Folder) Successfully deleted: C:\Users\Chris\AppData\Local\2345explorer (Folder) Successfully deleted: C:\Users\Chris\AppData\Roaming\gplyra (Folder) Successfully deleted: C:\Users\Chris\AppData\Roaming\microleaves (Folder) Successfully deleted: C:\Users\Chris\AppData\Roaming\system healer (Folder) Successfully deleted: C:\Users\Public\Desktop\help.lnk (Shortcut) Successfully deleted: C:\Users\Public\Desktop\launch one system care.lnk (Shortcut) Successfully deleted: C:\Users\Public\Desktop\launch system healer.lnk (Shortcut) Successfully deleted: C:\Users\Public\thunder network (Folder) Successfully deleted: C:\WINDOWS\system32\Tasks\f494ff623cc69bbd1dd97ccac5e45b06 (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\One System Care Monitor (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\One System Care Run Delay (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\One System Care Task (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\One System CarePeriod (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\Online Application V2G1 (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\Online Application V2G2 (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\Online Application V2G3 (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\System Healer Task (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\System HealerPeriod (Task) Successfully deleted: C:\WINDOWS\system32\Tasks\System HealerStartUp (Task) Successfully deleted: C:\WINDOWS\Tasks\One System CarePeriod.job (Task) Successfully deleted: C:\WINDOWS\Tasks\Online Application V2G1.job (Task) Successfully deleted: C:\WINDOWS\Tasks\Online Application V2G2.job (Task) Successfully deleted: C:\WINDOWS\Tasks\Online Application V2G3.job (Task) Successfully deleted: C:\WINDOWS\Tasks\System HealerPeriod.job (Task) Successfully deleted: C:\WINDOWS\Tasks\System HealerStartUp.job (Task) Successfully deleted: C:\Program Files (x86)\onesystemcare (Folder) Successfully deleted: C:\WINDOWS\SysWOW64\sho1B0C.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho1DF9.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho35F4.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho40F3.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho42FC.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho4A41.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho56CC.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho676F.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho6BE1.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho7372.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho7599.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\sho79BC.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoCFBB.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoD7CA.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoDAD5.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoE220.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoF4FF.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoF893.tmp (File) Successfully deleted: C:\WINDOWS\SysWOW64\shoFF7D.tmp (File) Registry: 7 Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\a69b0d02f864acba69fc4e51b8f1aca1 (Registry Key) Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\f494ff623cc69bbd1dd97ccac5e45b06 (Registry Key) Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97510FAC-ED50-46BF-B2A1-25F434BF1030} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97510FAC-ED50-46BF-B2A1-25F434BF1030} (Registry Key) Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 17/07/2017 at 18:13:51,13 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~