Metallica

Moderators
  • Content count

    1,744
  • Joined

  • Last visited

About Metallica

  • Rank
    Master of PUPs
  • Birthday 05/19/1963

Contact Methods

  • ICQ
    0

Profile Information

  • Location
    Netherlands

Recent Profile Visitors

153,393 profile views
  1. What is SystemBoosterPro? The Malwarebytes research team has determined that SystemBoosterPro is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with SystemBoosterPro? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, startmenu, and on your desktop: and see this type of warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: How did SystemBoosterPro get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove SystemBoosterPro? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of SystemBoosterPro? No, Malwarebytes removes SystemBoosterPro completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the SystemBoosterPro installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\SystemBoosterPro\SystemBoosterPro.exe C:\Users\{username}\Desktop\SystemBoosterPro.lnk C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro C:\Program Files (x86)\SystemBoosterPro SystemBoosterPro (HKLM-x32\...\SystemBoosterPro) (Version: 38.1 - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\SystemBoosterPro Adds the file SystemBoosterPro.exe"="8/31/2016 3:37 PM, 5059072 bytes, A Adds the file uninst.exe"="2/17/2017 8:52 AM, 63459 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro Adds the file SystemBoosterPro.lnk"="2/17/2017 8:52 AM, 1139 bytes, A Adds the file Uninstall.lnk"="2/17/2017 8:52 AM, 872 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file SystemBoosterPro.lnk"="2/17/2017 8:52 AM, 1103 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SystemBoosterPro.exe] "(Default)"="REG_SZ", "C:\Program Files (x86)\SystemBoosterPro\SystemBoosterPro.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SystemBoosterPro] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\SystemBoosterPro\SystemBoosterPro.exe" "DisplayName"="REG_SZ", "SystemBoosterPro" "DisplayVersion"="REG_SZ", "38.1" "NSIS:Language"="REG_SZ", "1033" "Publisher"="REG_SZ", "" "UninstallString"="REG_SZ", "C:\Program Files (x86)\SystemBoosterPro\uninst.exe" "URLInfoAbout"="REG_SZ", "" [HKEY_CURRENT_USER\Software\SystemBoosterPro] "Activated"="REG_DWORD", 0 "AutoRun"="REG_DWORD", 0 "BackupDir"="REG_SZ", "Backup\" "CloseToTray"="REG_DWORD", 1 "ErrFixed"="REG_DWORD", 0 "ErrFound"="REG_DWORD", 0 "IDLang"="REG_DWORD", 0 "InstallID"="REG_SZ", "8DF622D99DD30679E0A274C4045DFFA8" "LastFixDatei"="REG_BINARY, .... "LastScanDatei"="REG_BINARY, .... "Partner"="REG_SZ", "" "PhSuppNum"="REG_SZ", "" "ProxyHost"="REG_SZ", "" "ProxyLogin"="REG_SZ", "" "ProxyPassw"="REG_SZ", "" "ProxyPort"="REG_SZ", "" "SerialNum"="REG_SZ", "" "Subtrack"="REG_SZ", "" "UseProxy"="REG_DWORD", 0 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/17/17 Scan Time: 9:04 AM Logfile: mbamSystemBoosterPro.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1284 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360483 Time Elapsed: 2 min, 5 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SYSTEMBOOSTERPRO\SYSTEMBOOSTERPRO.EXE, Quarantined, [1890], [369662],1.0.1284 Module: 1 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SYSTEMBOOSTERPRO\SYSTEMBOOSTERPRO.EXE, Quarantined, [1890], [369662],1.0.1284 Registry Key: 1 PUP.Optional.oTweak, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SystemBoosterPro, Delete-on-Reboot, [1890], [334912],1.0.1284 Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SystemBoosterPro, Delete-on-Reboot, [1890], [334912],1.0.1284 PUP.Optional.oTweak, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SYSTEMBOOSTERPRO, Delete-on-Reboot, [1890], [369661],1.0.1284 File: 6 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SYSTEMBOOSTERPRO\SYSTEMBOOSTERPRO.EXE, Delete-on-Reboot, [1890], [369662],1.0.1284 PUP.Optional.oTweak, C:\Program Files (x86)\SystemBoosterPro\uninst.exe, Delete-on-Reboot, [1890], [334912],1.0.1284 PUP.Optional.oTweak, C:\USERS\{username}\DESKTOP\SYSTEMBOOSTERPRO.LNK, Delete-on-Reboot, [1890], [334910],1.0.1284 PUP.Optional.oTweak, C:\USERS\{username}\DESKTOP\SYSTEMBOOSTERPRO.EXE, Delete-on-Reboot, [1890], [369662],1.0.1284 PUP.Optional.oTweak, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro\SystemBoosterPro.lnk, Delete-on-Reboot, [1890], [369661],1.0.1284 PUP.Optional.oTweak, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro\Uninstall.lnk, Delete-on-Reboot, [1890], [369661],1.0.1284 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  2. What is SoftPlanet Update Manager? The Malwarebytes research team has determined that SoftPlanet Update Manager is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by SoftPlanet Update Manager? You may see these warnings during install: this icon on your desktop and in your startmenu: You may see this entry in your list of installed programs: and this entry in your Scheduled Tasks: This is the main screen of the program: How did SoftPlanet Update Manager get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove SoftPlanet Update Manager? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of SoftPlanet Update Manager? No, Malwarebytes removes SoftPlanet Update Manager completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the SoftPlanet Update Manager adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks some of the connections the installer tries to make: Technical details for experts Possible signs in FRST logs: (Secure Download Ltd.) C:\Program Files (x86)\SoftPlanet Software Assistant\spassist.exe C:\Windows\System32\Tasks\SoftPlanet Software Assistant C:\Users\{username}\AppData\Local\SoftPlanet C:\Users\Public\Desktop\SoftPlanet Software Assistant.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPlanet Software Assistant C:\Program Files (x86)\SoftPlanet Software Assistant SoftPlanet Software Assistant version 1.19 (HKLM-x32\...\{C87BD92A-FDDE-42C5-84F7-5159BEC08A01}_is1) (Version: 1.19 - Secure Download Ltd.) Task: {EC535BD8-953E-4497-BCE7-71C730BD2C6D} - System32\Tasks\SoftPlanet Software Assistant => C:\Program Files (x86)\SoftPlanet Software Assistant\spassist.exe [2013-12-09] (Secure Download Ltd.) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\SoftPlanet Software Assistant Adds the file spassist.exe"="12/9/2013 6:12 PM, 4511072 bytes, A Adds the file unins000.dat"="2/16/2017 8:41 AM, 9422 bytes, A Adds the file unins000.exe"="2/16/2017 8:41 AM, 718497 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPlanet Software Assistant Adds the file SoftPlanet Software Assistant.lnk"="2/16/2017 8:41 AM, 1172 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant Adds the file latest.xml"="2/16/2017 8:41 AM, 2480 bytes, A Adds the file lr.xml"="2/16/2017 8:41 AM, 1201 bytes, A Adds the file prev.xml"="2/16/2017 8:41 AM, 2480 bytes, A Adds the file recom.xml"="2/16/2017 8:41 AM, 1250 bytes, A Adds the file table.html"="2/16/2017 8:41 AM, 16345 bytes, A Adds the file template.html"="2/16/2017 8:41 AM, 13847 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file SoftPlanet Software Assistant.lnk"="2/16/2017 8:41 AM, 1154 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file SoftPlanet Software Assistant"="2/16/2017 8:41 AM, 3320 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C87BD92A-FDDE-42C5-84F7-5159BEC08A01}_is1] "DisplayName"="REG_SZ", "SoftPlanet Software Assistant version 1.19" "DisplayVersion"="REG_SZ", "1.19" "EstimatedSize"="REG_DWORD", 5095 "HelpLink"="REG_SZ", "http://www.softplanet.com/" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\SoftPlanet Software Assistant" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "SoftPlanet Software Assistant" "Inno Setup: Language"="REG_SZ", "english" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon" "Inno Setup: Setup Version"="REG_SZ", "5.5.4 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170216" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\SoftPlanet Software Assistant\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 19 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Secure Download Ltd." "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.softplanet.com/" "URLUpdateInfo"="REG_SZ", "http://www.softplanet.com/" [HKEY_CURRENT_USER\Software\SoftPlanet\Software Assistant] "CID"="REG_SZ", "FFC59ABF-9501-44E4-8A8B-DAA6A431C9D1" "FirstRun"="REG_SZ", "No" "InstallDate"="REG_SZ", "2/16/2017 8:41:20 AM" "LastFetch"="REG_SZ", "2/16/2017 8:41:20 AM" "LastNotify"="REG_SZ", "1/17/2017 8:41:20 AM" "ref"="REG_SZ", "sa" "Version"="REG_SZ", "1.19" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/16/17 Scan Time: 8:47 AM Logfile: mbamSoftplanet.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1274 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360268 Time Elapsed: 1 min, 32 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SOFTPLANET SOFTWARE ASSISTANT\SPASSIST.EXE, Quarantined, [2862], [181161],1.0.1274 Module: 1 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SOFTPLANET SOFTWARE ASSISTANT\SPASSIST.EXE, Quarantined, [2862], [181161],1.0.1274 Registry Key: 4 PUP.Optional.SecureDownload, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C87BD92A-FDDE-42C5-84F7-5159BEC08A01}_is1, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SoftPlanet Software Assistant, Delete-on-Reboot, [2862], [370771],1.0.1274 PUP.Optional.SecureDownload, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EC535BD8-953E-4497-BCE7-71C730BD2C6D}, Delete-on-Reboot, [2862], [370772],1.0.1274 PUP.Optional.SecureDownload, HKCU\SOFTWARE\SOFTPLANET\Software Assistant, Delete-on-Reboot, [2862], [251994],1.0.1274 Registry Value: 1 PUP.Optional.SecureDownload, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EC535BD8-953E-4497-BCE7-71C730BD2C6D}|PATH, Delete-on-Reboot, [2862], [370772],1.0.1274 Data Stream: 0 (No malicious items detected) Folder: 4 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SoftPlanet Software Assistant, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SOFTPLANET SOFTWARE ASSISTANT, Delete-on-Reboot, [2862], [181176],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\USERS\{username}\APPDATA\LOCAL\SOFTPLANET, Delete-on-Reboot, [2862], [251888],1.0.1274 File: 12 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SOFTPLANET SOFTWARE ASSISTANT\SPASSIST.EXE, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.dat, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.exe, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\USERS\PUBLIC\DESKTOP\SOFTPLANET SOFTWARE ASSISTANT.LNK, Delete-on-Reboot, [2862], [251887],1.0.1274 PUP.Optional.SecureDownload, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPlanet Software Assistant\SoftPlanet Software Assistant.lnk, Delete-on-Reboot, [2862], [181176],1.0.1274 PUP.Optional.SecureDownload, C:\USERS\{username}\APPDATA\LOCAL\SOFTPLANET\SOFTWARE ASSISTANT\TABLE.HTML, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\latest.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\lr.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\prev.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\recom.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\template.html, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\WINDOWS\SYSTEM32\TASKS\SOFTPLANET SOFTWARE ASSISTANT, Delete-on-Reboot, [2862], [251889],1.0.1274 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  3. What is Your Instant Email? The Malwarebytes research team has determined that Your Instant Email is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. Your Instant Email is a member of the Spigot family as described in the blogpost Spigot browser hijackers. How do I know if my computer is affected by Your Instant Email? You may see this Firefox extension: this new default search provider in Internet Explorer: and this entry in your list of installed software: You may also see these warnings during install: and this new startpage in the affected browser(s): How did Your Instant Email get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove Your Instant Email? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Your Instant Email? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the Your Instant Email entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Your Instant Email hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yourinstantemail.com/?source=tt&uid={uid1}&uc=20170215&ap=&i_id=email__1.30 SearchScopes: HKCU -> DefaultScope {3FE479AA-6079-437A-913F-2FB27F48B31A} URL = hxxp://search.yourinstantemail.com/s?source=tt-bb8&uid={uid1}&uc=20170215&ap=&i_id=email__1.30&query={searchTerms} SearchScopes: HKCU -> {3FE479AA-6079-437A-913F-2FB27F48B31A} URL = hxxp://search.yourinstantemail.com/s?source=tt-bb8&uid={uid1}&uc=20170215&ap=&i_id=email__1.30&query={searchTerms} FF Homepage: hxxp://search.yourinstantemail.com?uid={uid2}&uc=20170215&ap=&source=tt&page=homepage&implementation_id=email_4.0.12 FF Extension: Email - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Email.xpi [2017-02-15] C:\Users\{username}\AppData\Roaming\SpigotSettings Your Instant Email (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.2.0.5 - Spigot, Inc.) <==== ATTENTION Most relevant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @Email.xpi"="2/15/2017 8:51 AM, 21706 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Email\simple-storage Adds the file store.json"="2/15/2017 8:55 AM, 315 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SpigotSettings Adds the file Uninstall.exe"="2/15/2017 8:50 AM, 267616 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.yourinstantemail.com/?source=tt&uid={uid1}&uc=20170215&ap=&i_id=email__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{3FE479AA-6079-437A-913F-2FB27F48B31A}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3FE479AA-6079-437A-913F-2FB27F48B31A}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.yourinstantemail.com/s?source=tt-bb8&uid={uid1}&uc=20170215&ap=&i_id=email__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "Your Instant Email" "DisplayVersion"="REG_SZ", "2.2.0.5" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\SpigotSettings\" "Publisher"="REG_SZ", "Spigot, Inc." "UninstallHomepage"="REG_SZ", "http://search.yourinstantemail.com/?source=tt&uid={uid1}&uc=20170215&ap=&i_id=email__1.30" "UninstallImpression"="REG_SZ", "http://imp.yourinstantemail.com/impression.do?source=tt&sub_id=20170215&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=&user_id={uid1}&implementation_id=email__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\SpigotSettings\Uninstall.exe" /uninstall" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/15/17 Scan Time: 9:08 AM Logfile: mbamYourInstantEmail.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1266 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360113 Time Elapsed: 1 min, 30 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [810], [300859],1.0.1266 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3FE479AA-6079-437A-913F-2FB27F48B31A}, Delete-on-Reboot, [2353], [368913],1.0.1266 Registry Value: 1 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3FE479AA-6079-437A-913F-2FB27F48B31A}|URL, Delete-on-Reboot, [2353], [368913],1.0.1266 Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.MyEmailXP, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Email\simple-storage, Delete-on-Reboot, [1843], [335005],1.0.1266 PUP.Optional.MyEmailXP, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@EMAIL, Delete-on-Reboot, [1843], [335005],1.0.1266 File: 4 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\SPIGOTSETTINGS\UNINSTALL.EXE, Delete-on-Reboot, [810], [300859],1.0.1266 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [2353], [361537],1.0.1266 PUP.Optional.MyEmailXP, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Email\simple-storage\store.json, Delete-on-Reboot, [1843], [335005],1.0.1266 PUP.Optional.MyEmailXP, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@EMAIL.XPI, Delete-on-Reboot, [1843], [335030],1.0.1266 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  4. What is OneSystemCare? The Malwarebytes research team has determined that OneSystemCare is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with OneSystemCare? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar and on your desktop: and you may see this type of warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: and these tasks in your Task Scheduler: How did OneSystemCare get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was installed by another PUP. How do I remove OneSystemCare? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of OneSystemCare? No, Malwarebytes removes OneSystemCare completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the OneSystemCare installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\OneSystemCare\SystemConsole.exe () C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe C:\Windows\System32\Tasks\{057E7947-780B-0E0B-7D11-0E0D0B0C110F} C:\Windows\System32\Tasks\One System Care Task C:\Windows\System32\Tasks\One System Care Run Delay C:\Windows\System32\Tasks\One System Care Monitor C:\Windows\System32\Tasks\One System CarePeriod C:\Windows\Tasks\One System CarePeriod.job C:\ProgramData\2a2276f9-20a1-1 C:\ProgramData\2a2276f9-0b93-0 C:\Users\{username}\AppData\Roaming\One System Care C:\Program Files (x86)\OneSystemCare C:\Users\Public\Desktop\Launch One System Care.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care One System Care (HKLM-x32\...\OneSystemCare) (Version: 4.4.0.3 - OneSystemCare) <==== ATTENTION Task: {11FD0FCC-787D-4FF1-B466-D5659CEA6633} - System32\Tasks\One System CarePeriod => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2016-12-26] () <==== ATTENTION Task: {4D89F1C3-36A8-4429-8FC1-0B263DA7E332} - System32\Tasks\One System Care Monitor => C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe [2016-12-26] () <==== ATTENTION Task: {668D20B7-A868-4B90-AF03-489B802C5E0A} - System32\Tasks\One System Care Run Delay => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2016-12-26] () <==== ATTENTION Task: {6CAB0476-77E0-4D8A-9D0A-D4FC8118D982} - System32\Tasks\{057E7947-780B-0E0B-7D11-0E0D0B0C110F} => powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand OwAgADsAIAA7ADsAOwA7ADsAIAAgACAAIAA7ACAAIAA7ADsAIAAgACAAIAA7ACAAIAA7ACAAIAAgADsAJABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUA (the data entry has 10184 more characters). Task: {F04F6E92-DB17-4ED4-8BB7-2F698ABDAD9E} - System32\Tasks\One System Care Task => C:\Program Files (x86)\OneSystemCare\SystemConsole.exe [2016-12-26] () <==== ATTENTION Task: C:\Windows\Tasks\One System CarePeriod.job => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe <==== ATTENTION Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\OneSystemCare Adds the file cancel.bmp"="12/26/2016 10:27 AM, 20360 bytes, A Adds the file CleanupConsole.exe"="12/26/2016 10:35 AM, 2238656 bytes, A Adds the file OneSystemCare.exe"="12/26/2016 10:35 AM, 4678336 bytes, A Adds the file OneSystemCare.ini"="2/14/2017 9:16 AM, 843 bytes, A Adds the file osc.ico"="12/26/2016 10:27 AM, 34494 bytes, A Adds the file SystemConsole.exe"="12/26/2016 10:35 AM, 952512 bytes, A Adds the file uninstall.bmp"="12/26/2016 10:27 AM, 802196 bytes, A Adds the file Uninstaller.exe"="12/26/2016 10:35 AM, 779592 bytes, A Adds the folder C:\ProgramData\2a2276f9-0b93-0 Adds the file BITA281.tmp"="2/14/2017 9:15 AM, 0 bytes, HA Adds the folder C:\ProgramData\2a2276f9-20a1-1 Adds the file BITA119.tmp"="2/14/2017 9:15 AM, 0 bytes, HA Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care Adds the file Launch One System Care.lnk"="2/14/2017 9:14 AM, 1085 bytes, A Adds the file One System Care on the Web.url"="2/14/2017 9:14 AM, 54 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\One System Care\Languages In the existing folder C:\Users\Public\Desktop Adds the file Launch One System Care.lnk"="2/14/2017 9:14 AM, 1067 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file {057E7947-780B-0E0B-7D11-0E0D0B0C110F}"="2/14/2017 9:15 AM, 24696 bytes, A Adds the file One System Care Monitor"="2/14/2017 9:15 AM, 3268 bytes, A Adds the file One System Care Run Delay"="2/14/2017 9:15 AM, 3334 bytes, A Adds the file One System Care Task"="2/14/2017 9:15 AM, 3576 bytes, A Adds the file One System CarePeriod"="2/14/2017 9:15 AM, 2868 bytes, A In the existing folder C:\Windows\Tasks Adds the file One System CarePeriod.job"="2/14/2017 9:15 AM, 284 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures] "One System CarePeriod.job"="REG_BINARY, ................................ "One System CarePeriod.job.fp"="REG_DWORD", 669890839 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564] "0"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\3f14500d2a2276f9] "0"="REG_SZ", "Gw7UvYUTOHrejuVCAbVnctRCA2_vYd0wOoR-9d0iFHgcEV9RLwjKpMaAmMD_Cpi7qG4AIW9C8rrPZqPWiNpB2sMhoV9tWTTGftHbE8TPworo7NXZNsRsDcOYyz1u1G-YSBmBOmYnTettG3d55Xa-L0P6u_Z9YwytjJueDW19fDt1IkrxJvFximWXBB3B6YEro2U9glLikIylxSztmvR7rsu3JVo9K8LHS2kVtOmoPG4UJNcHU24m26NvkQHOTB3mCf47TENy7HPHYW5jB-DQjd_ejg2SoE3OTmybhVgX8RzJtR6gPFGss4Ou49-kFmGf8-NG9ECRE9tXL3YopR7rAootnhjjyRB07bL4Cx2vpfthFN3FkqyqOoyhxBx4ITdg4Fv6OinyKXaDQ0UsA_AbQ0-LN7gR7ne6JvBU6yhds7_bfGfUgl75xDNY7N4OHZsT7LUbKzFKhK1JKa9V5RCnPHJdWaoXKr7nB83hZA4bHxT99rut19sNPbU3lauo33ZFoctaZGx_PixnpNhKqNzpCX--zuyuvV6yz71Jx2_6uQYNzJIOYSQwbZWfkm9rn3Bhb0OrZbYJKoQVKsUMCDIU4rT9llrJieaMgZJoqwGhu6glFkbUlLTH5oYmx9FlbfB6EGYaMRuGSHFxmqu6BybH7CG1JqWMfLquTNAUm9fTLyr6URfTEg0jzv_jNqn3XeTbweN2aRF69AZcY-fhJXtDMHw1kKXNp4SrPvxvJdz2GJRdWt5-qKo1lnh4XQW14v0_ZdV4g6Uq03pX6e5IUheci2_P1CctuOn5h63LrRheqTcvoBvW0mOKIPYmjpT60FFHueWm0Q64_P_pEjoxoZG3ReYE7y81tNef1lh7h6WUxBSnR5v5hRf01z1hj61v-OvUBEC7-oUmsHwO5XTq7OhdArtYXKTHku4yS2iO12oVRetE2o0DfxIokdbS2LCgABaRoZfNEj3TlaWA15P1kmYHbeXt_KpdRk_kn1mL0bjx7JeyaiE55edPUKTyUBmywbi6ZRy2MrvSTHmA5FFz0d8NHLlNczVQ4PvSYqD3KKYbH9FMoc8hnlu-3i3He_okW5yCijcIpfLqVhjJy92pFWBA06LG2hbtOysxRQbJwOtWmgyda7udOa3wFU8dqs3EuNcF_ZZWguvZlpAje7gbTgTFiX-ZRmKrmmI2lBb2exZ0aCjDSg2chOBKpA5zhZ1bKaXZVMRWjFzBZC48xjbLlwsgr-4FodNzQCpVeQMi5udvH5Nj74mIELUtwFakAE41fZ-ME8jnz77gJbwYpuT_QW_bo7nz1CzKGoMaux6xevphDUjaYslVKI1mPMSYes5h2jmoaSS7f99oPwd2-KudaATla6fo0S1AdoM58cwW4Xkr5mQxYs63mJlvkZUKMozlHaMMVHGK8vkqf-o10XB8u-xuxBOZPndY4f08mZviBQCwm_TjG2oaXRMuVJ4SFBNhPvuDiBkGjbYXmg9H_JG5kKhga5XDTMO1bQYOtsIXBgno2iwVyiaM3hRTELqDz1VcvFftSh0Gjy026t_GYCEnUsmkf0g79ejpOsBFF47TimDgjAi6WyvO4JVpPfTFTE68m_RReguPf5gikd2XCljvfeW2--vMUNZfroXopgSSzYVAgjcukkPdjjdqrrtDHl1VxFIKW7Nu3RfuG4bTlN9QGNL8sDP31kP3II4JZ1t8N7mfjtWieAPJQ0GnOnvqZwjOBl0sFIh5tmb3aFgD5RMQmpxA3RkMHmIPE_dB0D_Y4qu4Vpw-81vAL2aEQWqfsTS3Hhnhxs2mrf3iVQmBI_GS4foqx6cgZZFCGguKQr-RimRwCikEdMmSTjlhTUpj0ox2H4VCUQxyfbsI9Q7MhzYwhyRJthfWF-tBNTvP_7Q4D8rBtOY61if8V-xBklsK1zBJHuOSgRxxP9ohXqH390TKfknNWxyu5jPuex10rSRNfdwhipY6T225Jqnocv1zEXuzIppGTI1vjhANSTbnZrl4GMSYFS0AEptpaQX0tkA0HzHB-UC3mT6E_2pDZf0EYspXA6LFRJkwRFh2jtykhsGAdYIgArMOVYirsNQV1BCyV7oBnqnJm-Dn07_a8oy37Rj1Zh30CPtFuMLFwiIY1NXPBpy0Hpq1632J5EoYw4dCemUXFujWaRgSh_fKyb0yuulXHjqe3CL_vROlNU6O-WxGRU8TgRX94DfSG5NKbS9c0bWb8YKLS2hd_w1z4or-T659dd2EofrAM7N2ulXUc0E5Ix2i4R3UvkDrRMdFl5nfbB-ZpYfXnBoWN_tKlfg5iPdF2SsAnaWEhDdvTD9ppQcqIuTGGV27Zz194XNN4EVY-G4ODLf8bUAmwcptcxIDUFAB6SXXs9NsYu5A998REl9tS7_FMiTwjuR_3W1OG4R5-Zzip_5u2X38mhFt2eiOWMPPqLAFrWLpaCWLEUF1mhiQBbtB1PNJN-cFFHzn0aDoRG295kEZguU2-M3VjuY7srSLbl7cHQ9BNAzVKk4pO-l_RN-8sp1SAeDlpeYtSqoKerx-vx2hxjWy-KhkAVYNDxxGVN_eGJBSuVCrse6YioYPz_RJxNWsIbeg7lcXJzkr61JCZpXqzzLFE--XnhlyZrG4fc2fk4EjURZ97G4scXwgsHKZlpbYx0K_BTX6E6-BOeohPwYo2p-2AFXTKu_xV49I-x3f1e7MRdV0l8yo55dcJHcMc-Tx5863IQpq8vINxdeMXQoj1qLMpWtNbCZ5z6u62uT6K8ePYpNqYjBOdWMK9-MuV6r52txv8QDDvOh-MzbIn0d5UTfszJhi5GRMHDQiN1xw2UnoC8jH1cvJSeWAI2mFJ4ZnUQ5maShr_y2vk-xfLlgkl6WpTENKJpSdLkTkUTXqmInk65OnWOO6V54G5wZAtdeE_xgzLfgWnDJyTUV0_EijSvrjUEf3DpxUjxZnOXXSWqdDGOVEr_h7lAzvBD0iPhDR4hYh6OPraPV4FqsCSMD2pK7TGgOTV_jauBrFqphjA9ZaQIc6HlFsb5GU75wUGJug_gaxaLLU8AoAccVKJjw00ir9QppposAM8VnRtMtD9Ns6LTWhKeLOWA5zOylSi_1sgFkBvUjcdEFAKDXn2wRz" "1"="REG_SZ", "lOTnlgOfnqUskMunF-Jfg1R86ulQ" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\OneSystemCare\Uninstaller.exe" "DisplayName"="REG_SZ", "One System Care" "DisplayVersion"="REG_SZ", "4.4.0.3" "Publisher"="REG_SZ", "OneSystemCare" "rn"="REG_DWORD", 0 "UninstallString"="REG_SZ", "C:\Program Files (x86)\OneSystemCare\Uninstaller.exe" "URLInfoAbout"="REG_SZ", "http://www.onesystemcare.com" [HKEY_CURRENT_USER\Software\One System Care] "Configuration"="REG_BINARY, .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................. "InstLang"="REG_SZ", "1033" "PurchaseLink"="REG_SZ", "1" "ScanAtStartup"="REG_DWORD", 0 "ScheduleScan"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/14/17 Scan Time: 9:28 AM Logfile: mbamOneSystemCare.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1257 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360070 Time Elapsed: 3 min, 11 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 3 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\SYSTEMCONSOLE.EXE, Quarantined, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRA~2\ONESYS~1\SYSTEM~1.EXE, Quarantined, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.EXE, Quarantined, [537], [311034],1.0.1257 Module: 1 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.EXE, Quarantined, [537], [311034],1.0.1257 Registry Key: 12 Adware.OptimizerEliteMax, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OneSystemCare, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, HKCU\SOFTWARE\One System Care, Delete-on-Reboot, [578], [311038],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{11FD0FCC-787D-4FF1-B466-D5659CEA6633}, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4D89F1C3-36A8-4429-8FC1-0B263DA7E332}, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{668D20B7-A868-4B90-AF03-489B802C5E0A}, Delete-on-Reboot, [578], [258294],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F04F6E92-DB17-4ED4-8BB7-2F698ABDAD9E}, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f, Delete-on-Reboot, [578], [336950],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f, Delete-on-Reboot, [578], [336950],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System Care Monitor, Delete-on-Reboot, [578], [241385],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System Care Run Delay, Delete-on-Reboot, [578], [241385],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System Care Task, Delete-on-Reboot, [578], [241385],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System CarePeriod, Delete-on-Reboot, [578], [241385],1.0.1257 Registry Value: 10 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|DhcpNameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{EDB0D6D8-B1F7-496F-A023-44DF7155F1CD}|NameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{EDB0D6D8-B1F7-496F-A023-44DF7155F1CD}|DhcpNameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{11FD0FCC-787D-4FF1-B466-D5659CEA6633}|PATH, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4D89F1C3-36A8-4429-8FC1-0B263DA7E332}|PATH, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{668D20B7-A868-4B90-AF03-489B802C5E0A}|PATH, Delete-on-Reboot, [578], [258294],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F04F6E92-DB17-4ED4-8BB7-2F698ABDAD9E}|PATH, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f|DESCRIPTION, Delete-on-Reboot, [578], [336950],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f|DESCRIPTION, Delete-on-Reboot, [578], [336950],1.0.1257 Data Stream: 0 (No malicious items detected) Folder: 7 PUP.Optional.DNSUnlocker.ACMB2, C:\PROGRAMDATA\2a2276f9-0b93-0, Delete-on-Reboot, [46], [182288],1.0.1257 PUP.Optional.DNSUnlocker.ACMB2, C:\PROGRAMDATA\2a2276f9-20a1-1, Delete-on-Reboot, [46], [182288],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\WL, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\USERS\{username}\APPDATA\ROAMING\One System Care, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAM FILES (X86)\ONESYSTEMCARE, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ONE SYSTEM CARE, Delete-on-Reboot, [578], [241379],1.0.1257 File: 35 PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\2a2276f9-0b93-0\BITA281.tmp, Delete-on-Reboot, [46], [182288],1.0.1257 PUP.Optional.DNSUnlocker.ACMB2, C:\WINDOWS\SYSTEM32\TASKS\{057E7947-780B-0E0B-7D11-0E0D0B0C110F}, Delete-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\2a2276f9-20a1-1\BITA119.tmp, Delete-on-Reboot, [46], [182288],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\SYSTEMCONSOLE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRA~2\ONESYS~1\SYSTEM~1.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Danish.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Dutch.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\English.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\French.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\German.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Italian.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Norwegian.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Parameters.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Portuguese.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Spanish.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Swedish.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\tmpLang.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\CallBanner.png, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\FinishedScan.png, Delete-on-Reboot, [578], [178764],1.0.1257 Adware.OptimizerEliteMax, C:\USERS\{username}\DESKTOP\ONESYSTEMCARE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, C:\USERS\PUBLIC\DESKTOP\LAUNCH ONE SYSTEM CARE.LNK, Delete-on-Reboot, [578], [241377],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\UNINSTALLER.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\CLEANUPCONSOLE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.INI, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\Program Files (x86)\OneSystemCare\cancel.bmp, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\Program Files (x86)\OneSystemCare\osc.ico, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\Program Files (x86)\OneSystemCare\uninstall.bmp, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\TASKS\ONE SYSTEM CAREPERIOD.JOB, Delete-on-Reboot, [578], [241382],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System Care Monitor, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System Care Run Delay, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System Care Task, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System CarePeriod, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ONE SYSTEM CARE\LAUNCH ONE SYSTEM CARE.LNK, Delete-on-Reboot, [578], [241379],1.0.1257 PUP.Optional.OneSystemCare, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care\One System Care on the Web.url, Delete-on-Reboot, [578], [241379],1.0.1257 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  5. No problem. If it happens again, you can add an exclusion for the exploit detection if you are sure it's something you want to alllow. Under Settings select the Exclusions tab > Add Exclusion > select Exclude a Previously Detected Exploit > Next > select the exploit you want to exclude and click OK.
  6. What is GetCouponsFast? The Malwarebytes research team has determined that GetCouponsFast is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. GetCouponsFast is a Mindspark/Ask toolbar now known as IAC Applications. How do I know if my computer is affected by GetCouponsFast? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browsers: How did GetCouponsFast get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove GetCouponsFast? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of GetCouponsFast? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the GetCouponsFast entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the GetCouponsFast hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/getcouponsfast/ttab02/index.html?n={n1}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/getcouponsfast/ttab02/index.html?coId={coid2}&subId&ln=en&n={n2}&p2={p22}&si FF Extension: GetCouponsFast - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_jhMembers_@www.getcouponsfast.com [2017-02-13] CHR Extension: (GetCouponsFast) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj [2017-02-13] C:\Users\{username}\AppData\Local\GetCouponsFastTooltab GetCouponsFast Internet Explorer Homepage and New Tab (HKCU\...\GetCouponsFastTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION Significant changes made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\GetCouponsFastTooltab Adds the file TooltabExtension.dll"="10/19/2016 6:15 PM, 266864 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0 Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iadmakoacmnjmcacmhlcjcameijgcopj Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\iadmakoacmnjmcacmhlcjcameijgcopj Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com Adds the file bootstrap.js"="2/13/2017 9:44 AM, 24730 bytes, A Adds the file chrome.manifest"="2/13/2017 9:44 AM, 135 bytes, A Adds the file chrome.manifest.restartless"="2/13/2017 9:44 AM, 135 bytes, A Adds the file install.rdf"="2/13/2017 9:44 AM, 1441 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome Adds the file ffxtbr.jar"="2/13/2017 9:44 AM, 344204 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF Adds the file manifest.mf"="2/13/2017 9:44 AM, 680 bytes, A Adds the file mozilla.rsa"="2/13/2017 9:44 AM, 4192 bytes, A Adds the file mozilla.sf"="2/13/2017 9:44 AM, 121 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\getcouponsfast_jh Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\GetCouponsFast] "Start Page"="REG_SZ", "http://hp.myway.com/getcouponsfast/ttab02/index.html?n=C05BAFB&p2=^CQC^yyyyyy^TTAB02^nl&ptb={ptb1}&coid={coid1}" "UnInstallSurveyUrl"="REG_SZ", "http://@{downloadDomain}.dl.myway.com/uninstall.jhtml?surveyUrl=http%3A%2F%2Fwww.research.net" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://hp.myway.com/getcouponsfast/ttab02/index.html?n={n1}&ptb={ptb1}&coid={coid1}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GetCouponsFastTooltab Uninstall Internet Explorer] "DisplayName"="REG_SZ", "GetCouponsFast Internet Explorer Homepage and New Tab" "HelpLink"="REG_SZ", "http://support.mindspark.com/" "Publisher"="REG_SZ", "Mindspark Interactive Network, Inc." "UninstallString"="REG_SZ", "Rundll32.exe "C:\Users\{username}\AppData\Local\GetCouponsFastTooltab\TooltabExtension.dll" U uninstall:GetCouponsFast" "URLInfoAbout"="REG_SZ", "http://support.mindspark.com/" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/13/17 Scan Time: 9:55 AM Logfile: mbamGetCouponsFast.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1249 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359800 Time Elapsed: 2 min, 5 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GETCOUPONSFASTTOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [340], [301125],1.0.1249 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GetCouponsFastTooltab Uninstall Internet Explorer, Delete-on-Reboot, [340], [301125],1.0.1249 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GetCouponsFastTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [340], [352442],1.0.1249 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [340], [293497],1.0.1249 Data Stream: 0 (No malicious items detected) Folder: 89 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GetCouponsFastTooltab, Delete-on-Reboot, [1048], [356944],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\abstractbutton\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\thirdparty\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\uninstall\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\weather\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\generic\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\alert\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\link\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\abstractbutton, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\rss\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\images, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\radioWrapper, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\thirdparty, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\foreground, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\uninstall, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\generic, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\weather, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\alert, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\link, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\rss, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\adapter, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\_metadata, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IADMAKOACMNJMCACMHLCJCAMEIJGCOPJ, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_JHMEMBERS_@WWW.GETCOUPONSFAST.COM, Delete-on-Reboot, [340], [302304],1.0.1249 File: 287 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GETCOUPONSFASTTOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [340], [301125],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [356946],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [340], [240306],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [340], [240306],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.myway.com_0.localstorage, Delete-on-Reboot, [340], [240305],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [340], [240305],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IADMAKOACMNJMCACMHLCJCAMEIJGCOPJ\12.202.10.39297_0\MANIFEST.JSON, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\README.txt, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\bs.30.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\common.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\dynamic.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\enableDetect.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\eventListening.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\global.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\list-interaction.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\messageEventListener.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\navRedirector.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\paramReplacer.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\PartnerId.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\set.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\unifiedLogging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\foreground\button.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\background\searchBox.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\css\supertab.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\html\supertab.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\reporting.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\supertab.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\__utm.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\arrowSprite.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon128.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon16.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon19disabled.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon19on.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon48.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012495.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012507.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012508.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012559.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012576.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\down_arrow.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\magnifying_glass.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\search_button.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\tvf_icon_guide.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\tvf_logo.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\wrench.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\newTabInitialize.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\chromeStorage.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\chromeUtils.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\companionSWUtils.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\exeManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\exeManagerNMD.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\exePackageManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\focusManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\globalBlacklistManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\messaging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\mutation_summary-min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\mutation_summary.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\newTabInfo.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\options.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\readLocalStorage.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\reservespaceifenabled.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\scriptInjector.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\searchContext.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\settingsOverrides.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\toolbarCookieParser.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\toolbarPreinit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\URILoaderContentScript.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\webTooltabAPI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\Widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\widgetFactory.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\widgetWindowManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\cache.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\ce.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\debug.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\ss.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\activePing.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\buttonLogger.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\competitorDnsList.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\console.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\httpTransport.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\HttpURL.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\internationalSearch.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\rsvp-latest.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\testHttpTransport.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\unifiedLogger.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\unifiedLogging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\universalConsole.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\utils.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\_metadata\computed_hashes.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\_metadata\verified_contents.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\bg.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\buildVars, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\buildVars.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\companionSW.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\config.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\contentScript.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\contentScript.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\debug.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\debug.jade, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\extension_toolbar_api.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\initWidgetWindow.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\newTabContentScript.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\options.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent2.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent2.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spentJ.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spentK.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spentK.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\startup.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\stub.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\stubby.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\superFrame.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbar.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbar.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbarUI.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbarUI.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbarUI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\url.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\webtooltab.cs.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_JHMEMBERS_@WWW.GETCOUPONSFAST.COM\INSTALL.RDF, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome\ffxtbr.jar, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF\manifest.mf, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF\mozilla.rsa, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF\mozilla.sf, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\bootstrap.js, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome.manifest, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome.manifest.restartless, Delete-on-Reboot, [340], [302304],1.0.1249 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  7. Hi reidsci, Did I understand correct that this is something you created yourself? I do understand why our Anti-Exploit module would block that, since it is unexpected and malware-like behavior. Another question for you: did this start immediately after you upgraded from Malwarebytes version 2 to 3?
  8. What is Trotux? The Malwarebytes research team has determined that Trotux is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by Trotux? You may see this entry in your list of installed programs: this type of Scheduled Tasks (random names): these changed search settings in the affected browsers: and this startpage: You may also notice a fake Firefox profiles as described here: GsearchFinder hijackers add extra Firefox profile How did Trotux get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove Trotux? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Trotux? No, Malwarebytes removes Trotux completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the Trotux adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks the origin of the installer: Technical details for experts Possible signs in FRST logs: HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 ShellExecuteHooks: - {58AF6728-ECD0-11E6-BFEA-64006A5CFC23} - C:\Users\{username}\AppData\Roaming\Climofabech\Gipphsaweght.dll [146944 2017-02-10] () FF NewTab: hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp FF DefaultSearchEngine: trotux FF SelectedSearchEngine: trotux FF Homepage: hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\mhc384j1.default\searchplugins\4qy3hwj4.xml [2017-02-10] CHR HomePage: ChromeDefaultData -> hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp" CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=sp CHR DefaultSearchKeyword: ChromeDefaultData -> trotux R2 Stuhoph; C:\Program Files (x86)\Grerhient\cgghtdeberkmnt.dll [149504 2017-02-10] () [File not signed] C:\WINDOWS\System32\Tasks\Drecaward Client C:\WINDOWS\System32\Tasks\Niiseclajuent C:\Users\{username}\AppData\Roaming\Climofabech C:\Users\{username}\AppData\Local\Ckekiry C:\Program Files (x86)\Drecaward Client C:\Program Files (x86)\Grerhient trotux - Uninstall (HKLM-x32\...\{8230A356-F879-4B82-AF04-032A578692C0}) (Version: - ) Task: {1B965CA1-35D0-4C1D-B92A-FE8677ECA306} - System32\Tasks\Drecaward Client => C:\Program Files (x86)\Grerhient\dozuent.exe [2017-02-10] (Glarysoft Ltd) Task: {D766AA6E-86D0-4DF0-BCC5-BCACB56D5FE6} - System32\Tasks\Niiseclajuent => /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&amp;v=2017210 /q () C:\Users\{username}\AppData\Roaming\Climofabech\Gipphsaweght.dll () C:\Program Files (x86)\Drecaward Client\local64spl.dll () c:\program files (x86)\grerhient\cgghtdeberkmnt.dll Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Drecaward Client Adds the file local64spl.dll"="2/10/2017 11:34 AM, 309760 bytes, A Adds the file local64spl.dll.ini"="2/10/2017 11:34 AM, 20 bytes, A Adds the folder C:\Program Files (x86)\Grerhient Adds the file cgghtdeberkmnt.dll"="2/10/2017 11:34 AM, 149504 bytes, A Adds the file CrashReport.dll"="2/10/2017 11:34 AM, 121344 bytes, A Adds the file dozuent.exe"="2/10/2017 11:34 AM, 1026216 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Drecaward Client"="2/10/2017 11:34 AM, 6082 bytes, A Adds the file Niiseclajuent"="2/10/2017 11:34 AM, 3780 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\0B3C7EB2C2FC8FF89E16DF9C80C0327A] "(Default)"="REG_SZ"", "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}" "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}"="REG_BINARY, ............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}\InProcServer32] "(Default)"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Climofabech\Gipphsaweght.dll" "ThreadingModel"="REG_SZ"", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft] "help"="REG_SZ"", "http://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}"="REG_SZ"", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] "EnableShellExecuteHooks"="REG_DWORD"", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Mvasephermuy] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\{84416237-6490-494D-9AD6-4994DD978971}] "chd"="REG_SZ"", "C:\Users\{username}\AppData\Local\Ckekiry" "ffd"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Profiles\Grerkaghgerdiing.default" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\0B3C7EB2C2FC8FF89E16DF9C80C0327A] "(Default)"="REG_SZ"", "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}" "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}"="REG_BINARY, ............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ckafoyanerqeent] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\dozuent.exe] "(Default)"="REG_SZ"", "2017210" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8230A356-F879-4B82-AF04-032A578692C0}] "DisplayName"="REG_SZ"", "trotux - Uninstall" "UninstallString"="REG_SZ"", "C:\Program Files (x86)\Grerhient\dozuent.exe ef869dec-feed-46e1-a4fe-427f47f37b77 "/k={8230A356-F879-4B82-AF04-032A578692C0}"" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost] "Stuhoph"="REG_MULTI_SZ, "Stuhoph" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Suvosh] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\trotuxSoftware\trotuxhp] "oem"="REG_SZ"", "wsy1" "Time"="REG_DWORD"", 1486722892 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\xvtrzx] "day"="REG_SZ"", "20170210" "upday"="REG_SZ"", "20170210" [HKEY_LOCAL_MACHINE\SOFTWARE\xvtrzx] "day"="REG_SZ"", "20170210" "upday"="REG_SZ"", "20170210" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers] "order" = REG_MULTI_SZ, "LanMan Print Services Internet Print Provider 4qy3hwj4 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\4qy3hwj4] "DisplayName"="REG_SZ"", "zvgbuz" "Name"="REG_SZ"", "C:\Program Files (x86)\Drecaward Client\local64spl.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Stuhoph] "Description"="REG_SZ"", "Provides global functions for other parts of Chislereuction." "DisplayName"="REG_SZ"", "Stuhoph" "ErrorControl"="REG_DWORD"", 1 "FailureActions"="REG_BINARY, ...................... "ImagePath"="REG_EXPAND_SZ, "%SystemRoot%\system32\svchost.exe -k Stuhoph" "ObjectName"="REG_SZ"", "LocalSystem" "Start"="REG_DWORD"", 2 "Type"="REG_DWORD"", 272 "WOW64"="REG_DWORD"", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Stuhoph\Parameters] "ServiceDll"="REG_EXPAND_SZ, "C:\Program Files (x86)\Grerhient\cgghtdeberkmnt.dll" "ServiceMain"="REG_SZ"", "Clanochphoderk" [HKEY_USERS\.DEFAULT\Software\xvtrzx] "day"="REG_SZ"", "20170210" "upday"="REG_SZ"", "20170210" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/10/17 Scan Time: 12:14 PM Logfile: mbamTrotux.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.50 Update Package Version: 1.0.1225 License: Premium -System Information- OS: Windows 10 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 384454 Time Elapsed: 9 min, 6 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 4 Adware.Elex.SHHKRST, C:\USERS\{username}\APPDATA\ROAMING\CLIMOFABECH\GIPPHSAWEGHT.DLL, Quarantined, [1238], [362727],1.0.1225 Adware.Elex.SHHKRST, C:\USERS\{username}\APPDATA\ROAMING\CLIMOFABECH\GIPPHSAWEGHT.DLL, Quarantined, [1238], [362727],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\GRERHIENT\CGGHTDEBERKMNT.DLL, Quarantined, [2145], [366971],1.0.1225 Adware.Elex.Generic, C:\Program Files (x86)\Drecaward Client\local64spl.dll, Quarantined, [2145], [358303],1.0.1225 Registry Key: 5 Adware.Elex.SHHKRST, HKLM\SOFTWARE\CLASSES\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}, Delete-on-Reboot, [1238], [362727],1.0.1225 Adware.Elex.SHHKRST, HKLM\SOFTWARE\CLASSES\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}\InprocServer32, Delete-on-Reboot, [1238], [362727],1.0.1225 PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\trotuxSoftware, Delete-on-Reboot, [418], [182848],1.0.1225 Adware.Sasquor.SPL, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\PRINT\PROVIDERS\4qy3hwj4, Delete-on-Reboot, [2086], [339986],1.0.1225 PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{8230A356-F879-4B82-AF04-032A578692C0}, Delete-on-Reboot, [418], [182846],1.0.1225 Registry Value: 5 Adware.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS|{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}, Delete-on-Reboot, [1238], [362727],1.0.1225 Adware.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS, Delete-on-Reboot, [1238], [-1],0.0.0 Adware.Elex.SHHKRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS, Delete-on-Reboot, [1238], [-1],0.0.0 Adware.Sasquor.SPL, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\PRINT\PROVIDERS\4qy3hwj4|NAME, Delete-on-Reboot, [2086], [339986],1.0.1225 PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{8230A356-F879-4B82-AF04-032A578692C0}|DISPLAYNAME, Delete-on-Reboot, [418], [182846],1.0.1225 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 4 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\USERS\{username}\APPDATA\ROAMING\Mozilla\Firefox\naweriweentcofise, Delete-on-Reboot, [2773], [363173],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\DRECAWARD CLIENT, Delete-on-Reboot, [2145], [358303],1.0.1225 File: 23 Adware.Elex.SHHKRST, C:\USERS\{username}\APPDATA\ROAMING\CLIMOFABECH\GIPPHSAWEGHT.DLL, Delete-on-Reboot, [1238], [362727],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\prefs.js, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\profiles.ini, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\search.json, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\search.json.mozlz4, Delete-on-Reboot, [2773], [363173],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\GRERHIENT\CGGHTDEBERKMNT.DLL, Delete-on-Reboot, [2145], [366971],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\SEARCHPLUGINS\4QY3HWJ4.XML, Delete-on-Reboot, [418], [324483],1.0.1225 PUP.Optional.Elex, C:\USERS\{username}\DESKTOP\WSY1_AY.EXE, Delete-on-Reboot, [15], [315776],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\DRECAWARD CLIENT\LOCAL64SPL.DLL.INI, Delete-on-Reboot, [2145], [358303],1.0.1225 Adware.Elex.Generic, C:\Program Files (x86)\Drecaward Client\local64spl.dll, Delete-on-Reboot, [2145], [358303],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\SEARCHPLUGINS\4QY3HWJ4.XML, Delete-on-Reboot, [418], [302745],1.0.1225 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  9. What is winsvc.vbs? The Malwarebytes research team has determined that winsvc.vbs is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by winsvc.vbs? You may see this entry in your startup folder: How did winsvc.vbs get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove winsvc.vbs? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of winsvc.vbs? No, Malwarebytes removes winsvc.vbs completely. If you return to a temporary profile after the first reboot, simply reboot once more. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the winsvc.vbs adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks the source of the installer: Technical details for experts Possible signs in FRST logs: (Node.js) C:\Users\{username}\AppData\Roaming\win-svc\bin\winsvc.exe Startup: C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winsvc.vbs [2016-12-21] () C:\Users\{username}\AppData\Roaming\win-svc The most significant alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Adds the file winsvc.vbs"="12/21/2016 10:43 AM, 189 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\win-svc Adds the file cmd.bat"="1/25/2017 2:34 PM, 322 bytes, A Adds the file reg.reg"="1/25/2017 2:24 PM, 150 bytes, A Adds the file run.vbs"="12/21/2016 11:01 AM, 87 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\win-svc\bin Adds the folder C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast Adds the file index.js"="12/20/2016 9:02 AM, 1352 bytes, A Adds the file LICENSE"="12/20/2016 9:02 AM, 1115 bytes, A Adds the file package.json"="12/20/2016 9:02 AM, 2538 bytes, A Adds the file README.md"="12/20/2016 9:02 AM, 2992 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GenericCo\GenericKey] "GenericName"="REG_SZ", "GenericVal1" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/9/17 Scan Time: 1:07 PM Logfile: mbamcli.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1217 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359430 Time Elapsed: 1 min, 17 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\WIN-SVC\BIN\WINSVC.EXE, Quarantined, [1033], [360756],1.0.1217 Module: 1 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\WIN-SVC\BIN\WINSVC.EXE, Quarantined, [1033], [360756],1.0.1217 Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 95 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\fixtures, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release\obj.target, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\obj.target, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc\wg-meetings, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\example, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test\server, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\example, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\example, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\build, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\bin, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\.bin, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\win-svc, Delete-on-Reboot, [1033], [360756],1.0.1217 File: 440 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\WIN-SVC\BIN\WINSVC.EXE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\asyncworker.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\buffers.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\callback.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\converters.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\errors.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\maybe_types.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\methods.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\new.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\node_misc.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\object_wrappers.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\persistent.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\scopes.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\script.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\string_bytes.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\v8_internals.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\v8_misc.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools\1to2.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\CHANGELOG.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\include_dirs.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\LICENSE.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_callbacks.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_callbacks_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_callbacks_pre_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_converters.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_converters_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_converters_pre_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_implementation_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_implementation_pre_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_maybe_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_maybe_pre_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_new.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_object_wrap.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_persistent_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_persistent_pre_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_string_bytes.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_typedarray_contents.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_weak.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\.bin\uuid, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\test\after-test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\LICENCE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\test\slice-buffer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\test\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\lib\base64-arraybuffer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\LICENSE-MIT, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\example.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\test\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\.zuul.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\test\inherit.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\lib\util.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\float.patch, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\.jshintrc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\CHANGELOG.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\debug.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\node.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\polling-jsonp.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\polling-xhr.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\polling.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\websocket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\socket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transport.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\xmlhttprequest.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\engine.io.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib\keys.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\fixtures\big.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\inherits.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\inherits_browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\build\build.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\lib\json3.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\lib\json3.min.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\LICENSE.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\bench.gnu, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\bench.sh, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\benchmark-native.c, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\benchmark.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\bin\uuid, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test\compare_v1.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test\test.html, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\LICENSE.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\uuid.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\test\object.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\lib\options.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release\obj.target\service.node.d, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release\service.node.d, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\obj.target\service.node, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\service.node, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\binding.Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\config.gypi, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\service.target.mk, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\example\periodic-logger.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\pthread.cc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\pthread.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\service.cc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\service.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\binding.gyp, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\license.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc\wg-meetings\2015-01-30.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc\stream.markdown, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_duplex.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_passthrough.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_readable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_transform.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_writable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\.zuul.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\duplex.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\passthrough.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\readable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\transform.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\writable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.js.map, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.min.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.slim.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.slim.js.map, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.slim.min.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\manager.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\on.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\socket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\url.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\.jshintrc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\debug.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\node.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\binary.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\is-buffer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\LICENCE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\example\tarray.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test\server\undef_globals.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test\tarray.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\readme.markdown, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\node.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\BufferPool.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\BufferUtil.fallback.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\BufferUtil.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\ErrorCodes.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Extensions.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\PerMessageDeflate.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Receiver.hixie.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Receiver.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Sender.hixie.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Sender.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Validation.fallback.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Validation.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\WebSocket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\WebSocketServer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\SECURITY.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\LICENSE-MIT.txt, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\wtf-8.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\example\demo.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\lib\XMLHttpRequest.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-constants.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-events.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-exceptions.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-headers.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-redirect-302.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-redirect-303.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-redirect-307.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-request-methods.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-request-protocols.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\testdata.txt, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\autotest.watchr, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\app, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\main.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\v, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\cmd.bat, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\reg.reg, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\run.vbs, Delete-on-Reboot, [1033], [360756],1.0.1217 Trojan.Agent.VBS, C:\USERS\{username}\DESKTOP\INST-CLI-17.EXE, Delete-on-Reboot, [771], [368894],1.0.1217 Trojan.Agent.VBS, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\WINSVC.VBS, Delete-on-Reboot, [771], [362645],1.0.1217 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  10. What is GetFitNow? The Malwarebytes research team has determined that GetFitNow is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. GetFitNow is a member of the Spigot family. How do I know if my computer is affected by GetFitNow? You may see these browser extensions/add-ons: and these altered settings: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browser(s): How did GetFitNow get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove GetFitNow? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of GetFitNow? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the GetFitNow entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the GetFitNow hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.getfitnow.co/?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30 SearchScopes: HKCU -> DefaultScope {E4B45767-A66A-459A-B864-3B8F8C7E246A} URL = hxxp://search.getfitnow.co/s?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30&query={searchTerms} SearchScopes: HKCU -> {E4B45767-A66A-459A-B864-3B8F8C7E246A} URL = hxxp://search.getfitnow.co/s?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30&query={searchTerms} FF Homepage: hxxp://search.getfitnow.co?uid={uid2}&uc=20170208&ap=appfocus1&source=tt&page=homepage&implementation_id=fitness_4.0.1 FF Extension: Fitness - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Fitness.xpi [2017-02-08] CHR Extension: (Get Fit Now) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh [2017-02-08] C:\Users\{username}\AppData\Roaming\SpigotSettings GetFitNow (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.1.0.1 - Spigot, Inc.) <==== ATTENTION The most significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\jgblngkjeffdpdnfgenlfjnaakgahfoh Adds the file 000003.log"="2/8/2017 9:18 AM, 252 bytes, A Adds the file CURRENT"="2/8/2017 9:18 AM, 16 bytes, A Adds the file LOCK"="2/8/2017 9:18 AM, 0 bytes, A Adds the file LOG"="2/8/2017 9:28 AM, 410 bytes, A Adds the file LOG.old"="2/8/2017 9:18 AM, 184 bytes, A Adds the file MANIFEST-000001"="2/8/2017 9:18 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @Fitness.xpi"="2/8/2017 9:16 AM, 64432 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Fitness\simple-storage Adds the file store.json"="2/8/2017 9:17 AM, 317 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SpigotSettings Adds the file Uninstall.exe"="2/8/2017 9:12 AM, 267616 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.getfitnow.co/?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{E4B45767-A66A-459A-B864-3B8F8C7E246A}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E4B45767-A66A-459A-B864-3B8F8C7E246A}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.getfitnow.co/s?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "GetFitNow" "DisplayVersion"="REG_SZ", "2.1.0.1" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\SpigotSettings\" "Publisher"="REG_SZ", "Spigot, Inc." "UninstallHomepage"="REG_SZ", "http://search.getfitnow.co/?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30" "UninstallImpression"="REG_SZ", "http://imp.getfitnow.co/impression.do?source=&sub_id=20170208&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=appfocus1&user_id={uid1}&implementation_id=fitness__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\SpigotSettings\Uninstall.exe" /uninstall" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/8/17 Scan Time: 9:38 AM Logfile: mbamGetFitNow.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1207 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359252 Time Elapsed: 1 min, 45 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 1 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [811], [300859],1.0.1207 Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 13 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Fitness\simple-storage, Delete-on-Reboot, [2350], [364585],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@FITNESS, Delete-on-Reboot, [2350], [364585],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_locales\en, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html\popup, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_metadata, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js\popup, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_locales, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\newtab, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\css, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JGBLNGKJEFFDPDNFGENLFJNAAKGAHFOH, Delete-on-Reboot, [2350], [362981],1.0.1207 File: 18 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Fitness\simple-storage\store.json, Delete-on-Reboot, [2350], [364585],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [2350], [361537],1.0.1207 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\SPIGOTSETTINGS\UNINSTALL.EXE, Delete-on-Reboot, [811], [300859],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JGBLNGKJEFFDPDNFGENLFJNAAKGAHFOH\3.0_0\BACKGROUND.JS, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\css\description.css, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\css\popup.css, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html\popup\description.html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html\popup\popup.html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js\popup\popup.js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js\userNewTab.js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\newtab\newtab.html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_locales\en\messages.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_metadata\computed_hashes.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_metadata\verified_contents.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\contentscript.js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\icon.png, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\manifest.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@FITNESS.XPI, Delete-on-Reboot, [2350], [364607],1.0.1207 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  11. What is RunBooster? The Malwarebytes research team has determined that RunBooster is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by RunBooster? You may see this entry in your list of installed programs: this Scheduled Task: and you may see this warning during install: How did RunBooster get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove RunBooster? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of RunBooster? No, Malwarebytes removes RunBooster completely. This adware creates a scheduled task. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the RunBooster adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: (SkyNET Corporation) C:\Program Files\RunBooster\RunBoosterService64.exe R2 RunBooster; C:\Program Files\RunBooster\RunBoosterService64.exe [286720 2017-02-07] (SkyNET Corporation) [File not signed] R2 WinDivert1.2; C:\Windows\system32\drivers\WinDivert64.sys [37552 2017-02-07] (Basil) (Basil) C:\Windows\system32\Drivers\WinDivert64.sys C:\Windows\System32\Tasks\RunBoosterUpdateTask C:\Program Files\RunBooster RunBooster (HKLM\...\RunBooster) (Version: 1.0.3 - SkyNET Corporation) <==== ATTENTION Task: {9475BC77-1F2B-4B71-B8C3-7702B8C4DBC9} - System32\Tasks\RunBoosterUpdateTask => C:\Program Files\RunBooster\RunBoosterUpdateTask64.exe [2017-02-07] (SkyNET Corporation) <==== ATTENTION () C:\Program Files\RunBooster\WinDivert.dll Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files\RunBooster Adds the file msvcr110.dll"="2/7/2017 8:57 AM, 849360 bytes, A Adds the file RunBoosterService64.exe"="2/7/2017 8:57 AM, 286720 bytes, A Adds the file RunBoosterUpdateTask64.exe"="2/7/2017 8:57 AM, 399360 bytes, A Adds the file Uninstall.exe"="2/7/2017 8:57 AM, 349184 bytes, A Adds the file WinDivert.dll"="2/7/2017 8:57 AM, 30208 bytes, A In the existing folder C:\Windows\System32\drivers Adds the file WinDivert64.sys"="2/7/2017 8:57 AM, 37552 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file RunBoosterUpdateTask"="2/7/2017 8:57 AM, 4272 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RunBooster] "DisplayIcon"="REG_SZ", "C:\Program Files\RunBooster\RunBoosterService64.exe" "DisplayName"="REG_SZ", "RunBooster" "DisplayVersion"="REG_SZ", "1.0.3" "EstimatedSize"="REG_DWORD", 1869 "InstallDate"="REG_SZ", "20170207" "InstallLocation"="REG_SZ", "C:\Program Files\RunBooster" "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "SkyNET Corporation" "UninstallString"="REG_SZ", "C:\Program Files\RunBooster\Uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\RunBooster\Cryptography] "MachineGuid"="REG_SZ", "11b5228c-8e3a-466c-acdb-cfb97cf018a2" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RunBooster] "Description"="REG_SZ", "Shows unique selling propositions while surfing in the web" "DisplayName"="REG_SZ", "RunBooster Service" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Program Files\RunBooster\RunBoosterService64.exe" "ObjectName"="REG_SZ", "NT AUTHORITY\LocalService" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDivert1.2] "DisplayName"="REG_SZ", "WinDivert1.2" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "\??\C:\Windows\system32\drivers\WinDivert64.sys" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDivert1.2\Enum] "0"="REG_SZ", "Root\LEGACY_WINDIVERT1.2\0000" "Count"="REG_DWORD", 1 "NextInstance"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDivert1.2\Parameters\Wdf] "TimeOfLastSqmLog"="REG_QWORD, .... "WdfMajorVersion"="REG_DWORD", 1 "WdfMinorVersion"="REG_DWORD", 9 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/7/17 Scan Time: 9:11 AM Logfile: mbamRunBooster.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1201 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359009 Time Elapsed: 2 min, 3 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Adware.RunBooster, C:\PROGRAM FILES\RUNBOOSTER\RUNBOOSTERSERVICE64.EXE, Quarantined, [2278], [357591],1.0.1201 Module: 1 Adware.RunBooster, C:\PROGRAM FILES\RUNBOOSTER\RUNBOOSTERSERVICE64.EXE, Quarantined, [2278], [357591],1.0.1201 Registry Key: 3 Adware.RunBooster, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9475BC77-1F2B-4B71-B8C3-7702B8C4DBC9}, Delete-on-Reboot, [2278], [358296],1.0.1201 Adware.RunBooster, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\RunBoosterUpdateTask, Delete-on-Reboot, [2278], [358287],1.0.1201 Adware.RunBooster, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RUNBOOSTER, Delete-on-Reboot, [2278], [357591],1.0.1201 Registry Value: 2 Adware.RunBooster, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9475BC77-1F2B-4B71-B8C3-7702B8C4DBC9}|PATH, Delete-on-Reboot, [2278], [358296],1.0.1201 Adware.RunBooster, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RUNBOOSTER|DESCRIPTION, Delete-on-Reboot, [2278], [357591],1.0.1201 Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 4 Adware.RunBooster, C:\USERS\{username}\DESKTOP\RUNBOOSTERSETUP64_3231.EXE, Delete-on-Reboot, [2278], [357686],1.0.1201 Adware.RunBooster, C:\PROGRAM FILES\RUNBOOSTER\RUNBOOSTERUPDATETASK64.EXE, Delete-on-Reboot, [2278], [357685],1.0.1201 Adware.RunBooster, C:\WINDOWS\SYSTEM32\TASKS\RUNBOOSTERUPDATETASK, Delete-on-Reboot, [2278], [357683],1.0.1201 Adware.RunBooster, C:\PROGRAM FILES\RUNBOOSTER\RUNBOOSTERSERVICE64.EXE, Delete-on-Reboot, [2278], [357591],1.0.1201 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  12. What is ConvertPDFsNow? The Malwarebytes research team has determined that ConvertPDFsNow is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. ConvertPDFsNow is a Mindspark/Ask toolbar now known as IAC Applications. How do I know if my computer is affected by ConvertPDFsNow? You may see these browser extensions/add-ons: The extensions will add this toolbar: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browsers: How did ConvertPDFsNow get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove ConvertPDFsNow? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of ConvertPDFsNow? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the ConvertPDFsNow entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the ConvertPDFsNow hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/convertpdfsnow/ttab02ie/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/convertpdfsnow/ttab02/index.html?coId={coid2}&subId&ln=en&n={n2}&ptb={ptb2}&st&p2={p22}&si FF Extension: ConvertPDFsNow - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_jqMembers_@www.convertpdfsnow.com [2017-02-06] CHR Extension: (ConvertPDFsNow) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk [2017-02-06] C:\Users\{username}\AppData\Local\ConvertPDFsNowTooltab ConvertPDFsNow Internet Explorer Homepage and New Tab (HKCU\...\ConvertPDFsNowTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/6/17 Scan Time: 9:15 AM Logfile: mbamConvertPDFsNow.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1189 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 358797 Time Elapsed: 1 min, 33 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\CONVERTPDFSNOWTOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [341], [301125],1.0.1189 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ConvertPDFsNowTooltab Uninstall Internet Explorer, Delete-on-Reboot, [341], [301125],1.0.1189 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [341], [293497],1.0.1189 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ConvertPDFsNowTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [341], [352442],1.0.1189 Data Stream: 0 (No malicious items detected) Folder: 89 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\ConvertPDFsNowTooltab, Delete-on-Reboot, [1049], [356944],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\abstractbutton\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\thirdparty\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\uninstall\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\weather\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\weather\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\weather\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\generic\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\alert\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\link\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\weather, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\abstractbutton, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\rss\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\rss\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare\icons, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\images, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\rss, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\radioWrapper, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\thirdparty, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\foreground, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\uninstall, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\generic, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\weather, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\background, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\alert, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\link, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\rss, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\window, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\adapter, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\libs, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\_metadata, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ILJADAGANNNEOBNIKLCOCAONBNOCINLK, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\META-INF, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\chrome, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_JQMEMBERS_@WWW.CONVERTPDFSNOW.COM, Delete-on-Reboot, [341], [302304],1.0.1189 File: 287 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\CONVERTPDFSNOWTOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [341], [301125],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [319354],1.0.1189 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1049], [356946],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_convertpdfsnow.dl.myway.com_0.localstorage, Delete-on-Reboot, [341], [240305],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_convertpdfsnow.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [341], [240305],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_convertpdfsnow.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [341], [240306],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_convertpdfsnow.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [341], [240306],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ILJADAGANNNEOBNIKLCOCAONBNOCINLK\12.202.10.39268_0\MANIFEST.JSON, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\menu\README.txt, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\bs.30.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\common.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\dynamic.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\enableDetect.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\global.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\messageEventListener.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\navRedirector.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\paramReplacer.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\PartnerId.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\set.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\foreground\button.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\background\searchBox.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\css\supertab.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\html\supertab.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js\reporting.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js\supertab.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\components\supertab\js\__utm.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\arrowSprite.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\icon128.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\icon16.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\icon19disabled.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\icon19on.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\icon48.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\233011883.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\233011895.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\233011896.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\233011947.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\233011964.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\down_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\magnifying_glass.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\search_button.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\tvf_icon_guide.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\tvf_logo.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\images\wrench.png, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\newTabInitialize.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\chromeStorage.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\chromeUtils.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\companionSWUtils.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\exeManager.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\exeManagerNMD.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\exePackageManager.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\focusManager.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\globalBlacklistManager.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\messaging.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\mutation_summary-min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\mutation_summary.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\newTabInfo.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\options.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\readLocalStorage.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\reservespaceifenabled.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\scriptInjector.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\searchContext.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\settingsOverrides.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\toolbarCookieParser.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\toolbarPreinit.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\URILoaderContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\webTooltabAPI.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\Widget.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\widgetFactory.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\js\widgetWindowManager.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\cache.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\ce.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\debug.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\native\ss.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\activePing.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\buttonLogger.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\competitorDnsList.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\console.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\httpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\HttpURL.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\internationalSearch.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\rsvp-latest.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\testHttpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\unifiedLogger.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\universalConsole.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\shared\utils.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\_metadata\computed_hashes.json, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\_metadata\verified_contents.json, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spent.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\bg.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\buildVars, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\buildVars.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\companionSW.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\config.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\contentScript.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\contentScript.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\debug.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\debug.jade, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\extension_toolbar_api.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\initWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\newTabContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\options.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spent.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spent.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spent2.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spent2.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spentJ.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spentK.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\spentK.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\startup.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\stub.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\stubby.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\superFrame.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\toolbar.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\toolbar.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\toolbarUI.css, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\toolbarUI.html, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\toolbarUI.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\url.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljadagannneobniklcocaonbnocinlk\12.202.10.39268_0\webtooltab.cs.js, Delete-on-Reboot, [341], [301932],1.0.1189 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_JQMEMBERS_@WWW.CONVERTPDFSNOW.COM\INSTALL.RDF, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\chrome\ffxtbr.jar, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\META-INF\manifest.mf, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\META-INF\mozilla.rsa, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\META-INF\mozilla.sf, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\bootstrap.js, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\chrome.manifest, Delete-on-Reboot, [341], [302304],1.0.1189 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jqMembers_@www.convertpdfsnow.com\chrome.manifest.restartless, Delete-on-Reboot, [341], [302304],1.0.1189 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  13. What is 24x7 Help? The Malwarebytes research team has determined that 24x7 Help is a Tech Support Scam. These so-called "Tech Support Scammers" try to trick you into calling their phone number for various reasons, all of which turn out to be fraudulent in the end. How do I know if my computer is affected by 24x7 Help? You may have seen this warning during install: this entry in your list of installed software and features: and these icons on your desktop, in your startmenu, your taskbar and the toolbar of practically every other appplication: and these screens during "operations": How did 24x7 Help get on my computer? Tech Support Scammers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove 24x7 Help? Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application, but due to the nature of the infection this will require a few extra steps. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of 24x7 Help? No, Malwarebytes removes 24x7 Help completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Tech Support Scam. and we block traffic to their domain. Technical details for experts You may see these entries in FRST logs: (PCRx.com, LLC) C:\Program Files (x86)\24x7Help\App24x7Svc.exe (Crawler, LLC) C:\Program Files (x86)\24x7Help\App24x7Help.exe (PCRx.com, LLC) C:\Program Files (x86)\24x7Help\App24x7Hook.exe (PCRx.com, LLC) C:\Program Files (x86)\24x7Help\App24x7Hook64.exe HKLM-x32\...\Run: [24x7HELP] => C:\Program Files (x86)\24x7Help\App24x7Help.exe [1918264 2015-06-26] (Crawler, LLC) R2 24x7HelpSvc; C:\Program Files (x86)\24x7Help\App24x7Svc.exe [339768 2015-06-26] (PCRx.com, LLC) C:\Users\{username}\AppData\Roaming\24x7 Help C:\Users\Public\Desktop\24x7 Help.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\24x7 Help C:\Program Files (x86)\24x7Help 24x7 Help (HKLM-x32\...\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1) (Version: 2.2.0.15 - Crawler Group) <==== ATTENTION () C:\Program Files (x86)\24x7Help\24x7desk.64.dll Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\24x7Help Adds the file 24x7desk.64.dll"="6/26/2015 2:18 AM, 227128 bytes, A Adds the file 24x7desk.dll"="6/26/2015 2:18 AM, 213304 bytes, A Adds the file App24x7Help.exe"="6/26/2015 2:18 AM, 1918264 bytes, A Adds the file App24x7Hook.dll"="6/26/2015 2:18 AM, 39224 bytes, A Adds the file App24x7Hook.exe"="6/26/2015 2:18 AM, 40760 bytes, A Adds the file App24x7Hook64.dll"="6/26/2015 2:18 AM, 44344 bytes, A Adds the file App24x7Hook64.exe"="6/26/2015 2:18 AM, 45880 bytes, A Adds the file App24x7Svc.exe"="6/26/2015 2:18 AM, 339768 bytes, A Adds the file unins000.dat"="2/3/2017 1:24 PM, 36475 bytes, A Adds the file unins000.exe"="2/3/2017 1:24 PM, 1311056 bytes, A Adds the file unins000.msg"="2/3/2017 1:24 PM, 10582 bytes, A Adds the folder C:\Program Files (x86)\24x7Help\Update Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\24x7 Help Adds the file 24x7 Help.lnk"="2/3/2017 1:24 PM, 1040 bytes, A Adds the file 24x7Help.org.url"="2/3/2017 1:24 PM, 50 bytes, A Adds the file Uninstall 24x7 Help.lnk"="2/3/2017 1:24 PM, 961 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\24x7 Help\skin Adds the file 24x7_UploaderDark01.png"="5/6/2012 2:23 AM, 46003 bytes, A Adds the file 24x7bubble_Left.png"="7/31/2012 5:04 PM, 4326 bytes, A Adds the file 24x7bubble_Right.png"="7/31/2012 5:04 PM, 4336 bytes, A Adds the file 24x7bubble_X00.png"="7/31/2012 5:04 PM, 1150 bytes, A Adds the file 24x7bubble_X01.png"="7/31/2012 5:04 PM, 1158 bytes, A Adds the file 24x7bubble_X02.png"="7/31/2012 5:04 PM, 1150 bytes, A Adds the file 24x7Dark_NoTabs_Back00.png"="6/15/2012 11:48 AM, 1124 bytes, A Adds the file 24x7Dark_NoTabs_PhoneIcon.png"="6/18/2012 4:07 PM, 931 bytes, A Adds the file 24x7Dark001_SettingsActive.png"="9/3/2012 2:43 PM, 1116 bytes, A Adds the file 24x7Dark001_SettingsBack.png"="9/3/2012 2:28 PM, 1115 bytes, A Adds the file 24x7Dark001_SettingsHover.png"="9/3/2012 2:41 PM, 1118 bytes, A Adds the file 24x7logoNew_dark01.png"="6/5/2012 4:03 PM, 2433 bytes, A Adds the file 24x7NewAppGraph_CPUblue.png"="12/3/2013 11:54 AM, 1173 bytes, A Adds the file 24x7NewAppGraph_CPUgreen.png"="12/3/2013 11:55 AM, 1174 bytes, A Adds the file 24x7NewAppGraph_CPUmonitorIcon00.png"="11/21/2013 11:38 AM, 2511 bytes, A Adds the file 24x7NewAppGraph_CPUmonitorIcon01.png"="11/21/2013 11:37 AM, 2791 bytes, A Adds the file 24x7NewAppGraph_graph.png"="11/21/2013 10:28 AM, 1683 bytes, A Adds the file 24x7NewAppGraph_LivechatIcon00.png"="11/21/2013 11:36 AM, 1540 bytes, A Adds the file 24x7NewAppGraph_LivechatIcon01.png"="11/21/2013 11:37 AM, 1580 bytes, A Adds the file 24x7NewAppGraph_lowerstripe.png"="11/21/2013 8:48 AM, 1260 bytes, A Adds the file 24x7NewAppGraph_manphoto.png"="11/21/2013 8:53 AM, 28368 bytes, A Adds the file 24x7NewAppGraph_SupportIcon00.png"="11/21/2013 11:35 AM, 2455 bytes, A Adds the file 24x7NewAppGraph_SupportIcon01.png"="11/21/2013 11:35 AM, 2624 bytes, A Adds the file 24x7NewAppGraph_SystemCheckIcon00.png"="11/21/2013 11:40 AM, 2235 bytes, A Adds the file 24x7NewAppGraph_SystemCheckIcon01.png"="11/21/2013 11:40 AM, 2345 bytes, A Adds the file ArrowSmall.png"="9/13/2012 3:14 PM, 1045 bytes, A Adds the file ArrowSmallHot.png"="9/13/2012 3:14 PM, 1017 bytes, A Adds the file bubble.xml"="11/27/2013 1:18 PM, 1911 bytes, A Adds the file Hardware_Icon.png"="4/27/2012 2:39 PM, 1185 bytes, A Adds the file Icon_FAQ.png"="12/2/2013 11:07 AM, 1114 bytes, A Adds the file Icon_FAQ_nonactive.png"="12/2/2013 11:06 AM, 1117 bytes, A Adds the file Icon_Settings.png"="12/2/2013 11:07 AM, 1893 bytes, A Adds the file Icon_Settings_nonactive.png"="12/2/2013 11:07 AM, 1820 bytes, A Adds the file MainImg_SettingsDark01.png"="5/2/2012 1:55 PM, 18693 bytes, A Adds the file Navigation_HomeIcon00_Dark01.png"="5/2/2012 2:36 PM, 1215 bytes, A Adds the file Navigation_HomeIcon01_Dark01.png"="5/2/2012 2:37 PM, 1215 bytes, A Adds the file Navigation_SettingsIcon00_Dark01.png"="5/2/2012 2:34 PM, 1237 bytes, A Adds the file Navigation_SettingsIcon01_Dark01.png"="5/2/2012 2:35 PM, 1237 bytes, A Adds the file OK_IconGreen01.png"="4/27/2012 3:46 PM, 1370 bytes, A Adds the file PeriodicSystemCheckBubble.png"="12/18/2012 1:07 PM, 2240 bytes, A Adds the file Phones_Icon.png"="4/27/2012 2:40 PM, 1219 bytes, A Adds the file Security_Icon.png"="4/27/2012 2:39 PM, 1559 bytes, A Adds the file skin.xml"="1/14/2014 9:41 AM, 41662 bytes, A Adds the file Software_Icon.png"="4/27/2012 2:41 PM, 1773 bytes, A Adds the file SupportCheck01_arrow00.png"="4/27/2012 4:00 PM, 1280 bytes, A Adds the file SupportCheck01_arrow01.png"="4/27/2012 4:00 PM, 1232 bytes, A Adds the file Warning_Icon01.png"="4/27/2012 3:33 PM, 1205 bytes, A Adds the file Warning_IconOrange01.png"="4/27/2012 3:34 PM, 1205 bytes, A Adds the file Warning_IconRed01.png"="4/27/2012 3:44 PM, 1211 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file 24x7 Help.lnk"="2/3/2017 1:24 PM, 1022 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{865D7100-82C7-42F4-9C06-860DEC0871B2}] "(Default)"="REG_SZ", "24x7 Help" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{865D7100-82C7-42F4-9C06-860DEC0871B2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{865D7100-82C7-42F4-9C06-860DEC0871B2}\InprocServer32] "(Default)"="REG_SZ", "C:\Program Files (x86)\24x7Help\24x7desk.64.dll" "ThreadingModel"="REG_SZ", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\24x7HELP] "(Default)"="REG_SZ", "" "INSTALL_DATE"="REG_SZ", "42769.5590338657" "LAST_HIT"="REG_SZ", "42769.559807419" "LAST_SENDDATA"="REG_SZ", "42769.5596121065" "LAST_UPDATE"="REG_SZ", "42769.5590338657" "PHONE_NUMBER"="REG_SZ", "1-855-760-2497" "TABS"="REG_SZ", "" "UID"="REG_SZ", "576396702981981540" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "24x7HELP"="REG_SZ", ""C:\Program Files (x86)\24x7Help\App24x7Help.exe" /STARTUP" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\24x7Help\App24x7Help.exe" "DisplayName"="REG_SZ", "24x7 Help" "DisplayVersion"="REG_SZ", "2.2.0.15" "EstimatedSize"="REG_DWORD", 4076 "HelpLink"="REG_SZ", "http://www.24x7Help.org/" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\24x7Help" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "24x7 Help" "Inno Setup: Language"="REG_SZ", "en" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon" "Inno Setup: Setup Version"="REG_SZ", "5.3.8 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170203" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\24x7Help\" "MajorVersion"="REG_DWORD", 2 "MinorVersion"="REG_DWORD", 2 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Crawler Group" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\24x7Help\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\24x7Help\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.24x7Help.org/" "URLUpdateInfo"="REG_SZ", "http://www.24x7Help.org/" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\24x7HelpSvc] "DisplayName"="REG_SZ", "24x7HelpService" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\24x7Help\App24x7Svc.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 [HKEY_CURRENT_USER\Software\24x7HELP] "(Default)"="REG_SZ", "" "LANG_ID"="REG_SZ", "en" "LAST_PERIODIC_SYSTEMCHECK"="REG_SZ", "42769.5590248264" "REPRESENTATIVE_ICON"="REG_SZ", "7" "TECHSUPPORT_TEXT"="REG_SZ", "Click here for instant access to technical support from the 24x7 Help" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/3/17 Scan Time: 1:35 PM Logfile: mbam24x7Help.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.50 Update Package Version: 1.0.1171 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 358651 Time Elapsed: 2 min, 11 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 4 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HELP.EXE, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7SVC.EXE, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.EXE, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.EXE, Quarantined, [12657], [175288],1.0.1171 Module: 11 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\24X7DESK.64.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HELP.EXE, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.DLL, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7SVC.EXE, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.EXE, Quarantined, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.EXE, Quarantined, [12657], [175288],1.0.1171 Registry Key: 6 PUP.Optional.24x7, HKLM\SOFTWARE\CLASSES\CLSID\{865D7100-82C7-42F4-9C06-860DEC0871B2}, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, HKLM\SOFTWARE\CLASSES\CLSID\{865D7100-82C7-42F4-9C06-860DEC0871B2}\InprocServer32, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\24x7HelpSvc, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, HKLM\SOFTWARE\WOW6432NODE\24x7HELP, Delete-on-Reboot, [12657], [228527],1.0.1171 PUP.Optional.24x7, HKCU\SOFTWARE\24x7HELP, Delete-on-Reboot, [12657], [228528],1.0.1171 Registry Value: 1 PUP.Optional.24x7, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|24x7HELP, Delete-on-Reboot, [12657], [175288],1.0.1171 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 5 PUP.Optional.24x7, C:\Program Files (x86)\24x7Help\Update, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24x7Help, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\USERS\{username}\APPDATA\ROAMING\24X7 HELP, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\24X7 HELP, Delete-on-Reboot, [12657], [228525],1.0.1171 File: 65 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.DLL, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\24X7DESK.64.DLL, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HELP.EXE, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.DLL, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7SVC.EXE, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK64.EXE, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\PROGRAM FILES (X86)\24X7HELP\APP24X7HOOK.EXE, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\Program Files (x86)\24x7Help\24x7desk.dll, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\Program Files (x86)\24x7Help\unins000.dat, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\Program Files (x86)\24x7Help\unins000.exe, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\Program Files (x86)\24x7Help\unins000.msg, Delete-on-Reboot, [12657], [175288],1.0.1171 PUP.Optional.24x7, C:\USERS\{username}\APPDATA\ROAMING\24X7 HELP\SKIN\BUBBLE.XML, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_SupportIcon00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Icon_FAQ.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7bubble_Left.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7bubble_Right.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7bubble_X00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7bubble_X01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7bubble_X02.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7Dark001_SettingsActive.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7Dark001_SettingsBack.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7Dark001_SettingsHover.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7Dark_NoTabs_Back00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7Dark_NoTabs_PhoneIcon.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7logoNew_dark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_CPUblue.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_CPUgreen.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_CPUmonitorIcon00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_CPUmonitorIcon01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_graph.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_LivechatIcon00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_LivechatIcon01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_lowerstripe.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_manphoto.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_SupportIcon01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_SystemCheckIcon00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7NewAppGraph_SystemCheckIcon01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\24x7_UploaderDark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\ArrowSmall.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\ArrowSmallHot.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Hardware_Icon.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Icon_FAQ_nonactive.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Icon_Settings.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Icon_Settings_nonactive.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\MainImg_SettingsDark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Navigation_HomeIcon00_Dark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Navigation_HomeIcon01_Dark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Navigation_SettingsIcon00_Dark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Navigation_SettingsIcon01_Dark01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\OK_IconGreen01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\PeriodicSystemCheckBubble.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Phones_Icon.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Security_Icon.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\skin.xml, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Software_Icon.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\SupportCheck01_arrow00.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\SupportCheck01_arrow01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Warning_Icon01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Warning_IconOrange01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\Users\{username}\AppData\Roaming\24x7 Help\skin\Warning_IconRed01.png, Delete-on-Reboot, [12657], [233700],1.0.1171 PUP.Optional.24x7, C:\USERS\PUBLIC\DESKTOP\24X7 HELP.LNK, Delete-on-Reboot, [12657], [228529],1.0.1171 PUP.Optional.24x7Help, C:\USERS\{username}\DESKTOP\24X7HELP.EXE, Delete-on-Reboot, [1218], [306994],1.0.1171 PUP.Optional.24x7, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\24X7 HELP\24X7 HELP.LNK, Delete-on-Reboot, [12657], [228525],1.0.1171 PUP.Optional.24x7, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\24x7 Help\24x7Help.org.url, Delete-on-Reboot, [12657], [228525],1.0.1171 PUP.Optional.24x7, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\24x7 Help\Uninstall 24x7 Help.lnk, Delete-on-Reboot, [12657], [228525],1.0.1171 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  14. What is CleanMyPC? The Malwarebytes research team has determined that CleanMyPC is a fake registry cleaner. These so-called "registry cleaners" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with CleanMyPC? This is how the main screen of the registry cleaning application looks: You will find these icons in your taskbar, your startmenu and on your desktop: And see these warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: How did CleanMyPC get on my computer? These so-called registry cleaners use different methods of getting installed. This particular one was downloaded from their website. How do I remove CleanMyPC? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of CleanMyPC? No, Malwarebytes removes CleanMyPC completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this registry cleaner. As you can see below the full version of Malwarebytes would have protected you against the CleanMyPC installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block their domain. Technical details for experts You may see these entries in FRST logs: (CleanMyPC Tools Software) C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCleaner.exe (CleanMyPC Software) C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe HKCU\...\Run: [Registry Cleaner Scheduler] => C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe [1400024 2014-12-14] (CleanMyPC Software) C:\Users\{username}\AppData\Roaming\CleanMyPC Software C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC Registry Cleaner C:\Program Files (x86)\CleanMyPC CleanMyPC - Registry Cleaner (HKLM-x32\...\CleanMyPC - Registry Cleaner_is1) (Version: - CleanMyPC Software) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\CleanMyPC\Registry Cleaner Adds the file RCHelper.exe"="12/14/2014 8:15 PM, 1400024 bytes, A Adds the file RCleaner.exe"="12/14/2014 8:15 PM, 3583192 bytes, A Adds the file UnFD.exe"="12/14/2014 8:15 PM, 1466368 bytes, A Adds the file unins000.dat"="2/2/2017 9:15 AM, 3869 bytes, A Adds the file unins000.exe"="2/2/2017 9:14 AM, 754970 bytes, A Adds the file update.exe"="12/14/2014 8:15 PM, 664792 bytes, A Adds the file update.urs"="12/14/2014 8:15 PM, 352 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC Registry Cleaner Adds the file CleanMyPC - Registry Cleaner.lnk"="2/2/2017 9:15 AM, 1119 bytes, A Adds the file Registry Cleaner Online Help.lnk"="2/2/2017 9:15 AM, 2053 bytes, A Adds the file Uninstall CleanMyPC - Registry Cleaner.lnk"="2/2/2017 9:15 AM, 1119 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\CleanMyPC Software\CleanMyPC Registry Cleaner In the existing folder C:\Users\{username}\Desktop Adds the file CleanMyPC - Registry Cleaner.lnk"="2/2/2017 9:15 AM, 1101 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9254C72A-294B-BFDF-ACFA-A7E8A56FF865}] "(Default)"="REG_SZ", "CImeProductObject_JK Class" "dpOyjPvOmlcq"="REG_SZ", "fC[evgCGLVijRZcX|\d]me^NheWiw`i" "humqnl"="REG_SZ", "Xbfx[x@}pCsHwzmCRBQ[uCVAl`kHG_WA" "ivapVGzoVmm"="REG_SZ", "QekSTF{A|eSshe]B`" "sdapb"="REG_SZ", "APG\]_^GSuYQp{P{@hET@}z}AcNs" "wgcEfj"="REG_SZ", "@GDnfTO^olhBzDXGrP" "wvdutfclao"="REG_SZ", "[mCZtM|XLrQSYyyL_lDz]wHx" "zKnIomfly"="REG_SZ", "@Hqzme[qmei@J`mAx@XkgKAX{LUyQ}j" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9254C72A-294B-BFDF-ACFA-A7E8A56FF865}\InprocServer32] "(Default)"="REG_EXPAND_SZ, "%SystemRoot%\SysWow64\ime\shared\imjkapi.dll" "ThreadingModel"="REG_SZ", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9254C72A-294B-BFDF-ACFA-A7E8A56FF865}\ProgID] "(Default)"="REG_SZ", "IMEAPI.CImeProductObjectJK.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9254C72A-294B-BFDF-ACFA-A7E8A56FF865}\TypeLib] "(Default)"="REG_SZ", "{da524058-bdb4-482a-997a-338ae04d7156}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9254C72A-294B-BFDF-ACFA-A7E8A56FF865}\Version] "(Default)"="REG_SZ", "1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9254C72A-294B-BFDF-ACFA-A7E8A56FF865}\VersionIndependentProgID] "(Default)"="REG_SZ", "IMEAPI.CImeProductObjectJK" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\RCHelper.exe] "(Default)"="REG_SZ", "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe" "Path"="REG_SZ", "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\RCleaner.exe] "(Default)"="REG_SZ", "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCleaner.exe" "Path"="REG_SZ", "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ComputerAssociates\ITMRT] "HookExclude"="REG_MULTI_SZ, "RCleaner.exe " "InjectExclude"="REG_MULTI_SZ, "RCleaner.exe " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CleanMyPC - Registry Cleaner_is1] "DisplayName"="REG_SZ", "CleanMyPC - Registry Cleaner" "HelpLink"="REG_SZ", "http://www.registry-cleaner.net" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\CleanMyPC\Registry Cleaner" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "CleanMyPC Registry Cleaner" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon" "Inno Setup: Setup Version"="REG_SZ", "5.2.3" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170202" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\" "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "CleanMyPC Software" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\CleanMyPC\Registry Cleaner\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\CleanMyPC\Registry Cleaner\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.registry-cleaner.net" "URLUpdateInfo"="REG_SZ", "http://www.registry-cleaner.net" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe"="REG_SZ", "DisableNXShowUI" "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCleaner.exe"="REG_SZ", "DisableNXShowUI" "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\update.exe"="REG_SZ", "DisableNXShowUI" [HKEY_CURRENT_USER\Software\CleanMyPC\CleanMyPC - Registry Cleaner\Recent File List] [HKEY_CURRENT_USER\Software\CleanMyPC\CleanMyPC - Registry Cleaner\Settings] "FirstRun"="REG_DWORD", 0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Registry Cleaner Scheduler"="REG_SZ", ""C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe" /startup" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/2/17 Scan Time: 9:31 AM Logfile: mbamCleanMyPC.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.50 Update Package Version: 1.0.1155 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 358315 Time Elapsed: 3 min, 31 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 2 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe, Quarantined, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCleaner.exe, Quarantined, [2231], [348420],1.0.1155 Module: 2 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe, Quarantined, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCleaner.exe, Quarantined, [2231], [348420],1.0.1155 Registry Key: 6 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCHelper.exe, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCleaner.exe, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CleanMyPC - Registry Cleaner_is1, Delete-on-Reboot, [2231], [348426],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCHelper.exe, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCleaner.exe, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKCU\SOFTWARE\CLEANMYPC\CleanMyPC - Registry Cleaner, Delete-on-Reboot, [2231], [348427],1.0.1155 Registry Value: 5 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCHelper.exe|PATH, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCleaner.exe|PATH, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Registry Cleaner Scheduler, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCHelper.exe|PATH, Delete-on-Reboot, [2231], [366350],1.0.1155 PUP.Optional.CleanMyPC, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\RCleaner.exe|PATH, Delete-on-Reboot, [2231], [366350],1.0.1155 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 3 PUP.Optional.CleanMyPC, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CLEANMYPC REGISTRY CLEANER, Delete-on-Reboot, [2231], [348421],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\PROGRAM FILES (X86)\CLEANMYPC, Delete-on-Reboot, [2231], [348420],1.0.1155 File: 12 PUP.Optional.CleanMyPC, C:\USERS\{username}\DESKTOP\CLEANMYPC - REGISTRY CLEANER.LNK, Delete-on-Reboot, [2231], [348423],1.0.1155 PUP.Optional.CleanMyPC, C:\USERS\{username}\DESKTOP\REGCLEANER.EXE, Delete-on-Reboot, [2231], [361686],1.0.1155 PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC Registry Cleaner\CleanMyPC - Registry Cleaner.lnk, Delete-on-Reboot, [2231], [348421],1.0.1155 PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC Registry Cleaner\Registry Cleaner Online Help.lnk, Delete-on-Reboot, [2231], [348421],1.0.1155 PUP.Optional.CleanMyPC, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC Registry Cleaner\Uninstall CleanMyPC - Registry Cleaner.lnk, Delete-on-Reboot, [2231], [348421],1.0.1155 PUP.Optional.CleanMyPC, C:\PROGRAM FILES (X86)\CLEANMYPC\REGISTRY CLEANER\UNINS000.DAT, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCleaner.exe, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\UnFD.exe, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\unins000.exe, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\update.exe, Delete-on-Reboot, [2231], [348420],1.0.1155 PUP.Optional.CleanMyPC, C:\Program Files (x86)\CleanMyPC\Registry Cleaner\update.urs, Delete-on-Reboot, [2231], [348420],1.0.1155 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  15. What is Easy Online Game Access? The Malwarebytes research team has determined that Easy Online Game Access is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. How do I know if my computer is affected by Easy Online Game Access? You may see these warnings during install: this browser extension: this new default Search Provider: and this new startpage in the affected browser(s): How did Easy Online Game Access get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove Easy Online Game Access? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Easy Online Game Access? No, Malwarebytes removes Easy Online Game Access completely. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Easy Online Game Access hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block the traffic to their sites. Technical details for experts Possible signs in FRST logs: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.easyonlinegameaccess.com/?source=tt&uid={uid1}&uc=20170201&ap=&i_id=games__1.30 SearchScopes: HKCU -> DefaultScope {0B73690C-0686-422A-999D-FEE19642DD9E} URL = hxxp://search.easyonlinegameaccess.com/s?source=tt&uid={uid1}&uc=20170201&ap=&i_id=games__1.30&query={searchTerms} SearchScopes: HKCU -> {0B73690C-0686-422A-999D-FEE19642DD9E} URL = hxxp://search.easyonlinegameaccess.com/s?source=tt&uid={uid1}&uc=20170201&ap=&i_id=games__1.30&query={searchTerms} FF NewTab: hxxp://search.easyonlinegameaccess.com?uid={uid2}&uc=20170201&ap=&source=-bb8&page=newtab&implementation_id=games_0.2.0 FF Homepage: hxxp://search.easyonlinegameaccess.com?uid={uid2}&uc=20170201&ap=&source=-bb8&page=homepage&implementation_id=games_0.2.0 FF Extension: Games - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Games.xpi [2017-02-01] C:\Users\{username}\AppData\Roaming\SpigotSettings Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @Games.xpi"="2/1/2017 9:28 AM, 27453 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Games\simple-storage Adds the file store.json"="2/1/2017 9:29 AM, 327 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SpigotSettings Adds the file Uninstall.exe"="2/1/2017 9:25 AM, 267616 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.easyonlinegameaccess.com/?source=tt&uid={uid1}&uc=20170201&ap=&i_id=games__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{0B73690C-0686-422A-999D-FEE19642DD9E}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0B73690C-0686-422A-999D-FEE19642DD9E}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.easyonlinegameaccess.com/s?source=tt&uid={uid1}&uc=20170201&ap=&i_id=games__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "" "DisplayVersion"="REG_SZ", "2.1.0.1" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\SpigotSettings\" "Publisher"="REG_SZ", "Spigot, Inc." "UninstallHomepage"="REG_SZ", "http://search.easyonlinegameaccess.com/?source=tt&uid={uid1}&uc=20170201&ap=&i_id=games__1.30" "UninstallImpression"="REG_SZ", "http://imp.easyonlinegameaccess.com/impression.do?source=tt&sub_id=20170201&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=&user_id={uid1}&implementation_id=games__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\SpigotSettings\Uninstall.exe" /uninstall" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/1/17 Scan Time: 9:40 AM Logfile: mbamEasyOnlineGameAccess.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.50 Update Package Version: 1.0.1148 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 358118 Time Elapsed: 1 min, 36 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 1 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [811], [300859],1.0.1148 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Games\simple-storage, Delete-on-Reboot, [2349], [364932],1.0.1148 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@GAMES, Delete-on-Reboot, [2349], [364932],1.0.1148 File: 5 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [2349], [361537],1.0.1148 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [2349], [361538],1.0.1148 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Games\simple-storage\store.json, Delete-on-Reboot, [2349], [364932],1.0.1148 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\SPIGOTSETTINGS\UNINSTALL.EXE, Delete-on-Reboot, [811], [300859],1.0.1148 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@GAMES.XPI, Delete-on-Reboot, [811], [364940],1.0.1148 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.