Metallica

Moderators
  • Content count

    1,750
  • Joined

  • Last visited

About Metallica

  • Rank
    Master of PUPs
  • Birthday 05/19/1963

Contact Methods

  • ICQ
    0

Profile Information

  • Location
    Netherlands

Recent Profile Visitors

153,469 profile views
  1. What is DriverUpdaterPro? The Malwarebytes research team has determined that DriverUpdaterPro is a "system optimizer". These so-called "system optimizers" often use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with DriverUpdaterPro? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar and on your desktop: and see these warnings during install: and this screen if you try to fix any reported problems: You may see this entry in your list of installed programs: How did DriverUpdaterPro get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove DriverUpdaterPro? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of DriverUpdaterPro? No, Malwarebytes removes completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\DriverUpdaterPro\DriverUpdaterPro.exe HKCU\...\Run: [DUP] => C:\Program Files (x86)\DriverUpdaterPro\DriverUpdaterPro.exe [3051976 2016-10-02] () C:\Users\Public\Desktop\DriverUpdaterPro.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdaterPro C:\Program Files (x86)\DriverUpdaterPro DriverUpdaterPro (HKLM-x32\...\{A5510462-F6F1-4546-A573-E296FEE4BB6A}_is1) (Version: 10.0.0.0 - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\DriverUpdaterPro Adds the file aff.txt"="1/30/2017 4:10 PM, 3 bytes, A Adds the file DriverUpdaterPro.exe"="10/2/2016 5:00 PM, 3051976 bytes, A Adds the file unins000.dat"="2/24/2017 10:46 AM, 3748 bytes, A Adds the file unins000.exe"="2/24/2017 10:45 AM, 946120 bytes, A Adds the file unins000.msg"="2/24/2017 10:46 AM, 11225 bytes, A Adds the file UninstallPhone.bmp"="3/17/2016 3:26 PM, 468544 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdaterPro Adds the file DriverUpdaterPro.lnk"="2/24/2017 10:46 AM, 1121 bytes, A Adds the file Uninstall DriverUpdaterPro.lnk"="2/24/2017 10:46 AM, 1081 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch Adds the file DriverUpdaterPro.lnk"="2/24/2017 10:46 AM, 1127 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file DriverUpdaterPro.lnk"="2/24/2017 10:46 AM, 1103 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A5510462-F6F1-4546-A573-E296FEE4BB6A}_is1] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\DriverUpdaterPro\unins000.exe" "DisplayName"="REG_SZ", "DriverUpdaterPro" "DisplayVersion"="REG_SZ", "10.0.0.0" "EstimatedSize"="REG_DWORD", 4361 "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\DriverUpdaterPro" "Inno Setup: Icon Group"="REG_SZ", "DriverUpdaterPro" "Inno Setup: Language"="REG_SZ", "english" "Inno Setup: Setup Version"="REG_SZ", "5.5.1.ee1 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170224" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\DriverUpdaterPro\" "MajorVersion"="REG_DWORD", 10 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\DriverUpdaterPro\unins000.exe" /SILENT" "UninstallDataFile"="REG_SZ", "C:\Program Files (x86)\DriverUpdaterPro\unins000.dat" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\DriverUpdaterPro\unins000.exe"" [HKEY_CURRENT_USER\Software\DriverUpdaterPro] "Activated"="REG_DWORD", 0 "AutoRun"="REG_DWORD", 1 "CloseToTray"="REG_DWORD", 1 "flag_dage"="REG_DWORD", 365 "flag_firstresult"="REG_SZ", "2017-02-24 10:46:28 GMT+1" "flag_firstrun"="REG_SZ", "2017-02-24 10:46:25 GMT+1" "flag_ShowPhSupp"="REG_DWORD", 1 "idevuids"="REG_BINARY, (zero length data) "idevuids_sz"="REG_DWORD", 0 "IDLang"="REG_DWORD", 0 "InstallID"="REG_SZ", "6D755F42C24485321803522AB18F53AB" "IsSysUpdated"="REG_DWORD", 0 "LastScanDatei"="REG_BINARY, .... "LastScanSendDatei"="REG_BINARY, .... "odDrivers"="REG_DWORD", 0 "PhSuppNum"="REG_SZ", "1-877-883-9169" "ProxyHost"="REG_SZ", "" "ProxyLogin"="REG_SZ", "" "ProxyPassw"="REG_SZ", "" "ProxyPort"="REG_SZ", "" "SerialNum"="REG_SZ", "" "tDrivers"="REG_DWORD", 0 "udDrivers"="REG_DWORD", 0 "UseProxy"="REG_DWORD", 0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DUP"="REG_SZ", ""C:\Program Files (x86)\DriverUpdaterPro\DriverUpdaterPro.exe" /ot /as /ss" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/24/17 Scan Time: 10:53 AM Logfile: mbamDriverUpdaterPro.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1340 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 361600 Time Elapsed: 1 min, 36 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\DriverUpdaterPro.exe, Quarantined, [1890], [334857],1.0.1340 Module: 1 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\DriverUpdaterPro.exe, Quarantined, [1890], [334857],1.0.1340 Registry Key: 1 PUP.Optional.oTweak, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{A5510462-F6F1-4546-A573-E296FEE4BB6A}_is1, Delete-on-Reboot, [1890], [334857],1.0.1340 Registry Value: 1 PUP.Optional.oTweak, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DUP, Delete-on-Reboot, [1890], [334857],1.0.1340 Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\DRIVERUPDATERPRO, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\DRIVERUPDATERPRO, Delete-on-Reboot, [1890], [335029],1.0.1340 File: 10 PUP.Optional.DriverUpdaterPro, C:\USERS\{username}\DESKTOP\DRIVERUPDATERPRO.EXE, Delete-on-Reboot, [1233], [307359],1.0.1340 PUP.Optional.oTweak, C:\USERS\PUBLIC\DESKTOP\DRIVERUPDATERPRO.LNK, Delete-on-Reboot, [1890], [334858],1.0.1340 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\DRIVERUPDATERPRO\UNINSTALLPHONE.BMP, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\aff.txt, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\DriverUpdaterPro.exe, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\unins000.dat, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\unins000.exe, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\Program Files (x86)\DriverUpdaterPro\unins000.msg, Delete-on-Reboot, [1890], [334857],1.0.1340 PUP.Optional.oTweak, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdaterPro\DriverUpdaterPro.lnk, Delete-on-Reboot, [1890], [335029],1.0.1340 PUP.Optional.oTweak, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdaterPro\Uninstall DriverUpdaterPro.lnk, Delete-on-Reboot, [1890], [335029],1.0.1340 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  2. What is Easy Interests Access? The Malwarebytes research team has determined that Easy Interests Access is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. Easy Interests Access is a member of the Spigot family as described in the blogpost Spigot browser hijackers. How do I know if my computer is affected by Easy Interests Access? You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browser(s): and this new default search provider: How did Easy Interests Access get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove Easy Interests Access? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Easy Interests Access? If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Easy Interests Access hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to their domain: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.easyinterestsaccess.com/?source=tt&uid={uid1}&uc=20170223&ap=&i_id=interest__1.30 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.co.uk/?gws_rd=ssl SearchScopes: HKCU -> DefaultScope {8FCAF78A-539A-4882-B107-3BE2440D10F7} URL = hxxp://search.easyinterestsaccess.com/s?source=tt&uid={uid1}&uc=20170223&ap=&i_id=interest__1.30&query={searchTerms} SearchScopes: HKCU -> {8FCAF78A-539A-4882-B107-3BE2440D10F7} URL = hxxp://search.easyinterestsaccess.com/s?source=tt&uid={uid1}&uc=20170223&ap=&i_id=interest__1.30&query={searchTerms} C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Easy Interests Access (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.4.0.3 - Cloud Installer) The changes made by the IE installer (this one failed on Firefox and Chrome): File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Adds the file Uninstall.exe"="2/23/2017 11:10 AM, 256000 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.easyinterestsaccess.com/?source=tt&uid={uid1}&uc=20170223&ap=&i_id=interest__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{8FCAF78A-539A-4882-B107-3BE2440D10F7}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8FCAF78A-539A-4882-B107-3BE2440D10F7}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.easyinterestsaccess.com/s?source=tt&uid={uid1}&uc=20170223&ap=&i_id=interest__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "Easy Interests Access" "DisplayVersion"="REG_SZ", "2.4.0.3" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\" "Publisher"="REG_SZ", "Cloud Installer" "UninstallHomepage"="REG_SZ", "http://search.easyinterestsaccess.com/?source=tt&uid={uid1}&uc=20170223&ap=&i_id=interest__1.30" "UninstallImpression"="REG_SZ", "http://imp.easyinterestsaccess.com/impression.do?source=tt&sub_id=20170223&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=&user_id={uid1}&implementation_id=interest__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe" /uninstall" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/23/17 Scan Time: 11:19 AM Logfile: mbamEasyInterestsAccess.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1329 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 361399 Time Elapsed: 3 min, 52 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 1 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8FCAF78A-539A-4882-B107-3BE2440D10F7}, Quarantined, [2364], [368913],1.0.1329 Registry Value: 2 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8FCAF78A-539A-4882-B107-3BE2440D10F7}|URL, Quarantined, [2364], [368913],1.0.1329 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replaced, [2364], [373048],1.0.1329 Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 0 (No malicious items detected) Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  3. What is Disk Defrag Free? The Malwarebytes research team has determined that Disk Defrag Free is a "system optimizer". This one also bundles two other products from the same company and tries to hijack your browser(s) startpage and default search provider. On top of that it has a featured software advertizing function. More information about system optimizers in general, can be found on our Malwarebytes Labs blog. How do I know if I am infected with Disk Defrag Free? This is how the main screen of the sytem optimizer looks: You will find these icons on your desktop: and see these warnings during install: You may see this entry in your list of installed programs: and these tasks in your Task Scheduler: This is the new default search provider: How did Disk Defrag Free get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove Disk Defrag Free? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Disk Defrag Free? No, Malwarebytes removes Disk Defrag Free completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the Disk Defrag Free installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. Technical details for experts You may see these entries in FRST logs: (Auslogics) C:\Program Files (x86)\Auslogics\Disk Defrag\DiskDefrag.exe (Auslogics) C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe (Auslogics) C:\Program Files (x86)\Auslogics\BoostSpeed\BoostSpeed.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.yahoo.com/?fr=vmn&type=auslog_yaapp1_hp SearchScopes: HKCU -> DefaultScope {76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB} URL = hxxps://search.yahoo.com/search/?toggle=1&cop=mss&ei=UTF-8&fr=vmn&type=auslog_yaapp1_ch&p={searchTerms} SearchScopes: HKCU -> {76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB} URL = hxxps://search.yahoo.com/search/?toggle=1&cop=mss&ei=UTF-8&fr=vmn&type=auslog_yaapp1_ch&p={searchTerms} FF Homepage: hxxps://search.yahoo.com/?fr=vmn&type=auslog_yaapp1_hp CHR HomePage: Default -> hxxps://search.yahoo.com/?fr=vmn&type=auslog_yaapp1_hp CHR RestoreOnStartup: Default -> "hxxps://search.yahoo.com/?fr=vmn&type=auslog_yaapp1_hp" CHR StartupUrls: Default -> "hxxps://search.yahoo.com/?fr=vmn&type=auslog_yaapp1_hp" CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search/?toggle=1&cop=mss&ei=UTF-8&fr=vmn&type=auslog_yaapp1_ch&p={searchTerms} CHR DefaultSearchKeyword: Default -> yahoo.com CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms} C:\Users\{username}\Desktop\Auslogics BoostSpeed 9.lnk C:\ProgramData\BSD C:\Windows\System32\Tasks\Auslogics C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics C:\Program Files (x86)\Auslogics C:\Users\{username}\Desktop\Auslogics Driver Updater.lnk C:\Users\{username}\Desktop\Auslogics Disk Defrag.lnk C:\ProgramData\Auslogics Auslogics BoostSpeed 9 (HKLM-x32\...\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1) (Version: 9.1.2.0 - Auslogics Labs Pty Ltd) Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 7.1.1.0 - Auslogics Labs Pty Ltd) Auslogics Driver Updater (HKLM-x32\...\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_is1) (Version: 1.9.3.0 - Auslogics Labs Pty Ltd) Task: {306CF93A-A250-4CBB-8661-A87AF7C346A0} - System32\Tasks\Auslogics\Driver Updater\Start Driver Updater ?n {username} logon => C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe [2016-12-12] (Auslogics) Task: {78673419-C59D-492F-9659-E7862C9CA2CA} - System32\Tasks\Auslogics\BoostSpeed\Start BoostSpeed ?n {username} logon => C:\Program Files (x86)\Auslogics\BoostSpeed\BoostSpeed.exe [2017-02-15] (Auslogics) Task: {C1551C67-7F0D-42D8-B154-B38297955654} - System32\Tasks\Auslogics\Driver Updater\Scan => Rundll32.exe TaskSchedulerHelper.dll,RunTask "DriverUpdater.exe" "-UseTray -Schedule" Task: {DEE2D08D-ECAB-4B77-8AA8-6A29E1996117} - System32\Tasks\Auslogics\BoostSpeed\Scan and Repair => Rundll32.exe TaskSchedulerHelper.dll,RunTask "BoostSpeed.exe" "-UseTray -Schedule" The most significant alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Auslogics\BoostSpeed Adds the folder C:\Program Files (x86)\Auslogics\Disk Defrag Adds the folder C:\Program Files (x86)\Auslogics\Driver Updater Adds the folder C:\ProgramData\Auslogics\BoostSpeed\9.x Adds the folder C:\ProgramData\Auslogics\Disk Defrag\7.x\Data Adds the folder C:\ProgramData\Auslogics\Driver Updater\1.x Adds the folder C:\ProgramData\BSD\DriverHive Adds the file history2.dat"="2/22/2017 9:22 AM, 63 bytes, A Adds the folder C:\ProgramData\BSD\DriverHiveEngine Adds the file scandet2.dat"="2/22/2017 9:22 AM, 51069 bytes, A Adds the file scansummary2.dat"="2/22/2017 9:22 AM, 208 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed Adds the file Auslogics BoostSpeed 9 on the Web.url"="2/22/2017 9:23 AM, 126 bytes, A Adds the file Auslogics BoostSpeed 9.lnk"="2/22/2017 9:23 AM, 1286 bytes, A Adds the file Auslogics Rescue Center.lnk"="2/22/2017 9:23 AM, 1203 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag Adds the file Auslogics Disk Defrag on the Web.url"="2/22/2017 9:20 AM, 126 bytes, A Adds the file Auslogics Disk Defrag.lnk"="2/22/2017 9:20 AM, 1293 bytes, A Adds the file Check Your PC Performance.url"="2/22/2017 9:20 AM, 161 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater Adds the file Auslogics Driver Updater on the Web.url"="2/22/2017 9:21 AM, 129 bytes, A Adds the file Auslogics Driver Updater.lnk"="2/22/2017 9:21 AM, 1333 bytes, A In the existing folder C:\Users\{username}\AppData\LocalLow\Microsoft\Internet Explorer\Services Adds the file search_{76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB}.ico"="2/22/2017 9:21 AM, 5430 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file Auslogics BoostSpeed 9.lnk"="2/22/2017 9:23 AM, 1262 bytes, A Adds the file Auslogics Disk Defrag.lnk"="2/22/2017 9:20 AM, 1269 bytes, A Adds the file Auslogics Driver Updater.lnk"="2/22/2017 9:21 AM, 1309 bytes, A Adds the folder C:\Windows\System32\Tasks\Auslogics\BoostSpeed Adds the file Scan and Repair"="2/22/2017 9:23 AM, 3962 bytes, A Adds the file Start BoostSpeed ?n {username} logon"="2/22/2017 9:23 AM, 3638 bytes, A Adds the folder C:\Windows\System32\Tasks\Auslogics\Driver Updater Adds the file Scan"="2/22/2017 9:21 AM, 4154 bytes, A Adds the file Start Driver Updater ?n {username} logon"="2/22/2017 9:21 AM, 3702 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\ATPopups\1.x\Settings] "FirstInitDate"="REG_BINARY, .... "LastPopupShow"="REG_BINARY, .... [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\BoostSpeed\9.x\Settings] "ActionCenter.LastUpdateTime"="REG_BINARY, .... "App.Application.FileName"="REG_SZ", "C:\Program Files (x86)\Auslogics\BoostSpeed\BoostSpeed.exe" "General.Cookie"="REG_SZ", "disk_defrag_free_stub" "General.CookieLastAction"="REG_SZ", "" "General.CountRun.BoostSpeed.exe"="REG_QWORD, .... "General.DefWebBrowser"="REG_SZ", "C:\Program Files\Internet Explorer\IEXPLORE.EXE" "General.InstallDateTime"="REG_BINARY, .... "General.Language"="REG_SZ", "ENU" "General.LastRun.BoostSpeed.exe"="REG_BINARY, .... "General.URLSource"="REG_SZ", "boost-speed-9" "GoogleAnalytics.InstallDate"="REG_BINARY, .... "Integrator.CheckNewVersionDate"="REG_BINARY, .... "Integrator.CheckNewVersionResult"="REG_DWORD", 1 "Integrator.CheckNewVersionServer"="REG_DWORD", 151060992 "Integrator.NeedEnableAutoTool"="REG_DWORD", 0 "Integrator.Products.LastUpload"="REG_BINARY, .... "Integrator.Selected.ComputerSpeed.Internet"="REG_DWORD", 1 "Integrator.Selected.ComputerSpeed.Registry"="REG_DWORD", 1 "Integrator.Selected.ComputerSpeed.Shutdown"="REG_DWORD", 1 "Integrator.Selected.ComputerSpeed.Windows"="REG_DWORD", 1 "Integrator.Selected.DiskSpace.AppFiles"="REG_DWORD", 1 "Integrator.Selected.DiskSpace.SystemFiles"="REG_DWORD", 1 "Integrator.Selected.DiskSpace.TempFiles"="REG_DWORD", 1 "Integrator.Selected.DiskSpace.WebCache"="REG_DWORD", 1 "Integrator.Selected.SystemStability.BrokenShortcuts"="REG_DWORD", 1 "Integrator.Selected.SystemStability.HelpFiles"="REG_DWORD", 1 "Integrator.Selected.SystemStability.MissingSoftware"="REG_DWORD", 1 "Integrator.Selected.SystemStability.SystemErrors"="REG_DWORD", 1 "InternetOptimizer.Connection.GUID"="REG_SZ", "{EDB0D6D8-B1F7-496F-A023-44DF7155F1CD}" "InternetOptimizer.Connection.LastDetectDateTime"="REG_BINARY, .... "Popups.LibraryInitDate"="REG_BINARY, .... "Popups.PopupResults.LastShow"="REG_BINARY, .... "Popups.UpdateConfig.LastDate"="REG_BINARY, .... "Popups.UpdateConfig.LastRegDate"="REG_BINARY, .... "Popups.UpdateConfig.LastResult"="REG_DWORD", 1 "Tools.TATToolGuardCPU.Options.IsStarted"="REG_DWORD", 1 "Tools.TATToolGuardRERAM.Options.IsStarted"="REG_DWORD", 1 "Tools.TATToolGuardRERAM.Options.MemoryBlockPower"="REG_DWORD", 5 "Tools.TATToolGuardRERAM.Options.MemoryPart"="REG_DWORD", 70 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\Disk Defrag\7.x\Settings] "DiskDefrag.General.TemperatureType"="REG_DWORD", 2 "DiskDefrag.Giveaway.LastUpload"="REG_BINARY, .... "DiskDefrag.MainForm.LinksPanelLastHintDate"="REG_QWORD, .... "DiskDefrag.MainForm.LinksPanelStdDefragHintShowed"="REG_DWORD", 1 "General.Cookie"="REG_SZ", "diskdefragfree" "General.CookieLastAction"="REG_SZ", "" "General.DefWebBrowser"="REG_SZ", "C:\Program Files\Internet Explorer\IEXPLORE.EXE" "General.InstallDateTime"="REG_BINARY, .... "General.Language"="REG_SZ", "ENU" "General.LastRun.DiskDefrag.exe"="REG_BINARY, .... "GoogleAnalytics.InstallDate"="REG_BINARY, .... [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\Driver Updater\1.x\Settings] "ActionCenter.LastUpdateTime"="REG_BINARY, .... "DriverUpdater.AdvertProductsLastUpload"="REG_BINARY, .... "DriverUpdater.InstallTime"="REG_BINARY, .... "DriverUpdater.UpdateDate"="REG_BINARY, .... "General.Cookie"="REG_SZ", "disk_defrag_du_last_step" "General.CookieLastAction"="REG_SZ", "" "General.DefWebBrowser"="REG_SZ", "C:\Program Files\Internet Explorer\IEXPLORE.EXE" "General.InstallDateTime"="REG_BINARY, .... "General.Language"="REG_SZ", "ENU" "General.LastRun.DriverUpdater.exe"="REG_BINARY, .... "GoogleAnalytics.InstallDate"="REG_BINARY, .... "Popups.Driver UpdaterScanResult.LastShow"="REG_BINARY, .... "Popups.LibraryInitDate"="REG_BINARY, .... "Popups.VersionCheck.LastDate"="REG_BINARY, .... "Popups.VersionCheck.LastRegDate"="REG_BINARY, .... "Popups.VersionCheck.LastResult"="REG_DWORD", 2 "Popups.VersionCheck.NewVersion"="REG_DWORD", 17368064 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\Google Analytics Package\1.x\Settings] "ClientID"="REG_SZ", "{1AB35469-3B2E-4A29-A9B5-C7A47B2971F1}" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\stub_installer_boost-speed\2.x\Settings] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Auslogics\stub_installer_driver-updater\2.x\Settings] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\BSD\DriverHiveEngine] "DriverIgnoreList"="REG_SZ", "" "DriverUploadList"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_is1] "Contact"="REG_SZ", "info@auslogics.com" "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Auslogics\Driver Updater\DriverUpdater.exe" "DisplayName"="REG_SZ", "Auslogics Driver Updater" "DisplayVersion"="REG_SZ", "1.9.3.0" "EstimatedSize"="REG_DWORD", 30272 "HelpLink"="REG_SZ", "http://www.auslogics.com/en/support/" "Inno Setup CodeFile: SplitTestCase"="REG_SZ", "0" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Auslogics\Driver Updater" "Inno Setup: Icon Group"="REG_SZ", "Auslogics\Driver Updater" "Inno Setup: Language"="REG_SZ", "enu" "Inno Setup: Setup Version"="REG_SZ", "5.5.6 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170222" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Auslogics\Driver Updater\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 9 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Auslogics Labs Pty Ltd" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Auslogics\Driver Updater\unins000.exe" /SILENT" "Readme"="REG_SZ", "http://www.auslogics.com/en/software/driver-updater/" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Auslogics\Driver Updater\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.auslogics.com/en/contact/" "URLUpdateInfo"="REG_SZ", "http://www.auslogics.com/en/checkforupdate/?product=driver-updater&version=1.9.3.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1] "Contact"="REG_SZ", "info@auslogics.com" "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Auslogics\BoostSpeed\BoostSpeed.exe" "DisplayName"="REG_SZ", "Auslogics BoostSpeed 9" "DisplayVersion"="REG_SZ", "9.1.2.0" "EstimatedSize"="REG_DWORD", 72203 "HelpLink"="REG_SZ", "http://www.auslogics.com/en/support/" "Inno Setup CodeFile: SplitTestCase"="REG_SZ", "0" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Auslogics\BoostSpeed" "Inno Setup: Icon Group"="REG_SZ", "Auslogics\BoostSpeed" "Inno Setup: Language"="REG_SZ", "enu" "Inno Setup: Setup Version"="REG_SZ", "5.5.6 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170222" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Auslogics\BoostSpeed\" "MajorVersion"="REG_DWORD", 9 "MinorVersion"="REG_DWORD", 1 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Auslogics Labs Pty Ltd" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Auslogics\BoostSpeed\unins000.exe" /SILENT" "Readme"="REG_SZ", "http://www.auslogics.com/en/software/boost-speed/" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Auslogics\BoostSpeed\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.auslogics.com/en/contact/" "URLUpdateInfo"="REG_SZ", "http://www.auslogics.com/en/checkforupdate/?product=boost-speed&version=9.1.2.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1] "Contact"="REG_SZ", "info@auslogics.com" "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Auslogics\Disk Defrag\DiskDefrag.exe" "DisplayName"="REG_SZ", "Auslogics Disk Defrag" "DisplayVersion"="REG_SZ", "7.1.1.0" "EstimatedSize"="REG_DWORD", 28459 "HelpLink"="REG_SZ", "http://www.auslogics.com/en/support/" "Inno Setup CodeFile: SplitTestCase"="REG_SZ", "0" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Auslogics\Disk Defrag" "Inno Setup: Icon Group"="REG_SZ", "Auslogics\Disk Defrag" "Inno Setup: Language"="REG_SZ", "enu" "Inno Setup: Setup Version"="REG_SZ", "5.5.6 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170222" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Auslogics\Disk Defrag\" "MajorVersion"="REG_DWORD", 7 "MinorVersion"="REG_DWORD", 1 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Auslogics Labs Pty Ltd" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Auslogics\Disk Defrag\unins000.exe" /SILENT" "Readme"="REG_SZ", "http://www.auslogics.com/en/software/disk-defrag/" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Auslogics\Disk Defrag\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.auslogics.com/en/contact/" "URLUpdateInfo"="REG_SZ", "http://www.auslogics.com/en/checkforupdate/?product=disk-defrag&version=7.1.1.0" [HKEY_CURRENT_USER\Software\BSD\PCZ] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "https://search.yahoo.com/?fr=vmn&type=auslog_yaapp1_hp" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB}] "DisplayName"="REG_SZ", "Yahoo" "FaviconPath"="REG_SZ", "C:\Users\{username}\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB}.ico" "FaviconUrl"="REG_SZ", "http://search.yahoo.com/favicon.ico" "SuggestionsURL"="REG_SZ", "http://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "https://search.yahoo.com/search/?toggle=1&cop=mss&ei=UTF-8&fr=vmn&type=auslog_yaapp1_ch&p={searchTerms}" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/22/17 Scan Time: 9:36 AM Logfile: mbamDiskDefragFree.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1322 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 361364 Time Elapsed: 2 min, 2 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 3 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKDEFRAG.EXE, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [2024], [341786],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\BOOSTSPEED.EXE, Quarantined, [2030], [341835],1.0.1322 Module: 76 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\VCLIMG160.BPL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKCLEANERHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\LOCALIZER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\RTL160.BPL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\VCL160.BPL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\VOLUMESHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DEBUGHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKDEFRAG.EXE, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\AXCOMPONENTSVCL.BPL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\COMMONFORMS.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\COMMONFORMS.SITE.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\AXCOMPONENTSRTL.BPL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\AXBROWSERS.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKWIPEHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\GOOGLEANALYTICSHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\SHELLEXTENSION.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\REPORTHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Quarantined, [2024], [341786],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\TASKSCHEDULERHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKDEFRAGHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\LOCALIZER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\AXCOMPONENTSRTL.BPL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\REGISTRYCLEANERHELPER.DLL, Quarantined, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\VCLIMG160.BPL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RTL160.BPL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\SYSTEMINFORMATIONHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATUPDATERSHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RESCUECENTERHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.SITE.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ACTIONCENTERHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATDRIVERUPDATER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DEBUGHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\VCLIMG160.BPL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERHIVEENGINE.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\VCL160.BPL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\AXCOMPONENTSRTL.BPL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\COMMONFORMS.SITE.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\RTL160.BPL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\AXCOMPONENTSVCL.BPL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ACTIONCENTERFORMS.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\LOCALIZER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATPOPUPSHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\TASKSCHEDULERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\VOLUMESHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\BOOSTSPEED.EXE, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATTOOLSEXTHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ACTIONCENTERFORMS.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\RESCUECENTERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\GOOGLEANALYTICSHELPER.DLL, Quarantined, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\AXCOMPONENTSVCL.BPL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\TWEAKMANAGERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATTOOLSSTDHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\GOOGLEANALYTICSHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ADVISORHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\COMMONFORMS.ROUTINE.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\VCL160.BPL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\REPORTHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\UNINSTALLMANAGERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\DISKCLEANERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\DISKDEFRAGHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\AXBROWSERS.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\INTERNETOPTIMIZERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ACTIONCENTERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SETUP\SETUPCUSTOM.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SPYWARECHECKERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATPOPUPSHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATUPDATERSHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\BROWSERCAREHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SERVICESOPTIMIZATIONTOOL.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\DEBUGHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\TRACKERASERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SYSTEMINFORMATIONHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\REGISTRYCLEANERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SQLITE3.DLL, Quarantined, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SERVICEMANAGERHELPER.DLL, Quarantined, [2030], [341835],1.0.1322 Registry Key: 57 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_is1, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\BCAgentCOM32.BCAgent32, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\APPID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\INTERFACE\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\InprocServer32, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\InprocServer32, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\CLSID\{93469602-4134-4012-A6BC-3E73B9855F90}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\BCAgentCOM64.BCAgent64, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\APPID\{93469602-4134-4012-A6BC-3E73B9855F90}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{93469602-4134-4012-A6BC-3E73B9855F90}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{93469602-4134-4012-A6BC-3E73B9855F90}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-863B4A40A1A1}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\INTERFACE\{3CC2E0D5-193C-4192-B8BA-C0B2C19C6B87}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3CC2E0D5-193C-4192-B8BA-C0B2C19C6B87}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3CC2E0D5-193C-4192-B8BA-C0B2C19C6B87}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-863B4A40A1A1}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{F2C6F7D1-ED32-49E5-9919-863B4A40A1A1}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\CLSID\{93469602-4134-4012-A6BC-3E73B9855F90}\InprocServer32, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\TMAgentCOM.TMAgent, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\APPID\{93469602-4134-4012-A6BC-D46FF1C671E9}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{93469602-4134-4012-A6BC-D46FF1C671E9}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{93469602-4134-4012-A6BC-D46FF1C671E9}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\INTERFACE\{6855F0CE-00B1-483F-8633-33B650EE4310}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6855F0CE-00B1-483F-8633-33B650EE4310}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{6855F0CE-00B1-483F-8633-33B650EE4310}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}\InprocServer32, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\DiskDoctorChecker.DiskChecker, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\APPID\{278029E0-2347-4254-A65E-204AC55E2508}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{278029E0-2347-4254-A65E-204AC55E2508}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{278029E0-2347-4254-A65E-204AC55E2508}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\TYPELIB\{FE9301D5-9266-4A2F-8767-85482115CAB0}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\INTERFACE\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FE9301D5-9266-4A2F-8767-85482115CAB0}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FE9301D5-9266-4A2F-8767-85482115CAB0}, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\CLASSES\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}\InprocServer32, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\AUSLOGICS\BoostSpeed, Delete-on-Reboot, [2030], [370959],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, HKLM\SOFTWARE\WOW6432NODE\AUSLOGICS\BoostSpeed, Delete-on-Reboot, [2030], [341837],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\WOW6432NODE\AUSLOGICS\Disk Defrag, Delete-on-Reboot, [2301], [350021],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\AUSLOGICS\Driver Updater, Delete-on-Reboot, [2024], [341776],1.0.1322 Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 28 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\IgnoredLists, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\Logs, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAMDATA\Auslogics\BoostSpeed, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Reports, Delete-on-Reboot, [2301], [350024],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Data, Delete-on-Reboot, [2301], [350024],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x, Delete-on-Reboot, [2301], [350024],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAMDATA\Auslogics\Disk Defrag, Delete-on-Reboot, [2301], [350024],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Auslogics\Driver Updater\1.x\Logs, Delete-on-Reboot, [2024], [341777],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Auslogics\Driver Updater\1.x, Delete-on-Reboot, [2024], [341777],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAMDATA\Auslogics\Driver Updater, Delete-on-Reboot, [2024], [341777],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\AUSLOGICS\DRIVER UPDATER, Delete-on-Reboot, [2024], [341779],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Setup, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Data, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\AUSLOGICS\DRIVER UPDATER, Delete-on-Reboot, [2024], [341781],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\AUSLOGICS\BOOSTSPEED, Delete-on-Reboot, [2030], [341834],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Setup, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Data, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\WINDOWS\SYSTEM32\TASKS\AUSLOGICS\BOOSTSPEED, Delete-on-Reboot, [2030], [341836],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\AUSLOGICS\Disk Defrag, Delete-on-Reboot, [2301], [350023],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Setup, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Data, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG, Delete-on-Reboot, [2301], [350025],1.0.1322 File: 204 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\IgnoredLists\TRE_User.igl, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\Logs\BoostSpeedLogic.log, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\Logs\InternetOptimizerStatistics.log, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\Logs\TweakManagerStatistics.log, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Auslogics\BoostSpeed\9.x\StatDB.json, Delete-on-Reboot, [2030], [341833],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Data\giveaway.json, Delete-on-Reboot, [2301], [350024],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Auslogics\Disk Defrag\7.x\Data\giveaway.png, Delete-on-Reboot, [2301], [350024],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Auslogics\Driver Updater\1.x\Logs\DriverHiveEngine_0.log, Delete-on-Reboot, [2024], [341777],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Auslogics\Driver Updater\1.x\StatDB.json, Delete-on-Reboot, [2024], [341777],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\VCLIMG160.BPL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKCLEANERHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\LOCALIZER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\RTL160.BPL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\VCL160.BPL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\VOLUMESHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DEBUGHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKDEFRAG.EXE, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\AXCOMPONENTSVCL.BPL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\COMMONFORMS.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\COMMONFORMS.SITE.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\AXCOMPONENTSRTL.BPL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\AXBROWSERS.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKWIPEHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\GOOGLEANALYTICSHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\SHELLEXTENSION.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\REPORTHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERUPDATER.EXE, Delete-on-Reboot, [2024], [341786],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\TASKSCHEDULERHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\DISKDEFRAGHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\LOCALIZER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\AXCOMPONENTSRTL.BPL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\PROGRAM FILES (X86)\AUSLOGICS\DISK DEFRAG\REGISTRYCLEANERHELPER.DLL, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\VCLIMG160.BPL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RTL160.BPL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\SYSTEMINFORMATIONHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATUPDATERSHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\RESCUECENTERHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\COMMONFORMS.SITE.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ACTIONCENTERHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATDRIVERUPDATER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DEBUGHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\VCLIMG160.BPL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\DRIVERHIVEENGINE.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\VCL160.BPL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\AXCOMPONENTSRTL.BPL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\COMMONFORMS.SITE.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\RTL160.BPL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\AXCOMPONENTSVCL.BPL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ACTIONCENTERFORMS.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\LOCALIZER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\ATPOPUPSHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\TASKSCHEDULERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\VOLUMESHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\BOOSTSPEED.EXE, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATTOOLSEXTHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ACTIONCENTERFORMS.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\RESCUECENTERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\GOOGLEANALYTICSHELPER.DLL, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\AXCOMPONENTSVCL.BPL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\TWEAKMANAGERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATTOOLSSTDHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\GOOGLEANALYTICSHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ADVISORHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\COMMONFORMS.ROUTINE.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\VCL160.BPL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\REPORTHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\UNINSTALLMANAGERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\DISKCLEANERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\DISKDEFRAGHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\AXBROWSERS.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\INTERNETOPTIMIZERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ACTIONCENTERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SETUP\SETUPCUSTOM.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SPYWARECHECKERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATPOPUPSHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\ATUPDATERSHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\BROWSERCAREHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SERVICESOPTIMIZATIONTOOL.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\DEBUGHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\TRACKERASERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SYSTEMINFORMATIONHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\REGISTRYCLEANERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SQLITE3.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\PROGRAM FILES (X86)\AUSLOGICS\BOOSTSPEED\SERVICEMANAGERHELPER.DLL, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater\Auslogics Driver Updater on the Web.url, Delete-on-Reboot, [2024], [341779],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater\Auslogics Driver Updater.lnk, Delete-on-Reboot, [2024], [341779],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Setup\SetupCustom.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Data\main.ini, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Data\products.json, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\deu.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\enu.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\esp.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\fra.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\ita.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\jpn.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\Lang\rus.lng, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\ATToolsExtHelper.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\ATToolsStdHelper.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\SendDebugLog.exe, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\ServiceManagerHelper.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\sqlite3.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\unins000.dat, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\unins000.exe, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\unins000.msg, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\VolumesHelper.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\CommonForms.Routine.dll, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\DPInst32.exe, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\DPInst64.exe, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\EULA.rtf, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater\GASender.exe, Delete-on-Reboot, [2024], [341780],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Windows\System32\Tasks\Auslogics\Driver Updater\Scan, Delete-on-Reboot, [2024], [341781],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\Windows\System32\Tasks\Auslogics\Driver Updater\Start Driver Updater \u00d0\u00ben {username} logon, Delete-on-Reboot, [2024], [341781],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed\Auslogics BoostSpeed 9 on the Web.url, Delete-on-Reboot, [2030], [341834],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed\Auslogics BoostSpeed 9.lnk, Delete-on-Reboot, [2030], [341834],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed\Auslogics Rescue Center.lnk, Delete-on-Reboot, [2030], [341834],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\deu.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\enu.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\esp.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\fra.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\ita.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\jpn.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Lang\rus.lng, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Data\Applications.dat, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Data\main.ini, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\Data\products.json, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\InternetOptimizer.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\ndefrg32.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\ndefrg64.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\rdboot32.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\rdboot64.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\RegistryCleaner.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\RegistryDefrag.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\RegistryDefragHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\RescueCenter.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\RescueCenterForm.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\SendDebugLog.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\ShellExtension.ContextMenu.x32.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\ShellExtension.ContextMenu.x64.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\ShellExtension.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\StartupManager.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\StartupManagerHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\SystemInformation.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\TaskManager.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\BrowserCareHelper.Agent.x32.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\BrowserCareHelper.Agent.x64.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\cdefrag.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\CommonForms.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\TaskManagerHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\TweakManager.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\unins000.dat, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\unins000.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\unins000.msg, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\UninstallManager.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\GASender.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\TaskManagerHelper.Agent.x64.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskDefrag.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskDoctor.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskDoctorChecker.x64.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskDoctorHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskExplorer.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskExplorerHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DiskWipeHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DSSrcAsync.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DSSrcWM.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DuplicateFileFinder.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\DuplicateFileFinderHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\EULA.rtf, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\FileRecovery.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\FileRecoveryHelper.dll, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\FileShredder.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Program Files (x86)\Auslogics\BoostSpeed\FreeSpaceWiper.exe, Delete-on-Reboot, [2030], [341835],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Windows\System32\Tasks\Auslogics\BoostSpeed\Scan and Repair, Delete-on-Reboot, [2030], [341836],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\Windows\System32\Tasks\Auslogics\BoostSpeed\Start BoostSpeed \u00d0\u00ben {username} logon, Delete-on-Reboot, [2030], [341836],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag\Auslogics Disk Defrag on the Web.url, Delete-on-Reboot, [2301], [350023],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag\Auslogics Disk Defrag.lnk, Delete-on-Reboot, [2301], [350023],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Disk Defrag\Check Your PC Performance.url, Delete-on-Reboot, [2301], [350023],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\deu.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\enu.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\esp.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\fra.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\ita.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\jpn.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Lang\rus.lng, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Data\main.ini, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\Setup\SetupCustom.dll, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\cdefrag.exe, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\CommonForms.Routine.dll, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\EULA.rtf, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\GASender.exe, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\ndefrg32.exe, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\ndefrg64.exe, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\SendDebugLog.exe, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\ShellExtension.ContextMenu.x32.dll, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\ShellExtension.ContextMenu.x64.dll, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\sqlite3.dll, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\unins000.dat, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\unins000.exe, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\Program Files (x86)\Auslogics\Disk Defrag\unins000.msg, Delete-on-Reboot, [2301], [350025],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\USERS\{username}\DESKTOP\DISK-DEFRAG-SETUP.EXE, Delete-on-Reboot, [2301], [353217],1.0.1322 PUP.Optional.AuslogicsDiskDefrag, C:\USERS\{username}\DESKTOP\AUSLOGICS DISK DEFRAG.LNK, Delete-on-Reboot, [2301], [350022],1.0.1322 PUP.Optional.AuslogicsBoostSpeed, C:\USERS\{username}\DESKTOP\AUSLOGICS BOOSTSPEED 9.LNK, Delete-on-Reboot, [2030], [342026],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\USERS\{username}\DESKTOP\AUSLOGICS DRIVER UPDATER.LNK, Delete-on-Reboot, [2024], [341778],1.0.1322 PUP.Optional.AuslogicsDriverUpdater, C:\USERS\{username}\APPDATA\LOCAL\TEMP\IS-OT2B7.TMP\DRIVER_UPDATER_STUB_INSTALLER.EXE, Delete-on-Reboot, [2024], [341786],1.0.1322 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  4. What is AllInOneDocs? The Malwarebytes research team has determined that AllInOneDocs is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. AllInOneDocs is a Mindspark/Ask toolbar now known as IAC Applications. How do I know if my computer is affected by AllInOneDocs? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browsers: How did AllInOneDocs get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove AllInOneDocs? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of AllInOneDocs? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the AllInOneDocs entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the AllInOneDocs hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/allinonedocs/ttab02/index.html?n={n1}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/allinonedocs/ttab02/index.html?coId={coid2}&subId&ln=en&n={n2}&ptb={ptb2}&st=tab&p2={p22}&si FF Extension: AllInOneDocs - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_iwMembers_@free.allinonedocs.com [2017-02-21] CHR Extension: (AllInOneDocs) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm [2017-02-21] C:\Users\{username}\AppData\Local\AllInOneDocsTooltab AllInOneDocs Internet Explorer Homepage and New Tab (HKCU\...\AllInOneDocsTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/21/17 Scan Time: 9:14 AM Logfile: mbamAllInOneDocs.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1314 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 361007 Time Elapsed: 1 min, 32 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\ALLINONEDOCSTOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [341], [301125],1.0.1314 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\AllInOneDocsTooltab Uninstall Internet Explorer, Delete-on-Reboot, [341], [301125],1.0.1314 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [341], [293497],1.0.1314 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\AllInOneDocsTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [341], [352442],1.0.1314 Data Stream: 0 (No malicious items detected) Folder: 90 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL EXTENSION SETTINGS\JJNJENBCNPIKFEPKIJMDHIMFCEIOGKGM, Delete-on-Reboot, [341], [371658],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\AllInOneDocsTooltab, Delete-on-Reboot, [1050], [356944],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\META-INF, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\chrome, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_IWMEMBERS_@FREE.ALLINONEDOCS.COM, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\abstractbutton\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\thirdparty\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\uninstall\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\weather\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\weather\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\weather\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\generic\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\alert\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\link\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\weather, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\abstractbutton, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\rss\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\rss\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare\icons, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\images, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\rss, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\radioWrapper, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\thirdparty, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\foreground, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\uninstall, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\generic, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\weather, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\background, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\alert, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\link, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\rss, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\window, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\adapter, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\libs, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\_metadata, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JJNJENBCNPIKFEPKIJMDHIMFCEIOGKGM, Delete-on-Reboot, [341], [301932],1.0.1314 File: 294 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\ALLINONEDOCSTOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [341], [301125],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjnjenbcnpikfepkijmdhimfceiogkgm\000003.log, Delete-on-Reboot, [341], [371658],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjnjenbcnpikfepkijmdhimfceiogkgm\CURRENT, Delete-on-Reboot, [341], [371658],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjnjenbcnpikfepkijmdhimfceiogkgm\LOCK, Delete-on-Reboot, [341], [371658],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjnjenbcnpikfepkijmdhimfceiogkgm\LOG, Delete-on-Reboot, [341], [371658],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jjnjenbcnpikfepkijmdhimfceiogkgm\MANIFEST-000001, Delete-on-Reboot, [341], [371658],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [319354],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1050], [356946],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_allinonedocs.dl.myway.com_0.localstorage, Delete-on-Reboot, [341], [240305],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_allinonedocs.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [341], [240305],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_allinonedocs.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [341], [240306],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_allinonedocs.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [341], [240306],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\chrome-extension_jjnjenbcnpikfepkijmdhimfceiogkgm_0.localstorage, Delete-on-Reboot, [341], [371665],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\chrome-extension_jjnjenbcnpikfepkijmdhimfceiogkgm_0.localstorage-journal, Delete-on-Reboot, [341], [371665],1.0.1314 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_IWMEMBERS_@FREE.ALLINONEDOCS.COM\BOOTSTRAP.JS, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\chrome\ffxtbr.jar, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\META-INF\manifest.mf, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\META-INF\mozilla.rsa, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\META-INF\mozilla.sf, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\chrome.manifest, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\chrome.manifest.restartless, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_iwMembers_@free.allinonedocs.com\install.rdf, Delete-on-Reboot, [1050], [371671],1.0.1314 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JJNJENBCNPIKFEPKIJMDHIMFCEIOGKGM\12.202.10.29174_0\MANIFEST.JSON, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\menu\README.txt, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\bs.30.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\common.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\dynamic.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\enableDetect.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\global.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\messageEventListener.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\navRedirector.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\paramReplacer.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\PartnerId.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\set.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\foreground\button.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\background\searchBox.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\css\supertab.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\html\supertab.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js\reporting.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js\supertab.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\components\supertab\js\__utm.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\arrowSprite.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\icon128.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\icon16.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\icon19disabled.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\icon19on.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\icon48.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\231968512.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\231968524.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\231968525.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\231968576.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\231968593.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\down_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\magnifying_glass.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\search_button.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\tvf_icon_guide.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\tvf_logo.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\images\wrench.png, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\newTabInitialize.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\chromeStorage.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\chromeUtils.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\companionSWUtils.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\exeManager.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\exeManagerNMD.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\exePackageManager.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\focusManager.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\globalBlacklistManager.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\messaging.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\mutation_summary-min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\mutation_summary.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\newTabInfo.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\options.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\readLocalStorage.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\reservespaceifenabled.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\scriptInjector.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\searchContext.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\settingsOverrides.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\toolbarCookieParser.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\toolbarPreinit.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\URILoaderContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\webTooltabAPI.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\Widget.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\widgetFactory.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\js\widgetWindowManager.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\cache.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\ce.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\debug.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\native\ss.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\activePing.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\buttonLogger.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\competitorDnsList.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\console.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\httpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\HttpURL.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\internationalSearch.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\rsvp-latest.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\testHttpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\unifiedLogger.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\universalConsole.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\shared\utils.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\_metadata\computed_hashes.json, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\_metadata\verified_contents.json, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spent.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\bg.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\buildVars, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\buildVars.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\companionSW.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\config.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\contentScript.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\contentScript.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\debug.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\debug.jade, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\extension_toolbar_api.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\initWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\newTabContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\options.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spent.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spent.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spent2.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spent2.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spentJ.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spentK.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\spentK.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\startup.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\stub.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\stubby.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\superFrame.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\toolbar.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\toolbar.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\toolbarUI.css, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\toolbarUI.html, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\toolbarUI.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\url.js, Delete-on-Reboot, [341], [301932],1.0.1314 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjnjenbcnpikfepkijmdhimfceiogkgm\12.202.10.29174_0\webtooltab.cs.js, Delete-on-Reboot, [341], [301932],1.0.1314 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  5. What is Youndoo? The Malwarebytes research team has determined that Youndoo is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. This version of the Youndoo search hijacker adds an extra Firefox profile and uses a Scheduled Task to re-infect or update the infection. How do I know if my computer is affected by Youndoo? You may see this entry in your list of installed software: this new startpage in the affected browsers: ] these Scheduled Tasks: and you may see this type of advertisements: How did Youndoo get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software. How do I remove Youndoo? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Youndoo? This adware creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. Follow the instructions posted here to remove the fake Firefox profile. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Youndoo hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to some of their domains: Technical details for experts Possible signs in FRST logs: HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 ShellExecuteHooks: - {5AD340E8-F445-11E6-B566-64006A5CFC23} - C:\Program Files (x86)\Thuluch\Reuqutain.dll [146432 2017-02-20] () FF NewTab: hxxp://www.youndoo.com/?z={z1}&from=wak&uid={uid1}&type=hp FF DefaultSearchEngine: youndoo FF SelectedSearchEngine: youndoo FF Homepage: hxxp://www.youndoo.com/?z={z1}&from=wak&uid={uid1}&type=hp FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\mhc384j1.default\searchplugins\jebnkuvk.xml [2017-02-20] CHR HomePage: ChromeDefaultData2 -> hxxp://www.youndoo.com/?z={z1}&from=wak&uid={uid1}&type=hp CHR StartupUrls: ChromeDefaultData2 -> "hxxp://www.youndoo.com/?z={z1}&from=wak&uid={uid1}&type=hp" CHR DefaultSearchURL: ChromeDefaultData2 -> hxxp://www.youndoo.com/search/?q={searchTerms}&z={z1}&from=wak&uid={uid1}&type=sp CHR DefaultSearchKeyword: ChromeDefaultData2 -> youndoo C:\Users\{username}\AppData\Local\Gunelejahidom C:\Program Files (x86)\Thuluch C:\WINDOWS\System32\Tasks\Nimasy Engine C:\WINDOWS\System32\Tasks\Gfakdutoing C:\Program Files (x86)\Nimasy Engine youndoo - Uninstall (HKLM-x32\...\{92C91B86-B20E-474B-A1D9-6B7D5AC229C4}) (Version: - ) Task: {17E1E42D-FDE0-4335-977B-6DFA92F053ED} - System32\Tasks\Gfakdutoing => /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u={uid1}&amp;v=2017220 /q Task: {40A77D42-8C8A-4FA2-8C4E-51FBC532FD30} - System32\Tasks\Nimasy Engine => C:\Program Files (x86)\Thuluch\plejither.exe [2017-02-20] (Glarysoft Ltd) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Nimasy Engine Adds the folder C:\Program Files (x86)\Thuluch Adds the file ClearData.exe"="2/20/2017 1:42 PM, 169664 bytes, A Adds the file CrashReport.dll"="2/20/2017 1:42 PM, 121344 bytes, A Adds the file mglobal.dll"="2/20/2017 1:42 PM, 112128 bytes, A Adds the file plejither.exe"="2/20/2017 1:42 PM, 1027000 bytes, A Adds the file Reuqutain.dll"="2/20/2017 1:42 PM, 146432 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Gfakdutoing"="2/20/2017 1:42 PM, 5128 bytes, A Adds the file Nimasy Engine"="2/20/2017 1:42 PM, 6030 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AD340E8-F445-11E6-B566-64006A5CFC23}\InProcServer32] "(Default)"="REG_SZ", "C:\Program Files (x86)\Thuluch\Reuqutain.dll" "ThreadingModel"="REG_SZ", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft] "help"="REG_SZ", "http://www.youndoo.com/?z={z1}&from=wak&uid={uid1}&type=hp" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AD340E8-F445-11E6-B566-64006A5CFC23}"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] "EnableShellExecuteHooks"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\{84416237-6490-494D-9AD6-4994DD978971}] "chd"="REG_SZ", "C:\Users\{username}\AppData\Local\Gunelejahidom" "ffd"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Profiles\Gherluwardcoozeied.default" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cherlaghphaige] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Gouwardguzele] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92C91B86-B20E-474B-A1D9-6B7D5AC229C4}] "DisplayName"="REG_SZ", "youndoo - Uninstall" "UninstallString"="REG_SZ", "C:\Program Files (x86)\Thuluch\plejither.exe 29be9ce7-f8b2-42b3-b0a4-32c68378402a "/k={92C91B86-B20E-474B-A1D9-6B7D5AC229C4}"" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\msServer] "(Default)"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\plejither.exe] "(Default)"="REG_SZ", "2017220" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\TaskInj] "(Default)"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\xvb`lj] "day"="REG_SZ", "20170220" "upday"="REG_SZ", "20170220" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\youndooSoftware\youndoohp] "oem"="REG_SZ", "wak" "Time"="REG_DWORD", 1487594583 [HKEY_LOCAL_MACHINE\SOFTWARE\xvb`lj] "day"="REG_SZ", "20170220" "upday"="REG_SZ", "20170220" [HKEY_USERS\.DEFAULT\Software\xvb`lj] "day"="REG_SZ", "20170220" "upday"="REG_SZ", "20170220" Malwarebytes log: {computername} www.{computername}.com -Log Details- Scan Date: 2/20/17 Scan Time: 2:10 PM Logfile: mbamYoundoo.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.50 Update Package Version: 1.0.1307 License: Premium -System Information- OS: Windows 10 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 420585 Time Elapsed: 8 min, 58 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 4 Adware.Elex.Generic, HKLM\SOFTWARE\CLASSES\CLSID\{5AD340E8-F445-11E6-B566-64006A5CFC23}, Delete-on-Reboot, [2155], [356410],1.0.1307 Adware.Elex.Generic, HKLM\SOFTWARE\CLASSES\CLSID\{5AD340E8-F445-11E6-B566-64006A5CFC23}\InprocServer32, Delete-on-Reboot, [2155], [356410],1.0.1307 PUP.Optional.Youndoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{92C91B86-B20E-474B-A1D9-6B7D5AC229C4}, Delete-on-Reboot, [767], [182916],1.0.1307 PUP.Optional.Youndoo, HKLM\SOFTWARE\WOW6432NODE\youndooSoftware, Delete-on-Reboot, [767], [182849],1.0.1307 Registry Value: 4 Adware.Elex.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS|{5AD340E8-F445-11E6-B566-64006A5CFC23}, Delete-on-Reboot, [2155], [356410],1.0.1307 Adware.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS, Delete-on-Reboot, [357], [-1],0.0.0 Adware.Elex.SHHKRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS, Delete-on-Reboot, [357], [-1],0.0.0 PUP.Optional.Youndoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{92C91B86-B20E-474B-A1D9-6B7D5AC229C4}|DISPLAYNAME, Delete-on-Reboot, [767], [182916],1.0.1307 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 3 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default, Delete-on-Reboot, [2786], [363173],1.0.1307 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles, Delete-on-Reboot, [2786], [363173],1.0.1307 PUP.Optional.FakeFFProfile, C:\USERS\{username}\APPDATA\ROAMING\Mozilla\Firefox\naweriweentcofise, Delete-on-Reboot, [2786], [363173],1.0.1307 File: 22 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\prefs.js, Delete-on-Reboot, [2786], [363173],1.0.1307 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\profiles.ini, Delete-on-Reboot, [2786], [363173],1.0.1307 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\search-metadata.json, Delete-on-Reboot, [2786], [363173],1.0.1307 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\search.json.mozlz4, Delete-on-Reboot, [2786], [363173],1.0.1307 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\THULUCH\REUQUTAIN.DLL, Delete-on-Reboot, [2155], [356410],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\PREFS.JS, Replaced, [767], [324487],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [767], [302817],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [767], [302817],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [767], [302817],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [767], [302817],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [767], [302817],1.0.1307 Adware.Elex, C:\USERS\{username}\DESKTOP\WAK_MY.EXE, Delete-on-Reboot, [305], [363419],1.0.1307 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GHERLUWARDCOOZEIED.DEFAULT\SEARCHPLUGINS\JEBNKUVK.XML, Delete-on-Reboot, [767], [324489],1.0.1307 Adware.Elex.SHHKRST, C:\PROGRAM FILES (X86)\THULUCH\CRASHREPORT.DLL, Delete-on-Reboot, [357], [372356],1.0.1307 Adware.Elex.SHHKRST, C:\WINDOWS\SYSTEM32\TASKS\Gfakdutoing, Delete-on-Reboot, [357], [-1],0.0.0 PUP.Optional.Youndoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\SEARCHPLUGINS\JEBNKUVK.XML, Delete-on-Reboot, [767], [302734],1.0.1307 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  6. What is SystemBoosterPro? The Malwarebytes research team has determined that SystemBoosterPro is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with SystemBoosterPro? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, startmenu, and on your desktop: and see this type of warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: How did SystemBoosterPro get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove SystemBoosterPro? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of SystemBoosterPro? No, Malwarebytes removes SystemBoosterPro completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the SystemBoosterPro installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\SystemBoosterPro\SystemBoosterPro.exe C:\Users\{username}\Desktop\SystemBoosterPro.lnk C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro C:\Program Files (x86)\SystemBoosterPro SystemBoosterPro (HKLM-x32\...\SystemBoosterPro) (Version: 38.1 - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\SystemBoosterPro Adds the file SystemBoosterPro.exe"="8/31/2016 3:37 PM, 5059072 bytes, A Adds the file uninst.exe"="2/17/2017 8:52 AM, 63459 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro Adds the file SystemBoosterPro.lnk"="2/17/2017 8:52 AM, 1139 bytes, A Adds the file Uninstall.lnk"="2/17/2017 8:52 AM, 872 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file SystemBoosterPro.lnk"="2/17/2017 8:52 AM, 1103 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SystemBoosterPro.exe] "(Default)"="REG_SZ", "C:\Program Files (x86)\SystemBoosterPro\SystemBoosterPro.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SystemBoosterPro] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\SystemBoosterPro\SystemBoosterPro.exe" "DisplayName"="REG_SZ", "SystemBoosterPro" "DisplayVersion"="REG_SZ", "38.1" "NSIS:Language"="REG_SZ", "1033" "Publisher"="REG_SZ", "" "UninstallString"="REG_SZ", "C:\Program Files (x86)\SystemBoosterPro\uninst.exe" "URLInfoAbout"="REG_SZ", "" [HKEY_CURRENT_USER\Software\SystemBoosterPro] "Activated"="REG_DWORD", 0 "AutoRun"="REG_DWORD", 0 "BackupDir"="REG_SZ", "Backup\" "CloseToTray"="REG_DWORD", 1 "ErrFixed"="REG_DWORD", 0 "ErrFound"="REG_DWORD", 0 "IDLang"="REG_DWORD", 0 "InstallID"="REG_SZ", "8DF622D99DD30679E0A274C4045DFFA8" "LastFixDatei"="REG_BINARY, .... "LastScanDatei"="REG_BINARY, .... "Partner"="REG_SZ", "" "PhSuppNum"="REG_SZ", "" "ProxyHost"="REG_SZ", "" "ProxyLogin"="REG_SZ", "" "ProxyPassw"="REG_SZ", "" "ProxyPort"="REG_SZ", "" "SerialNum"="REG_SZ", "" "Subtrack"="REG_SZ", "" "UseProxy"="REG_DWORD", 0 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/17/17 Scan Time: 9:04 AM Logfile: mbamSystemBoosterPro.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1284 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360483 Time Elapsed: 2 min, 5 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SYSTEMBOOSTERPRO\SYSTEMBOOSTERPRO.EXE, Quarantined, [1890], [369662],1.0.1284 Module: 1 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SYSTEMBOOSTERPRO\SYSTEMBOOSTERPRO.EXE, Quarantined, [1890], [369662],1.0.1284 Registry Key: 1 PUP.Optional.oTweak, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SystemBoosterPro, Delete-on-Reboot, [1890], [334912],1.0.1284 Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SystemBoosterPro, Delete-on-Reboot, [1890], [334912],1.0.1284 PUP.Optional.oTweak, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SYSTEMBOOSTERPRO, Delete-on-Reboot, [1890], [369661],1.0.1284 File: 6 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\SYSTEMBOOSTERPRO\SYSTEMBOOSTERPRO.EXE, Delete-on-Reboot, [1890], [369662],1.0.1284 PUP.Optional.oTweak, C:\Program Files (x86)\SystemBoosterPro\uninst.exe, Delete-on-Reboot, [1890], [334912],1.0.1284 PUP.Optional.oTweak, C:\USERS\{username}\DESKTOP\SYSTEMBOOSTERPRO.LNK, Delete-on-Reboot, [1890], [334910],1.0.1284 PUP.Optional.oTweak, C:\USERS\{username}\DESKTOP\SYSTEMBOOSTERPRO.EXE, Delete-on-Reboot, [1890], [369662],1.0.1284 PUP.Optional.oTweak, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro\SystemBoosterPro.lnk, Delete-on-Reboot, [1890], [369661],1.0.1284 PUP.Optional.oTweak, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemBoosterPro\Uninstall.lnk, Delete-on-Reboot, [1890], [369661],1.0.1284 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  7. What is SoftPlanet Update Manager? The Malwarebytes research team has determined that SoftPlanet Update Manager is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by SoftPlanet Update Manager? You may see these warnings during install: this icon on your desktop and in your startmenu: You may see this entry in your list of installed programs: and this entry in your Scheduled Tasks: This is the main screen of the program: How did SoftPlanet Update Manager get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove SoftPlanet Update Manager? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of SoftPlanet Update Manager? No, Malwarebytes removes SoftPlanet Update Manager completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the SoftPlanet Update Manager adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks some of the connections the installer tries to make: Technical details for experts Possible signs in FRST logs: (Secure Download Ltd.) C:\Program Files (x86)\SoftPlanet Software Assistant\spassist.exe C:\Windows\System32\Tasks\SoftPlanet Software Assistant C:\Users\{username}\AppData\Local\SoftPlanet C:\Users\Public\Desktop\SoftPlanet Software Assistant.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPlanet Software Assistant C:\Program Files (x86)\SoftPlanet Software Assistant SoftPlanet Software Assistant version 1.19 (HKLM-x32\...\{C87BD92A-FDDE-42C5-84F7-5159BEC08A01}_is1) (Version: 1.19 - Secure Download Ltd.) Task: {EC535BD8-953E-4497-BCE7-71C730BD2C6D} - System32\Tasks\SoftPlanet Software Assistant => C:\Program Files (x86)\SoftPlanet Software Assistant\spassist.exe [2013-12-09] (Secure Download Ltd.) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\SoftPlanet Software Assistant Adds the file spassist.exe"="12/9/2013 6:12 PM, 4511072 bytes, A Adds the file unins000.dat"="2/16/2017 8:41 AM, 9422 bytes, A Adds the file unins000.exe"="2/16/2017 8:41 AM, 718497 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPlanet Software Assistant Adds the file SoftPlanet Software Assistant.lnk"="2/16/2017 8:41 AM, 1172 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant Adds the file latest.xml"="2/16/2017 8:41 AM, 2480 bytes, A Adds the file lr.xml"="2/16/2017 8:41 AM, 1201 bytes, A Adds the file prev.xml"="2/16/2017 8:41 AM, 2480 bytes, A Adds the file recom.xml"="2/16/2017 8:41 AM, 1250 bytes, A Adds the file table.html"="2/16/2017 8:41 AM, 16345 bytes, A Adds the file template.html"="2/16/2017 8:41 AM, 13847 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file SoftPlanet Software Assistant.lnk"="2/16/2017 8:41 AM, 1154 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file SoftPlanet Software Assistant"="2/16/2017 8:41 AM, 3320 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C87BD92A-FDDE-42C5-84F7-5159BEC08A01}_is1] "DisplayName"="REG_SZ", "SoftPlanet Software Assistant version 1.19" "DisplayVersion"="REG_SZ", "1.19" "EstimatedSize"="REG_DWORD", 5095 "HelpLink"="REG_SZ", "http://www.softplanet.com/" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\SoftPlanet Software Assistant" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "SoftPlanet Software Assistant" "Inno Setup: Language"="REG_SZ", "english" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon" "Inno Setup: Setup Version"="REG_SZ", "5.5.4 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170216" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\SoftPlanet Software Assistant\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 19 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Secure Download Ltd." "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.softplanet.com/" "URLUpdateInfo"="REG_SZ", "http://www.softplanet.com/" [HKEY_CURRENT_USER\Software\SoftPlanet\Software Assistant] "CID"="REG_SZ", "FFC59ABF-9501-44E4-8A8B-DAA6A431C9D1" "FirstRun"="REG_SZ", "No" "InstallDate"="REG_SZ", "2/16/2017 8:41:20 AM" "LastFetch"="REG_SZ", "2/16/2017 8:41:20 AM" "LastNotify"="REG_SZ", "1/17/2017 8:41:20 AM" "ref"="REG_SZ", "sa" "Version"="REG_SZ", "1.19" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/16/17 Scan Time: 8:47 AM Logfile: mbamSoftplanet.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1274 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360268 Time Elapsed: 1 min, 32 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SOFTPLANET SOFTWARE ASSISTANT\SPASSIST.EXE, Quarantined, [2862], [181161],1.0.1274 Module: 1 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SOFTPLANET SOFTWARE ASSISTANT\SPASSIST.EXE, Quarantined, [2862], [181161],1.0.1274 Registry Key: 4 PUP.Optional.SecureDownload, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C87BD92A-FDDE-42C5-84F7-5159BEC08A01}_is1, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SoftPlanet Software Assistant, Delete-on-Reboot, [2862], [370771],1.0.1274 PUP.Optional.SecureDownload, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EC535BD8-953E-4497-BCE7-71C730BD2C6D}, Delete-on-Reboot, [2862], [370772],1.0.1274 PUP.Optional.SecureDownload, HKCU\SOFTWARE\SOFTPLANET\Software Assistant, Delete-on-Reboot, [2862], [251994],1.0.1274 Registry Value: 1 PUP.Optional.SecureDownload, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EC535BD8-953E-4497-BCE7-71C730BD2C6D}|PATH, Delete-on-Reboot, [2862], [370772],1.0.1274 Data Stream: 0 (No malicious items detected) Folder: 4 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SoftPlanet Software Assistant, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SOFTPLANET SOFTWARE ASSISTANT, Delete-on-Reboot, [2862], [181176],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\USERS\{username}\APPDATA\LOCAL\SOFTPLANET, Delete-on-Reboot, [2862], [251888],1.0.1274 File: 12 PUP.Optional.SecureDownload, C:\PROGRAM FILES (X86)\SOFTPLANET SOFTWARE ASSISTANT\SPASSIST.EXE, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.dat, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\Program Files (x86)\SoftPlanet Software Assistant\unins000.exe, Delete-on-Reboot, [2862], [181161],1.0.1274 PUP.Optional.SecureDownload, C:\USERS\PUBLIC\DESKTOP\SOFTPLANET SOFTWARE ASSISTANT.LNK, Delete-on-Reboot, [2862], [251887],1.0.1274 PUP.Optional.SecureDownload, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftPlanet Software Assistant\SoftPlanet Software Assistant.lnk, Delete-on-Reboot, [2862], [181176],1.0.1274 PUP.Optional.SecureDownload, C:\USERS\{username}\APPDATA\LOCAL\SOFTPLANET\SOFTWARE ASSISTANT\TABLE.HTML, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\latest.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\lr.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\prev.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\recom.xml, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\Users\{username}\AppData\Local\SoftPlanet\Software Assistant\template.html, Delete-on-Reboot, [2862], [251888],1.0.1274 PUP.Optional.SecureDownload, C:\WINDOWS\SYSTEM32\TASKS\SOFTPLANET SOFTWARE ASSISTANT, Delete-on-Reboot, [2862], [251889],1.0.1274 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  8. What is Your Instant Email? The Malwarebytes research team has determined that Your Instant Email is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. Your Instant Email is a member of the Spigot family as described in the blogpost Spigot browser hijackers. How do I know if my computer is affected by Your Instant Email? You may see this Firefox extension: this new default search provider in Internet Explorer: and this entry in your list of installed software: You may also see these warnings during install: and this new startpage in the affected browser(s): How did Your Instant Email get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove Your Instant Email? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Your Instant Email? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the Your Instant Email entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Your Instant Email hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yourinstantemail.com/?source=tt&uid={uid1}&uc=20170215&ap=&i_id=email__1.30 SearchScopes: HKCU -> DefaultScope {3FE479AA-6079-437A-913F-2FB27F48B31A} URL = hxxp://search.yourinstantemail.com/s?source=tt-bb8&uid={uid1}&uc=20170215&ap=&i_id=email__1.30&query={searchTerms} SearchScopes: HKCU -> {3FE479AA-6079-437A-913F-2FB27F48B31A} URL = hxxp://search.yourinstantemail.com/s?source=tt-bb8&uid={uid1}&uc=20170215&ap=&i_id=email__1.30&query={searchTerms} FF Homepage: hxxp://search.yourinstantemail.com?uid={uid2}&uc=20170215&ap=&source=tt&page=homepage&implementation_id=email_4.0.12 FF Extension: Email - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Email.xpi [2017-02-15] C:\Users\{username}\AppData\Roaming\SpigotSettings Your Instant Email (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.2.0.5 - Spigot, Inc.) <==== ATTENTION Most relevant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @Email.xpi"="2/15/2017 8:51 AM, 21706 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Email\simple-storage Adds the file store.json"="2/15/2017 8:55 AM, 315 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SpigotSettings Adds the file Uninstall.exe"="2/15/2017 8:50 AM, 267616 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.yourinstantemail.com/?source=tt&uid={uid1}&uc=20170215&ap=&i_id=email__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{3FE479AA-6079-437A-913F-2FB27F48B31A}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3FE479AA-6079-437A-913F-2FB27F48B31A}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.yourinstantemail.com/s?source=tt-bb8&uid={uid1}&uc=20170215&ap=&i_id=email__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "Your Instant Email" "DisplayVersion"="REG_SZ", "2.2.0.5" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\SpigotSettings\" "Publisher"="REG_SZ", "Spigot, Inc." "UninstallHomepage"="REG_SZ", "http://search.yourinstantemail.com/?source=tt&uid={uid1}&uc=20170215&ap=&i_id=email__1.30" "UninstallImpression"="REG_SZ", "http://imp.yourinstantemail.com/impression.do?source=tt&sub_id=20170215&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=&user_id={uid1}&implementation_id=email__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\SpigotSettings\Uninstall.exe" /uninstall" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/15/17 Scan Time: 9:08 AM Logfile: mbamYourInstantEmail.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1266 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360113 Time Elapsed: 1 min, 30 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [810], [300859],1.0.1266 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3FE479AA-6079-437A-913F-2FB27F48B31A}, Delete-on-Reboot, [2353], [368913],1.0.1266 Registry Value: 1 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3FE479AA-6079-437A-913F-2FB27F48B31A}|URL, Delete-on-Reboot, [2353], [368913],1.0.1266 Data Stream: 0 (No malicious items detected) Folder: 2 PUP.Optional.MyEmailXP, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Email\simple-storage, Delete-on-Reboot, [1843], [335005],1.0.1266 PUP.Optional.MyEmailXP, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@EMAIL, Delete-on-Reboot, [1843], [335005],1.0.1266 File: 4 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\SPIGOTSETTINGS\UNINSTALL.EXE, Delete-on-Reboot, [810], [300859],1.0.1266 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [2353], [361537],1.0.1266 PUP.Optional.MyEmailXP, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Email\simple-storage\store.json, Delete-on-Reboot, [1843], [335005],1.0.1266 PUP.Optional.MyEmailXP, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@EMAIL.XPI, Delete-on-Reboot, [1843], [335030],1.0.1266 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  9. What is OneSystemCare? The Malwarebytes research team has determined that OneSystemCare is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with OneSystemCare? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar and on your desktop: and you may see this type of warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: and these tasks in your Task Scheduler: How did OneSystemCare get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was installed by another PUP. How do I remove OneSystemCare? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of OneSystemCare? No, Malwarebytes removes OneSystemCare completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the OneSystemCare installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\OneSystemCare\SystemConsole.exe () C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe C:\Windows\System32\Tasks\{057E7947-780B-0E0B-7D11-0E0D0B0C110F} C:\Windows\System32\Tasks\One System Care Task C:\Windows\System32\Tasks\One System Care Run Delay C:\Windows\System32\Tasks\One System Care Monitor C:\Windows\System32\Tasks\One System CarePeriod C:\Windows\Tasks\One System CarePeriod.job C:\ProgramData\2a2276f9-20a1-1 C:\ProgramData\2a2276f9-0b93-0 C:\Users\{username}\AppData\Roaming\One System Care C:\Program Files (x86)\OneSystemCare C:\Users\Public\Desktop\Launch One System Care.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care One System Care (HKLM-x32\...\OneSystemCare) (Version: 4.4.0.3 - OneSystemCare) <==== ATTENTION Task: {11FD0FCC-787D-4FF1-B466-D5659CEA6633} - System32\Tasks\One System CarePeriod => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2016-12-26] () <==== ATTENTION Task: {4D89F1C3-36A8-4429-8FC1-0B263DA7E332} - System32\Tasks\One System Care Monitor => C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe [2016-12-26] () <==== ATTENTION Task: {668D20B7-A868-4B90-AF03-489B802C5E0A} - System32\Tasks\One System Care Run Delay => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe [2016-12-26] () <==== ATTENTION Task: {6CAB0476-77E0-4D8A-9D0A-D4FC8118D982} - System32\Tasks\{057E7947-780B-0E0B-7D11-0E0D0B0C110F} => powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand OwAgADsAIAA7ADsAOwA7ADsAIAAgACAAIAA7ACAAIAA7ADsAIAAgACAAIAA7ACAAIAA7ACAAIAAgADsAJABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUA (the data entry has 10184 more characters). Task: {F04F6E92-DB17-4ED4-8BB7-2F698ABDAD9E} - System32\Tasks\One System Care Task => C:\Program Files (x86)\OneSystemCare\SystemConsole.exe [2016-12-26] () <==== ATTENTION Task: C:\Windows\Tasks\One System CarePeriod.job => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe <==== ATTENTION Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\OneSystemCare Adds the file cancel.bmp"="12/26/2016 10:27 AM, 20360 bytes, A Adds the file CleanupConsole.exe"="12/26/2016 10:35 AM, 2238656 bytes, A Adds the file OneSystemCare.exe"="12/26/2016 10:35 AM, 4678336 bytes, A Adds the file OneSystemCare.ini"="2/14/2017 9:16 AM, 843 bytes, A Adds the file osc.ico"="12/26/2016 10:27 AM, 34494 bytes, A Adds the file SystemConsole.exe"="12/26/2016 10:35 AM, 952512 bytes, A Adds the file uninstall.bmp"="12/26/2016 10:27 AM, 802196 bytes, A Adds the file Uninstaller.exe"="12/26/2016 10:35 AM, 779592 bytes, A Adds the folder C:\ProgramData\2a2276f9-0b93-0 Adds the file BITA281.tmp"="2/14/2017 9:15 AM, 0 bytes, HA Adds the folder C:\ProgramData\2a2276f9-20a1-1 Adds the file BITA119.tmp"="2/14/2017 9:15 AM, 0 bytes, HA Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care Adds the file Launch One System Care.lnk"="2/14/2017 9:14 AM, 1085 bytes, A Adds the file One System Care on the Web.url"="2/14/2017 9:14 AM, 54 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\One System Care\Languages In the existing folder C:\Users\Public\Desktop Adds the file Launch One System Care.lnk"="2/14/2017 9:14 AM, 1067 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file {057E7947-780B-0E0B-7D11-0E0D0B0C110F}"="2/14/2017 9:15 AM, 24696 bytes, A Adds the file One System Care Monitor"="2/14/2017 9:15 AM, 3268 bytes, A Adds the file One System Care Run Delay"="2/14/2017 9:15 AM, 3334 bytes, A Adds the file One System Care Task"="2/14/2017 9:15 AM, 3576 bytes, A Adds the file One System CarePeriod"="2/14/2017 9:15 AM, 2868 bytes, A In the existing folder C:\Windows\Tasks Adds the file One System CarePeriod.job"="2/14/2017 9:15 AM, 284 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures] "One System CarePeriod.job"="REG_BINARY, ................................ "One System CarePeriod.job.fp"="REG_DWORD", 669890839 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564] "0"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\3f14500d2a2276f9] "0"="REG_SZ", "Gw7UvYUTOHrejuVCAbVnctRCA2_vYd0wOoR-9d0iFHgcEV9RLwjKpMaAmMD_Cpi7qG4AIW9C8rrPZqPWiNpB2sMhoV9tWTTGftHbE8TPworo7NXZNsRsDcOYyz1u1G-YSBmBOmYnTettG3d55Xa-L0P6u_Z9YwytjJueDW19fDt1IkrxJvFximWXBB3B6YEro2U9glLikIylxSztmvR7rsu3JVo9K8LHS2kVtOmoPG4UJNcHU24m26NvkQHOTB3mCf47TENy7HPHYW5jB-DQjd_ejg2SoE3OTmybhVgX8RzJtR6gPFGss4Ou49-kFmGf8-NG9ECRE9tXL3YopR7rAootnhjjyRB07bL4Cx2vpfthFN3FkqyqOoyhxBx4ITdg4Fv6OinyKXaDQ0UsA_AbQ0-LN7gR7ne6JvBU6yhds7_bfGfUgl75xDNY7N4OHZsT7LUbKzFKhK1JKa9V5RCnPHJdWaoXKr7nB83hZA4bHxT99rut19sNPbU3lauo33ZFoctaZGx_PixnpNhKqNzpCX--zuyuvV6yz71Jx2_6uQYNzJIOYSQwbZWfkm9rn3Bhb0OrZbYJKoQVKsUMCDIU4rT9llrJieaMgZJoqwGhu6glFkbUlLTH5oYmx9FlbfB6EGYaMRuGSHFxmqu6BybH7CG1JqWMfLquTNAUm9fTLyr6URfTEg0jzv_jNqn3XeTbweN2aRF69AZcY-fhJXtDMHw1kKXNp4SrPvxvJdz2GJRdWt5-qKo1lnh4XQW14v0_ZdV4g6Uq03pX6e5IUheci2_P1CctuOn5h63LrRheqTcvoBvW0mOKIPYmjpT60FFHueWm0Q64_P_pEjoxoZG3ReYE7y81tNef1lh7h6WUxBSnR5v5hRf01z1hj61v-OvUBEC7-oUmsHwO5XTq7OhdArtYXKTHku4yS2iO12oVRetE2o0DfxIokdbS2LCgABaRoZfNEj3TlaWA15P1kmYHbeXt_KpdRk_kn1mL0bjx7JeyaiE55edPUKTyUBmywbi6ZRy2MrvSTHmA5FFz0d8NHLlNczVQ4PvSYqD3KKYbH9FMoc8hnlu-3i3He_okW5yCijcIpfLqVhjJy92pFWBA06LG2hbtOysxRQbJwOtWmgyda7udOa3wFU8dqs3EuNcF_ZZWguvZlpAje7gbTgTFiX-ZRmKrmmI2lBb2exZ0aCjDSg2chOBKpA5zhZ1bKaXZVMRWjFzBZC48xjbLlwsgr-4FodNzQCpVeQMi5udvH5Nj74mIELUtwFakAE41fZ-ME8jnz77gJbwYpuT_QW_bo7nz1CzKGoMaux6xevphDUjaYslVKI1mPMSYes5h2jmoaSS7f99oPwd2-KudaATla6fo0S1AdoM58cwW4Xkr5mQxYs63mJlvkZUKMozlHaMMVHGK8vkqf-o10XB8u-xuxBOZPndY4f08mZviBQCwm_TjG2oaXRMuVJ4SFBNhPvuDiBkGjbYXmg9H_JG5kKhga5XDTMO1bQYOtsIXBgno2iwVyiaM3hRTELqDz1VcvFftSh0Gjy026t_GYCEnUsmkf0g79ejpOsBFF47TimDgjAi6WyvO4JVpPfTFTE68m_RReguPf5gikd2XCljvfeW2--vMUNZfroXopgSSzYVAgjcukkPdjjdqrrtDHl1VxFIKW7Nu3RfuG4bTlN9QGNL8sDP31kP3II4JZ1t8N7mfjtWieAPJQ0GnOnvqZwjOBl0sFIh5tmb3aFgD5RMQmpxA3RkMHmIPE_dB0D_Y4qu4Vpw-81vAL2aEQWqfsTS3Hhnhxs2mrf3iVQmBI_GS4foqx6cgZZFCGguKQr-RimRwCikEdMmSTjlhTUpj0ox2H4VCUQxyfbsI9Q7MhzYwhyRJthfWF-tBNTvP_7Q4D8rBtOY61if8V-xBklsK1zBJHuOSgRxxP9ohXqH390TKfknNWxyu5jPuex10rSRNfdwhipY6T225Jqnocv1zEXuzIppGTI1vjhANSTbnZrl4GMSYFS0AEptpaQX0tkA0HzHB-UC3mT6E_2pDZf0EYspXA6LFRJkwRFh2jtykhsGAdYIgArMOVYirsNQV1BCyV7oBnqnJm-Dn07_a8oy37Rj1Zh30CPtFuMLFwiIY1NXPBpy0Hpq1632J5EoYw4dCemUXFujWaRgSh_fKyb0yuulXHjqe3CL_vROlNU6O-WxGRU8TgRX94DfSG5NKbS9c0bWb8YKLS2hd_w1z4or-T659dd2EofrAM7N2ulXUc0E5Ix2i4R3UvkDrRMdFl5nfbB-ZpYfXnBoWN_tKlfg5iPdF2SsAnaWEhDdvTD9ppQcqIuTGGV27Zz194XNN4EVY-G4ODLf8bUAmwcptcxIDUFAB6SXXs9NsYu5A998REl9tS7_FMiTwjuR_3W1OG4R5-Zzip_5u2X38mhFt2eiOWMPPqLAFrWLpaCWLEUF1mhiQBbtB1PNJN-cFFHzn0aDoRG295kEZguU2-M3VjuY7srSLbl7cHQ9BNAzVKk4pO-l_RN-8sp1SAeDlpeYtSqoKerx-vx2hxjWy-KhkAVYNDxxGVN_eGJBSuVCrse6YioYPz_RJxNWsIbeg7lcXJzkr61JCZpXqzzLFE--XnhlyZrG4fc2fk4EjURZ97G4scXwgsHKZlpbYx0K_BTX6E6-BOeohPwYo2p-2AFXTKu_xV49I-x3f1e7MRdV0l8yo55dcJHcMc-Tx5863IQpq8vINxdeMXQoj1qLMpWtNbCZ5z6u62uT6K8ePYpNqYjBOdWMK9-MuV6r52txv8QDDvOh-MzbIn0d5UTfszJhi5GRMHDQiN1xw2UnoC8jH1cvJSeWAI2mFJ4ZnUQ5maShr_y2vk-xfLlgkl6WpTENKJpSdLkTkUTXqmInk65OnWOO6V54G5wZAtdeE_xgzLfgWnDJyTUV0_EijSvrjUEf3DpxUjxZnOXXSWqdDGOVEr_h7lAzvBD0iPhDR4hYh6OPraPV4FqsCSMD2pK7TGgOTV_jauBrFqphjA9ZaQIc6HlFsb5GU75wUGJug_gaxaLLU8AoAccVKJjw00ir9QppposAM8VnRtMtD9Ns6LTWhKeLOWA5zOylSi_1sgFkBvUjcdEFAKDXn2wRz" "1"="REG_SZ", "lOTnlgOfnqUskMunF-Jfg1R86ulQ" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\OneSystemCare\Uninstaller.exe" "DisplayName"="REG_SZ", "One System Care" "DisplayVersion"="REG_SZ", "4.4.0.3" "Publisher"="REG_SZ", "OneSystemCare" "rn"="REG_DWORD", 0 "UninstallString"="REG_SZ", "C:\Program Files (x86)\OneSystemCare\Uninstaller.exe" "URLInfoAbout"="REG_SZ", "http://www.onesystemcare.com" [HKEY_CURRENT_USER\Software\One System Care] "Configuration"="REG_BINARY, .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................. "InstLang"="REG_SZ", "1033" "PurchaseLink"="REG_SZ", "1" "ScanAtStartup"="REG_DWORD", 0 "ScheduleScan"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/14/17 Scan Time: 9:28 AM Logfile: mbamOneSystemCare.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1257 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 360070 Time Elapsed: 3 min, 11 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 3 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\SYSTEMCONSOLE.EXE, Quarantined, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRA~2\ONESYS~1\SYSTEM~1.EXE, Quarantined, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.EXE, Quarantined, [537], [311034],1.0.1257 Module: 1 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.EXE, Quarantined, [537], [311034],1.0.1257 Registry Key: 12 Adware.OptimizerEliteMax, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\OneSystemCare, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, HKCU\SOFTWARE\One System Care, Delete-on-Reboot, [578], [311038],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{11FD0FCC-787D-4FF1-B466-D5659CEA6633}, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4D89F1C3-36A8-4429-8FC1-0B263DA7E332}, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{668D20B7-A868-4B90-AF03-489B802C5E0A}, Delete-on-Reboot, [578], [258294],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F04F6E92-DB17-4ED4-8BB7-2F698ABDAD9E}, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f, Delete-on-Reboot, [578], [336950],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f, Delete-on-Reboot, [578], [336950],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System Care Monitor, Delete-on-Reboot, [578], [241385],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System Care Run Delay, Delete-on-Reboot, [578], [241385],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System Care Task, Delete-on-Reboot, [578], [241385],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\One System CarePeriod, Delete-on-Reboot, [578], [241385],1.0.1257 Registry Value: 10 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|DhcpNameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{EDB0D6D8-B1F7-496F-A023-44DF7155F1CD}|NameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{EDB0D6D8-B1F7-496F-A023-44DF7155F1CD}|DhcpNameServer, Replace-on-Reboot, [46], [-1],0.0.0 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{11FD0FCC-787D-4FF1-B466-D5659CEA6633}|PATH, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4D89F1C3-36A8-4429-8FC1-0B263DA7E332}|PATH, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{668D20B7-A868-4B90-AF03-489B802C5E0A}|PATH, Delete-on-Reboot, [578], [258294],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F04F6E92-DB17-4ED4-8BB7-2F698ABDAD9E}|PATH, Delete-on-Reboot, [578], [258705],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\04262113-2a31-48e1-b4bb-3b42174bea0f|DESCRIPTION, Delete-on-Reboot, [578], [336950],1.0.1257 PUP.Optional.OneSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\POWER\USER\POWERSCHEMES\e24b7131-d039-43cb-9e6f-ad4be601ec1f|DESCRIPTION, Delete-on-Reboot, [578], [336950],1.0.1257 Data Stream: 0 (No malicious items detected) Folder: 7 PUP.Optional.DNSUnlocker.ACMB2, C:\PROGRAMDATA\2a2276f9-0b93-0, Delete-on-Reboot, [46], [182288],1.0.1257 PUP.Optional.DNSUnlocker.ACMB2, C:\PROGRAMDATA\2a2276f9-20a1-1, Delete-on-Reboot, [46], [182288],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\WL, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\USERS\{username}\APPDATA\ROAMING\One System Care, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAM FILES (X86)\ONESYSTEMCARE, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ONE SYSTEM CARE, Delete-on-Reboot, [578], [241379],1.0.1257 File: 35 PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\2a2276f9-0b93-0\BITA281.tmp, Delete-on-Reboot, [46], [182288],1.0.1257 PUP.Optional.DNSUnlocker.ACMB2, C:\WINDOWS\SYSTEM32\TASKS\{057E7947-780B-0E0B-7D11-0E0D0B0C110F}, Delete-on-Reboot, [46], [-1],0.0.0 PUP.Optional.DNSUnlocker.ACMB2, C:\ProgramData\2a2276f9-20a1-1\BITA119.tmp, Delete-on-Reboot, [46], [182288],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\SYSTEMCONSOLE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRA~2\ONESYS~1\SYSTEM~1.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Danish.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Dutch.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\English.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\French.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\German.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Italian.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Norwegian.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Parameters.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Portuguese.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Spanish.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\Swedish.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\Languages\tmpLang.json, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\CallBanner.png, Delete-on-Reboot, [578], [178764],1.0.1257 PUP.Optional.OneSystemCare, C:\Users\{username}\AppData\Roaming\One System Care\FinishedScan.png, Delete-on-Reboot, [578], [178764],1.0.1257 Adware.OptimizerEliteMax, C:\USERS\{username}\DESKTOP\ONESYSTEMCARE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, C:\USERS\PUBLIC\DESKTOP\LAUNCH ONE SYSTEM CARE.LNK, Delete-on-Reboot, [578], [241377],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\UNINSTALLER.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 Adware.OptimizerEliteMax, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\CLEANUPCONSOLE.EXE, Delete-on-Reboot, [537], [311034],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAM FILES (X86)\ONESYSTEMCARE\ONESYSTEMCARE.INI, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\Program Files (x86)\OneSystemCare\cancel.bmp, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\Program Files (x86)\OneSystemCare\osc.ico, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\Program Files (x86)\OneSystemCare\uninstall.bmp, Delete-on-Reboot, [578], [241378],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\TASKS\ONE SYSTEM CAREPERIOD.JOB, Delete-on-Reboot, [578], [241382],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System Care Monitor, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System Care Run Delay, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System Care Task, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\WINDOWS\SYSTEM32\TASKS\One System CarePeriod, Delete-on-Reboot, [578], [241381],1.0.1257 PUP.Optional.OneSystemCare, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\ONE SYSTEM CARE\LAUNCH ONE SYSTEM CARE.LNK, Delete-on-Reboot, [578], [241379],1.0.1257 PUP.Optional.OneSystemCare, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care\One System Care on the Web.url, Delete-on-Reboot, [578], [241379],1.0.1257 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  10. No problem. If it happens again, you can add an exclusion for the exploit detection if you are sure it's something you want to alllow. Under Settings select the Exclusions tab > Add Exclusion > select Exclude a Previously Detected Exploit > Next > select the exploit you want to exclude and click OK.
  11. What is GetCouponsFast? The Malwarebytes research team has determined that GetCouponsFast is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. GetCouponsFast is a Mindspark/Ask toolbar now known as IAC Applications. How do I know if my computer is affected by GetCouponsFast? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browsers: How did GetCouponsFast get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove GetCouponsFast? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of GetCouponsFast? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the GetCouponsFast entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the GetCouponsFast hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/getcouponsfast/ttab02/index.html?n={n1}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/getcouponsfast/ttab02/index.html?coId={coid2}&subId&ln=en&n={n2}&p2={p22}&si FF Extension: GetCouponsFast - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_jhMembers_@www.getcouponsfast.com [2017-02-13] CHR Extension: (GetCouponsFast) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj [2017-02-13] C:\Users\{username}\AppData\Local\GetCouponsFastTooltab GetCouponsFast Internet Explorer Homepage and New Tab (HKCU\...\GetCouponsFastTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION Significant changes made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\GetCouponsFastTooltab Adds the file TooltabExtension.dll"="10/19/2016 6:15 PM, 266864 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0 Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iadmakoacmnjmcacmhlcjcameijgcopj Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\iadmakoacmnjmcacmhlcjcameijgcopj Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com Adds the file bootstrap.js"="2/13/2017 9:44 AM, 24730 bytes, A Adds the file chrome.manifest"="2/13/2017 9:44 AM, 135 bytes, A Adds the file chrome.manifest.restartless"="2/13/2017 9:44 AM, 135 bytes, A Adds the file install.rdf"="2/13/2017 9:44 AM, 1441 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome Adds the file ffxtbr.jar"="2/13/2017 9:44 AM, 344204 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF Adds the file manifest.mf"="2/13/2017 9:44 AM, 680 bytes, A Adds the file mozilla.rsa"="2/13/2017 9:44 AM, 4192 bytes, A Adds the file mozilla.sf"="2/13/2017 9:44 AM, 121 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\getcouponsfast_jh Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\GetCouponsFast] "Start Page"="REG_SZ", "http://hp.myway.com/getcouponsfast/ttab02/index.html?n=C05BAFB&p2=^CQC^yyyyyy^TTAB02^nl&ptb={ptb1}&coid={coid1}" "UnInstallSurveyUrl"="REG_SZ", "http://@{downloadDomain}.dl.myway.com/uninstall.jhtml?surveyUrl=http%3A%2F%2Fwww.research.net" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://hp.myway.com/getcouponsfast/ttab02/index.html?n={n1}&ptb={ptb1}&coid={coid1}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GetCouponsFastTooltab Uninstall Internet Explorer] "DisplayName"="REG_SZ", "GetCouponsFast Internet Explorer Homepage and New Tab" "HelpLink"="REG_SZ", "http://support.mindspark.com/" "Publisher"="REG_SZ", "Mindspark Interactive Network, Inc." "UninstallString"="REG_SZ", "Rundll32.exe "C:\Users\{username}\AppData\Local\GetCouponsFastTooltab\TooltabExtension.dll" U uninstall:GetCouponsFast" "URLInfoAbout"="REG_SZ", "http://support.mindspark.com/" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/13/17 Scan Time: 9:55 AM Logfile: mbamGetCouponsFast.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1249 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359800 Time Elapsed: 2 min, 5 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GETCOUPONSFASTTOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [340], [301125],1.0.1249 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GetCouponsFastTooltab Uninstall Internet Explorer, Delete-on-Reboot, [340], [301125],1.0.1249 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GetCouponsFastTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [340], [352442],1.0.1249 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [340], [293497],1.0.1249 Data Stream: 0 (No malicious items detected) Folder: 89 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GetCouponsFastTooltab, Delete-on-Reboot, [1048], [356944],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\abstractbutton\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\thirdparty\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\uninstall\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\weather\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\generic\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\alert\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\link\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\abstractbutton, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\rss\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\images, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\radioWrapper, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\thirdparty, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\foreground, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\uninstall, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\generic, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\weather, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\background, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\alert, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\link, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\rss, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\adapter, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\_metadata, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IADMAKOACMNJMCACMHLCJCAMEIJGCOPJ, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_JHMEMBERS_@WWW.GETCOUPONSFAST.COM, Delete-on-Reboot, [340], [302304],1.0.1249 File: 287 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GETCOUPONSFASTTOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [340], [301125],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [319354],1.0.1249 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [1048], [356946],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [340], [240306],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [340], [240306],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.myway.com_0.localstorage, Delete-on-Reboot, [340], [240305],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_getcouponsfast.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [340], [240305],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IADMAKOACMNJMCACMHLCJCAMEIJGCOPJ\12.202.10.39297_0\MANIFEST.JSON, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\menu\README.txt, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\bs.30.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\common.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\dynamic.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\enableDetect.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\eventListening.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\global.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\list-interaction.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\messageEventListener.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\navRedirector.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\paramReplacer.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\PartnerId.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\set.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\js\unifiedLogging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\foreground\button.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\background\searchBox.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\css\supertab.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\html\supertab.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\reporting.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\supertab.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\components\supertab\js\__utm.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\arrowSprite.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon128.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon16.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon19disabled.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon19on.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\icon48.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012495.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012507.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012508.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012559.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\233012576.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\down_arrow.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\magnifying_glass.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\search_button.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\tvf_icon_guide.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\tvf_logo.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\images\wrench.png, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\newTabInitialize.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\chromeStorage.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\chromeUtils.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\companionSWUtils.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\exeManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\exeManagerNMD.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\exePackageManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\focusManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\globalBlacklistManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\messaging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\mutation_summary-min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\mutation_summary.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\newTabInfo.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\options.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\readLocalStorage.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\reservespaceifenabled.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\scriptInjector.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\searchContext.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\settingsOverrides.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\toolbarCookieParser.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\toolbarPreinit.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\URILoaderContentScript.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\webTooltabAPI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\Widget.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\widgetFactory.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\js\widgetWindowManager.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\cache.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\ce.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\debug.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\native\ss.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\activePing.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\buttonLogger.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\competitorDnsList.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\console.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\httpTransport.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\HttpURL.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\internationalSearch.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\rsvp-latest.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\testHttpTransport.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\unifiedLogger.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\unifiedLogging.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\universalConsole.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\shared\utils.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\_metadata\computed_hashes.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\_metadata\verified_contents.json, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\bg.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\buildVars, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\buildVars.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\companionSW.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\config.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\contentScript.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\contentScript.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\debug.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\debug.jade, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\extension_toolbar_api.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\initWidgetWindow.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\newTabContentScript.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\options.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent2.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spent2.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spentJ.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spentK.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\spentK.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\startup.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\stub.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\stubby.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\superFrame.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbar.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbar.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbarUI.css, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbarUI.html, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\toolbarUI.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\url.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\iadmakoacmnjmcacmhlcjcameijgcopj\12.202.10.39297_0\webtooltab.cs.js, Delete-on-Reboot, [340], [301932],1.0.1249 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_JHMEMBERS_@WWW.GETCOUPONSFAST.COM\INSTALL.RDF, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome\ffxtbr.jar, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF\manifest.mf, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF\mozilla.rsa, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\META-INF\mozilla.sf, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\bootstrap.js, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome.manifest, Delete-on-Reboot, [340], [302304],1.0.1249 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_jhMembers_@www.getcouponsfast.com\chrome.manifest.restartless, Delete-on-Reboot, [340], [302304],1.0.1249 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  12. Hi reidsci, Did I understand correct that this is something you created yourself? I do understand why our Anti-Exploit module would block that, since it is unexpected and malware-like behavior. Another question for you: did this start immediately after you upgraded from Malwarebytes version 2 to 3?
  13. What is Trotux? The Malwarebytes research team has determined that Trotux is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by Trotux? You may see this entry in your list of installed programs: this type of Scheduled Tasks (random names): these changed search settings in the affected browsers: and this startpage: You may also notice a fake Firefox profiles as described here: GsearchFinder hijackers add extra Firefox profile How did Trotux get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove Trotux? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Trotux? No, Malwarebytes removes Trotux completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the Trotux adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks the origin of the installer: Technical details for experts Possible signs in FRST logs: HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 ShellExecuteHooks: - {58AF6728-ECD0-11E6-BFEA-64006A5CFC23} - C:\Users\{username}\AppData\Roaming\Climofabech\Gipphsaweght.dll [146944 2017-02-10] () FF NewTab: hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp FF DefaultSearchEngine: trotux FF SelectedSearchEngine: trotux FF Homepage: hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\mhc384j1.default\searchplugins\4qy3hwj4.xml [2017-02-10] CHR HomePage: ChromeDefaultData -> hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp" CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=sp CHR DefaultSearchKeyword: ChromeDefaultData -> trotux R2 Stuhoph; C:\Program Files (x86)\Grerhient\cgghtdeberkmnt.dll [149504 2017-02-10] () [File not signed] C:\WINDOWS\System32\Tasks\Drecaward Client C:\WINDOWS\System32\Tasks\Niiseclajuent C:\Users\{username}\AppData\Roaming\Climofabech C:\Users\{username}\AppData\Local\Ckekiry C:\Program Files (x86)\Drecaward Client C:\Program Files (x86)\Grerhient trotux - Uninstall (HKLM-x32\...\{8230A356-F879-4B82-AF04-032A578692C0}) (Version: - ) Task: {1B965CA1-35D0-4C1D-B92A-FE8677ECA306} - System32\Tasks\Drecaward Client => C:\Program Files (x86)\Grerhient\dozuent.exe [2017-02-10] (Glarysoft Ltd) Task: {D766AA6E-86D0-4DF0-BCC5-BCACB56D5FE6} - System32\Tasks\Niiseclajuent => /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&amp;v=2017210 /q () C:\Users\{username}\AppData\Roaming\Climofabech\Gipphsaweght.dll () C:\Program Files (x86)\Drecaward Client\local64spl.dll () c:\program files (x86)\grerhient\cgghtdeberkmnt.dll Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Drecaward Client Adds the file local64spl.dll"="2/10/2017 11:34 AM, 309760 bytes, A Adds the file local64spl.dll.ini"="2/10/2017 11:34 AM, 20 bytes, A Adds the folder C:\Program Files (x86)\Grerhient Adds the file cgghtdeberkmnt.dll"="2/10/2017 11:34 AM, 149504 bytes, A Adds the file CrashReport.dll"="2/10/2017 11:34 AM, 121344 bytes, A Adds the file dozuent.exe"="2/10/2017 11:34 AM, 1026216 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Drecaward Client"="2/10/2017 11:34 AM, 6082 bytes, A Adds the file Niiseclajuent"="2/10/2017 11:34 AM, 3780 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\0B3C7EB2C2FC8FF89E16DF9C80C0327A] "(Default)"="REG_SZ"", "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}" "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}"="REG_BINARY, ............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}\InProcServer32] "(Default)"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Climofabech\Gipphsaweght.dll" "ThreadingModel"="REG_SZ"", "Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft] "help"="REG_SZ"", "http://www.trotux.com/?z=1f52ad85c729d12e6f3c817gezfb7q5m9obo8bfc4c&from=wsy1&uid=ST500LT012-1DG142_S3PA6P09XXXXS3PA6P09&type=hp" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}"="REG_SZ"", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] "EnableShellExecuteHooks"="REG_DWORD"", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Mvasephermuy] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\{84416237-6490-494D-9AD6-4994DD978971}] "chd"="REG_SZ"", "C:\Users\{username}\AppData\Local\Ckekiry" "ffd"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Profiles\Grerkaghgerdiing.default" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\0B3C7EB2C2FC8FF89E16DF9C80C0327A] "(Default)"="REG_SZ"", "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}" "{EFD519A3-DC49-498A-8DD4-AD1DA8F97FCD}"="REG_BINARY, ............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ckafoyanerqeent] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\dozuent.exe] "(Default)"="REG_SZ"", "2017210" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8230A356-F879-4B82-AF04-032A578692C0}] "DisplayName"="REG_SZ"", "trotux - Uninstall" "UninstallString"="REG_SZ"", "C:\Program Files (x86)\Grerhient\dozuent.exe ef869dec-feed-46e1-a4fe-427f47f37b77 "/k={8230A356-F879-4B82-AF04-032A578692C0}"" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost] "Stuhoph"="REG_MULTI_SZ, "Stuhoph" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Suvosh] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\trotuxSoftware\trotuxhp] "oem"="REG_SZ"", "wsy1" "Time"="REG_DWORD"", 1486722892 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\xvtrzx] "day"="REG_SZ"", "20170210" "upday"="REG_SZ"", "20170210" [HKEY_LOCAL_MACHINE\SOFTWARE\xvtrzx] "day"="REG_SZ"", "20170210" "upday"="REG_SZ"", "20170210" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers] "order" = REG_MULTI_SZ, "LanMan Print Services Internet Print Provider 4qy3hwj4 " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\4qy3hwj4] "DisplayName"="REG_SZ"", "zvgbuz" "Name"="REG_SZ"", "C:\Program Files (x86)\Drecaward Client\local64spl.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Stuhoph] "Description"="REG_SZ"", "Provides global functions for other parts of Chislereuction." "DisplayName"="REG_SZ"", "Stuhoph" "ErrorControl"="REG_DWORD"", 1 "FailureActions"="REG_BINARY, ...................... "ImagePath"="REG_EXPAND_SZ, "%SystemRoot%\system32\svchost.exe -k Stuhoph" "ObjectName"="REG_SZ"", "LocalSystem" "Start"="REG_DWORD"", 2 "Type"="REG_DWORD"", 272 "WOW64"="REG_DWORD"", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Stuhoph\Parameters] "ServiceDll"="REG_EXPAND_SZ, "C:\Program Files (x86)\Grerhient\cgghtdeberkmnt.dll" "ServiceMain"="REG_SZ"", "Clanochphoderk" [HKEY_USERS\.DEFAULT\Software\xvtrzx] "day"="REG_SZ"", "20170210" "upday"="REG_SZ"", "20170210" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/10/17 Scan Time: 12:14 PM Logfile: mbamTrotux.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.50 Update Package Version: 1.0.1225 License: Premium -System Information- OS: Windows 10 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 384454 Time Elapsed: 9 min, 6 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 4 Adware.Elex.SHHKRST, C:\USERS\{username}\APPDATA\ROAMING\CLIMOFABECH\GIPPHSAWEGHT.DLL, Quarantined, [1238], [362727],1.0.1225 Adware.Elex.SHHKRST, C:\USERS\{username}\APPDATA\ROAMING\CLIMOFABECH\GIPPHSAWEGHT.DLL, Quarantined, [1238], [362727],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\GRERHIENT\CGGHTDEBERKMNT.DLL, Quarantined, [2145], [366971],1.0.1225 Adware.Elex.Generic, C:\Program Files (x86)\Drecaward Client\local64spl.dll, Quarantined, [2145], [358303],1.0.1225 Registry Key: 5 Adware.Elex.SHHKRST, HKLM\SOFTWARE\CLASSES\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}, Delete-on-Reboot, [1238], [362727],1.0.1225 Adware.Elex.SHHKRST, HKLM\SOFTWARE\CLASSES\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}\InprocServer32, Delete-on-Reboot, [1238], [362727],1.0.1225 PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\trotuxSoftware, Delete-on-Reboot, [418], [182848],1.0.1225 Adware.Sasquor.SPL, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\PRINT\PROVIDERS\4qy3hwj4, Delete-on-Reboot, [2086], [339986],1.0.1225 PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{8230A356-F879-4B82-AF04-032A578692C0}, Delete-on-Reboot, [418], [182846],1.0.1225 Registry Value: 5 Adware.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS|{58AF6728-ECD0-11E6-BFEA-64006A5CFC23}, Delete-on-Reboot, [1238], [362727],1.0.1225 Adware.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS, Delete-on-Reboot, [1238], [-1],0.0.0 Adware.Elex.SHHKRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS, Delete-on-Reboot, [1238], [-1],0.0.0 Adware.Sasquor.SPL, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\PRINT\PROVIDERS\4qy3hwj4|NAME, Delete-on-Reboot, [2086], [339986],1.0.1225 PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{8230A356-F879-4B82-AF04-032A578692C0}|DISPLAYNAME, Delete-on-Reboot, [418], [182846],1.0.1225 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 4 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\USERS\{username}\APPDATA\ROAMING\Mozilla\Firefox\naweriweentcofise, Delete-on-Reboot, [2773], [363173],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\DRECAWARD CLIENT, Delete-on-Reboot, [2145], [358303],1.0.1225 File: 23 Adware.Elex.SHHKRST, C:\USERS\{username}\APPDATA\ROAMING\CLIMOFABECH\GIPPHSAWEGHT.DLL, Delete-on-Reboot, [1238], [362727],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\prefs.js, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\profiles.ini, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\search.json, Delete-on-Reboot, [2773], [363173],1.0.1225 PUP.Optional.FakeFFProfile, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\mhc384j1.default\search.json.mozlz4, Delete-on-Reboot, [2773], [363173],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\GRERHIENT\CGGHTDEBERKMNT.DLL, Delete-on-Reboot, [2145], [366971],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\SEARCHPLUGINS\4QY3HWJ4.XML, Delete-on-Reboot, [418], [324483],1.0.1225 PUP.Optional.Elex, C:\USERS\{username}\DESKTOP\WSY1_AY.EXE, Delete-on-Reboot, [15], [315776],1.0.1225 Adware.Elex.Generic, C:\PROGRAM FILES (X86)\DRECAWARD CLIENT\LOCAL64SPL.DLL.INI, Delete-on-Reboot, [2145], [358303],1.0.1225 Adware.Elex.Generic, C:\Program Files (x86)\Drecaward Client\local64spl.dll, Delete-on-Reboot, [2145], [358303],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\PROFILES\GRERKAGHGERDIING.DEFAULT\PREFS.JS, Replaced, [418], [324486],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\PREFS.JS, Replaced, [418], [302758],1.0.1225 PUP.Optional.Trotux, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MHC384J1.DEFAULT\SEARCHPLUGINS\4QY3HWJ4.XML, Delete-on-Reboot, [418], [302745],1.0.1225 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  14. What is winsvc.vbs? The Malwarebytes research team has determined that winsvc.vbs is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by winsvc.vbs? You may see this entry in your startup folder: How did winsvc.vbs get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove winsvc.vbs? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of winsvc.vbs? No, Malwarebytes removes winsvc.vbs completely. If you return to a temporary profile after the first reboot, simply reboot once more. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the winsvc.vbs adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks the source of the installer: Technical details for experts Possible signs in FRST logs: (Node.js) C:\Users\{username}\AppData\Roaming\win-svc\bin\winsvc.exe Startup: C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winsvc.vbs [2016-12-21] () C:\Users\{username}\AppData\Roaming\win-svc The most significant alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Adds the file winsvc.vbs"="12/21/2016 10:43 AM, 189 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\win-svc Adds the file cmd.bat"="1/25/2017 2:34 PM, 322 bytes, A Adds the file reg.reg"="1/25/2017 2:24 PM, 150 bytes, A Adds the file run.vbs"="12/21/2016 11:01 AM, 87 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\win-svc\bin Adds the folder C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast Adds the file index.js"="12/20/2016 9:02 AM, 1352 bytes, A Adds the file LICENSE"="12/20/2016 9:02 AM, 1115 bytes, A Adds the file package.json"="12/20/2016 9:02 AM, 2538 bytes, A Adds the file README.md"="12/20/2016 9:02 AM, 2992 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GenericCo\GenericKey] "GenericName"="REG_SZ", "GenericVal1" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/9/17 Scan Time: 1:07 PM Logfile: mbamcli.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1217 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359430 Time Elapsed: 1 min, 17 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\WIN-SVC\BIN\WINSVC.EXE, Quarantined, [1033], [360756],1.0.1217 Module: 1 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\WIN-SVC\BIN\WINSVC.EXE, Quarantined, [1033], [360756],1.0.1217 Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 95 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\fixtures, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release\obj.target, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\obj.target, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc\wg-meetings, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\example, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test\server, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\example, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\example, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\build, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\bin, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\test, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\.bin, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\win-svc, Delete-on-Reboot, [1033], [360756],1.0.1217 File: 440 Adware.Elex, C:\USERS\{username}\APPDATA\ROAMING\WIN-SVC\BIN\WINSVC.EXE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\asyncworker.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\buffers.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\callback.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\converters.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\errors.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\maybe_types.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\methods.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\new.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\node_misc.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\object_wrappers.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\persistent.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\scopes.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\script.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\string_bytes.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\v8_internals.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\doc\v8_misc.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools\1to2.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\tools\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\CHANGELOG.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\include_dirs.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\LICENSE.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_callbacks.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_callbacks_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_callbacks_pre_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_converters.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_converters_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_converters_pre_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_implementation_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_implementation_pre_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_maybe_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_maybe_pre_43_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_new.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_object_wrap.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_persistent_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_persistent_pre_12_inl.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_string_bytes.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_typedarray_contents.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\nan_weak.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\nan\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\.bin\uuid, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\test\after-test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\LICENCE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\after\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\test\slice-buffer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\arraybuffer.slice\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\test\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\backo2\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\lib\base64-arraybuffer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\LICENSE-MIT, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\base64-arraybuffer\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\example.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\better-assert\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\test\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\.zuul.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\blob\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\callsite\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-bind\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-emitter\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\test\inherit.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\component-inherit\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\concat-stream\readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\lib\util.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\float.patch, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\core-util-is\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\.jshintrc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\CHANGELOG.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\debug.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\node.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\debug\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\polling-jsonp.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\polling-xhr.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\polling.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transports\websocket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\socket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\transport.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\lib\xmlhttprequest.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\engine.io.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-client\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\lib\keys.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\fixtures\big.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\node_modules\has-binary\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\engine.io-parser\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-binary\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\has-cors\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\indexof\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\inherits.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\inherits_browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\inherits\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\build\build.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\isarray\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\lib\json3.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\lib\json3.min.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\json3\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\LICENSE.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ms\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\bench.gnu, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\bench.sh, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\benchmark-native.c, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\benchmark.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\benchmark\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\bin\uuid, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test\compare_v1.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test\test.html, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\test\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\LICENSE.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\node-uuid\uuid.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\test\object.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\object-component\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\lib\options.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\options\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release\obj.target\service.node.d, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\.deps\Release\service.node.d, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\obj.target\service.node, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Release\service.node, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\binding.Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\config.gypi, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\build\service.target.mk, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\example\periodic-logger.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\pthread.cc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\pthread.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\service.cc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\src\service.h, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\binding.gyp, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\os-service\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parsejson\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseqs\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\parseuri\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\license.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\process-nextick-args\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc\wg-meetings\2015-01-30.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\doc\stream.markdown, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_duplex.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_passthrough.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_readable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_transform.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\lib\_stream_writable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\node_modules\isarray\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\.zuul.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\duplex.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\passthrough.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\readable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\transform.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\readable-stream\writable.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.js.map, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.min.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.slim.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.slim.js.map, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\dist\socket.io.slim.min.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\manager.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\on.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\socket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\lib\url.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-client\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\component-emitter\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\.jshintrc, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\bower.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\component.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\debug.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\node.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\debug\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\node_modules\ms\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\binary.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\is-buffer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\socket.io-parser\Readme.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\string_decoder\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\LICENCE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\to-array\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\example\tarray.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test\server\undef_globals.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\test\tarray.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\typedarray\readme.markdown, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ultron\test.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\browser.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\History.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\node.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\util-deprecate\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\BufferPool.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\BufferUtil.fallback.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\BufferUtil.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\ErrorCodes.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Extensions.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\PerMessageDeflate.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Receiver.hixie.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Receiver.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Sender.hixie.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Sender.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Validation.fallback.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\Validation.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\WebSocket.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\lib\WebSocketServer.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\.npmignore, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\.travis.yml, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\Makefile, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\ws\SECURITY.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\LICENSE-MIT.txt, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\wtf-8\wtf-8.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\example\demo.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\lib\XMLHttpRequest.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-constants.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-events.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-exceptions.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-headers.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-redirect-302.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-redirect-303.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-redirect-307.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-request-methods.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\test-request-protocols.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\tests\testdata.txt, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\autotest.watchr, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\xmlhttprequest-ssl\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\index.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\LICENSE, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\package.json, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\node_modules\yeast\README.md, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\app, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\main.js, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\bin\v, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\cmd.bat, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\reg.reg, Delete-on-Reboot, [1033], [360756],1.0.1217 Adware.Elex, C:\Users\{username}\AppData\Roaming\win-svc\run.vbs, Delete-on-Reboot, [1033], [360756],1.0.1217 Trojan.Agent.VBS, C:\USERS\{username}\DESKTOP\INST-CLI-17.EXE, Delete-on-Reboot, [771], [368894],1.0.1217 Trojan.Agent.VBS, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\WINSVC.VBS, Delete-on-Reboot, [771], [362645],1.0.1217 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  15. What is GetFitNow? The Malwarebytes research team has determined that GetFitNow is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. GetFitNow is a member of the Spigot family. How do I know if my computer is affected by GetFitNow? You may see these browser extensions/add-ons: and these altered settings: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browser(s): How did GetFitNow get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove GetFitNow? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of GetFitNow? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the GetFitNow entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the GetFitNow hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.getfitnow.co/?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30 SearchScopes: HKCU -> DefaultScope {E4B45767-A66A-459A-B864-3B8F8C7E246A} URL = hxxp://search.getfitnow.co/s?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30&query={searchTerms} SearchScopes: HKCU -> {E4B45767-A66A-459A-B864-3B8F8C7E246A} URL = hxxp://search.getfitnow.co/s?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30&query={searchTerms} FF Homepage: hxxp://search.getfitnow.co?uid={uid2}&uc=20170208&ap=appfocus1&source=tt&page=homepage&implementation_id=fitness_4.0.1 FF Extension: Fitness - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Fitness.xpi [2017-02-08] CHR Extension: (Get Fit Now) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh [2017-02-08] C:\Users\{username}\AppData\Roaming\SpigotSettings GetFitNow (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.1.0.1 - Spigot, Inc.) <==== ATTENTION The most significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\jgblngkjeffdpdnfgenlfjnaakgahfoh Adds the file 000003.log"="2/8/2017 9:18 AM, 252 bytes, A Adds the file CURRENT"="2/8/2017 9:18 AM, 16 bytes, A Adds the file LOCK"="2/8/2017 9:18 AM, 0 bytes, A Adds the file LOG"="2/8/2017 9:28 AM, 410 bytes, A Adds the file LOG.old"="2/8/2017 9:18 AM, 184 bytes, A Adds the file MANIFEST-000001"="2/8/2017 9:18 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @Fitness.xpi"="2/8/2017 9:16 AM, 64432 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Fitness\simple-storage Adds the file store.json"="2/8/2017 9:17 AM, 317 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SpigotSettings Adds the file Uninstall.exe"="2/8/2017 9:12 AM, 267616 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.getfitnow.co/?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{E4B45767-A66A-459A-B864-3B8F8C7E246A}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E4B45767-A66A-459A-B864-3B8F8C7E246A}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.getfitnow.co/s?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "GetFitNow" "DisplayVersion"="REG_SZ", "2.1.0.1" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\SpigotSettings\" "Publisher"="REG_SZ", "Spigot, Inc." "UninstallHomepage"="REG_SZ", "http://search.getfitnow.co/?source=&uid={uid1}&uc=20170208&ap=appfocus1&i_id=fitness__1.30" "UninstallImpression"="REG_SZ", "http://imp.getfitnow.co/impression.do?source=&sub_id=20170208&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=appfocus1&user_id={uid1}&implementation_id=fitness__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\SpigotSettings\Uninstall.exe" /uninstall" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 2/8/17 Scan Time: 9:38 AM Logfile: mbamGetFitNow.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1207 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 359252 Time Elapsed: 1 min, 45 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 1 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [811], [300859],1.0.1207 Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 13 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Fitness\simple-storage, Delete-on-Reboot, [2350], [364585],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@FITNESS, Delete-on-Reboot, [2350], [364585],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_locales\en, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html\popup, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_metadata, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js\popup, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_locales, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\newtab, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\css, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JGBLNGKJEFFDPDNFGENLFJNAAKGAHFOH, Delete-on-Reboot, [2350], [362981],1.0.1207 File: 18 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Fitness\simple-storage\store.json, Delete-on-Reboot, [2350], [364585],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Replaced, [2350], [361537],1.0.1207 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\SPIGOTSETTINGS\UNINSTALL.EXE, Delete-on-Reboot, [811], [300859],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JGBLNGKJEFFDPDNFGENLFJNAAKGAHFOH\3.0_0\BACKGROUND.JS, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\css\description.css, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\css\popup.css, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html\popup\description.html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\html\popup\popup.html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js\popup\popup.js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\js\userNewTab.js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\newtab\newtab.html, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_locales\en\messages.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_metadata\computed_hashes.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\_metadata\verified_contents.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\contentscript.js, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\icon.png, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgblngkjeffdpdnfgenlfjnaakgahfoh\3.0_0\manifest.json, Delete-on-Reboot, [2350], [362981],1.0.1207 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@FITNESS.XPI, Delete-on-Reboot, [2350], [364607],1.0.1207 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.