Metallica

Moderators
  • Content count

    1,773
  • Joined

  • Last visited

About Metallica

  • Rank
    Master of PUPs
  • Birthday 05/19/1963

Contact Methods

  • ICQ
    0

Profile Information

  • Location
    Netherlands

Recent Profile Visitors

153,829 profile views
  1. 420Rancher Can you let us know if your problem has been solved by using Malwarebytes Anti-Rootkit?
  2. What is HowToSimplified? The Malwarebytes research team has determined that HowToSimplified is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. HowToSimplified is a Mindspark/Ask toolbar now known as IAC Applications. How do I know if my computer is affected by HowToSimplified? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browsers: How did HowToSimplified get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove HowToSimplified? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of HowToSimplified? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the HowToSimplified entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the HowToSimplified hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/howtosimplified/S20228/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/howtosimplified/S20223/index.html?coId={coid2}&subId&ln=en&n={n1}&ptb={ptb2}&st&p2={p22}&si FF Extension: HowToSimplified - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_8eMembers_@download.howtosimplified.com [2017-03-27] CHR Extension: (HowToSimplified) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib [2017-03-27] CHR Extension: (Chrome Web Store Payments) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-27] C:\Users\{username}\AppData\Local\HowToSimplifiedTooltab HowToSimplified Internet Explorer Homepage and New Tab (HKCU\...\HowToSimplifiedTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION Most significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0 Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmgkbcihahpocjmclehpjejmgjmijcib Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mmgkbcihahpocjmclehpjejmgjmijcib Adds the file 000003.log"="3/27/2017 10:59 AM, 398 bytes, A Adds the file CURRENT"="3/27/2017 10:59 AM, 16 bytes, A Adds the file LOCK"="3/27/2017 10:59 AM, 0 bytes, A Adds the file LOG"="3/27/2017 10:59 AM, 184 bytes, A Adds the file MANIFEST-000001"="3/27/2017 10:59 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Local\HowToSimplifiedTooltab Adds the file TooltabExtension.dll"="2/16/2017 12:50 AM, 266864 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com Adds the file bootstrap.js"="3/27/2017 10:56 AM, 24730 bytes, A Adds the file chrome.manifest"="3/27/2017 10:56 AM, 135 bytes, A Adds the file chrome.manifest.restartless"="3/27/2017 10:56 AM, 135 bytes, A Adds the file install.rdf"="3/27/2017 10:56 AM, 1476 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\chrome Adds the file ffxtbr.jar"="3/27/2017 10:56 AM, 348711 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\META-INF Adds the file manifest.mf"="3/27/2017 10:56 AM, 680 bytes, A Adds the file mozilla.rsa"="3/27/2017 10:56 AM, 4198 bytes, A Adds the file mozilla.sf"="3/27/2017 10:56 AM, 121 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\HowToSimplified_8e Adds the file {ptb2}.sqlite"="3/27/2017 10:56 AM, 98304 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\HowToSimplified] "Start Page"="REG_SZ", "http://hp.myway.com/howtosimplified/S20228/index.html?n={n1}&p2={p23}&ptb={ptb1}&coid={coid1}" "UnInstallSurveyUrl"="REG_SZ", "http://@{downloadDomain}.dl.myway.com/uninstall.jhtml?surveyUrl=https%3A%2F%2Fwww.research.net%2Fr%2F%3Fc%3D{ptb1}%26ptb%3D{p23}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://hp.myway.com/howtosimplified/S20228/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\HowToSimplifiedTooltab Uninstall Internet Explorer] "DisplayName"="REG_SZ", "HowToSimplified Internet Explorer Homepage and New Tab" "HelpLink"="REG_SZ", "http://support.mindspark.com/" "Publisher"="REG_SZ", "Mindspark Interactive Network, Inc." "UninstallString"="REG_SZ", "Rundll32.exe "C:\Users\{username}\AppData\Local\HowToSimplifiedTooltab\TooltabExtension.dll" U uninstall:HowToSimplified" "URLInfoAbout"="REG_SZ", "http://support.mindspark.com/" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/27/17 Scan Time: 11:09 AM Logfile: mbamHowtoSimplified.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1605 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 366849 Time Elapsed: 6 min, 43 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\HOWTOSIMPLIFIEDTOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [341], [301125],1.0.1605 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HowToSimplifiedTooltab Uninstall Internet Explorer, Delete-on-Reboot, [341], [301125],1.0.1605 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HowToSimplifiedTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [341], [352442],1.0.1605 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [341], [293497],1.0.1605 Data Stream: 0 (No malicious items detected) Folder: 90 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\HowToSimplifiedTooltab, Delete-on-Reboot, [341], [368466],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\HowToSimplified_8e, Quarantined, [341], [240302],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\abstractbutton\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\thirdparty\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\uninstall\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\weather\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\weather\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\weather\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\generic\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\html, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\alert\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\link\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\weather, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\abstractbutton, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\html, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\rss\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\rss\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare\icons, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\images, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\rss, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\radioWrapper, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\thirdparty, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\html, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\html, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\foreground, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\uninstall, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\generic, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\weather, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\background, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\html, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\alert, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\html, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\link, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\rss, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\window, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\css, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\adapter, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\libs, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\_metadata, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MMGKBCIHAHPOCJMCLEHPJEJMGJMIJCIB, Quarantined, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\META-INF, Quarantined, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\chrome, Quarantined, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_8EMEMBERS_@DOWNLOAD.HOWTOSIMPLIFIED.COM, Quarantined, [341], [302304],1.0.1605 File: 289 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\HOWTOSIMPLIFIEDTOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [341], [301125],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1051], [319354],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\HowToSimplified_8e\{ptb2}.sqlite, Delete-on-Reboot, [341], [240302],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_howtosimplified.dl.myway.com_0.localstorage, Delete-on-Reboot, [341], [240305],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_howtosimplified.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [341], [240306],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\chrome-extension_mmgkbcihahpocjmclehpjejmgjmijcib_0.localstorage, Delete-on-Reboot, [341], [368479],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MMGKBCIHAHPOCJMCLEHPJEJMGJMIJCIB\12.600.11.3995_0\MANIFEST.JSON, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\menu\README.txt, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\bs.30.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\common.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\dynamic.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\enableDetect.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\global.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\messageEventListener.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\navRedirector.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\paramReplacer.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\PartnerId.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\set.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\foreground\button.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\background\searchBox.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\css\supertab.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\html\supertab.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js\reporting.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js\supertab.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\components\supertab\js\__utm.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\_metadata\computed_hashes.json, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\_metadata\verified_contents.json, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\arrowSprite.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\icon128.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\icon16.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\icon19disabled.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\icon19on.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\icon48.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\223764870.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\223764873.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\223764895.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\223764907.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\223764921.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\223764937.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\224383999.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\down_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\magnifying_glass.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\search_button.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\tvf_icon_guide.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\tvf_logo.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\images\wrench.png, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\newTabInitialize.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\chromeStorage.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\chromeUtils.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\companionSWUtils.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\exeManager.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\exeManagerNMD.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\exePackageManager.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\focusManager.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\globalBlacklistManager.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\messaging.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\mutation_summary-min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\mutation_summary.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\newTabInfo.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\options.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\readLocalStorage.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\reservespaceifenabled.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\scriptInjector.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\searchContext.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\settingsOverrides.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\toolbarCookieParser.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\toolbarPreinit.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\URILoaderContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\webTooltabAPI.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\Widget.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\widgetFactory.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\js\widgetWindowManager.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\cache.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\ce.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\debug.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\native\ss.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\activePing.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\buttonLogger.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\competitorDnsList.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\console.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\httpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\HttpURL.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\internationalSearch.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\rsvp-latest.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\testHttpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\unifiedLogger.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\universalConsole.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\shared\utils.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spent2.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\bg.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\buildVars, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\buildVars.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\companionSW.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\config.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\contentScript.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\contentScript.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\debug.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\debug.jade, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spentJ.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spentK.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spentK.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\startup.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\stub.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\stubby.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\superFrame.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\toolbar.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\toolbar.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\toolbarUI.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\toolbarUI.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\toolbarUI.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\url.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\urlFragmentActions.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\webtooltab.cs.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\extension_toolbar_api.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\initWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\newTabContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\options.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spent.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spent.html, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spent.js, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgkbcihahpocjmclehpjejmgjmijcib\12.600.11.3995_0\spent2.css, Delete-on-Reboot, [341], [301932],1.0.1605 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_8EMEMBERS_@DOWNLOAD.HOWTOSIMPLIFIED.COM\INSTALL.RDF, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\chrome\ffxtbr.jar, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\META-INF\manifest.mf, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\META-INF\mozilla.rsa, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\META-INF\mozilla.sf, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\bootstrap.js, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\chrome.manifest, Delete-on-Reboot, [341], [302304],1.0.1605 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_8eMembers_@download.howtosimplified.com\chrome.manifest.restartless, Delete-on-Reboot, [341], [302304],1.0.1605 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  3. What is RegistryCleanerPro? The Malwarebytes research team has determined that RegistryCleanerPro is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with RegistryCleanerPro? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, startmenu and on your desktop: and see these warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: How did RegistryCleanerPro get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove RegistryCleanerPro? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of RegistryCleanerPro? No, Malwarebytes removes RegistryCleanerPro completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the RegistryCleanerPro installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\RegistryCleanerPro\RegistryCleanerPro.exe C:\Users\{username}\Desktop\RegistryCleanerPro.lnk C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegistryCleanerPro C:\ProgramData\RegClean C:\Program Files (x86)\RegistryCleanerPro RegistryCleanerPro (HKLM-x32\...\RegistryCleanerPro) (Version: 38.1 - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\RegistryCleanerPro Adds the file RegistryCleanerPro.exe"="7/6/2016 9:47 AM, 2074888 bytes, A Adds the file uninst.exe"="3/24/2017 1:19 PM, 63446 bytes, A Adds the folder C:\ProgramData\RegClean\Backups Adds the folder C:\ProgramData\RegClean\Logs Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegistryCleanerPro Adds the file RegistryCleanerPro.lnk"="3/24/2017 1:19 PM, 1163 bytes, A Adds the file Uninstall.lnk"="3/24/2017 1:19 PM, 886 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file RegistryCleanerPro.lnk"="3/24/2017 1:19 PM, 1127 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\RegistryCleanerPro.exe] "(Default)"="REG_SZ", "C:\Program Files (x86)\RegistryCleanerPro\RegistryCleanerPro.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RegistryCleanerPro] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\RegistryCleanerPro\RegistryCleanerPro.exe" "DisplayName"="REG_SZ", "RegistryCleanerPro" "DisplayVersion"="REG_SZ", "38.1" "NSIS:Language"="REG_SZ", "1033" "Publisher"="REG_SZ", "" "UninstallString"="REG_SZ", "C:\Program Files (x86)\RegistryCleanerPro\uninst.exe" "URLInfoAbout"="REG_SZ", "" [HKEY_CURRENT_USER\Software\RegistryCleanerPro] "Activated"="REG_DWORD", 0 "AutoRun"="REG_DWORD", 0 "BackupDir"="REG_SZ", "Backup\" "CloseToTray"="REG_DWORD", 1 "CreateSysRestore"="REG_DWORD", 1 "DelBackupAfterRest"="REG_DWORD", 1 "ErrFixed"="REG_DWORD", 0 "ErrFound"="REG_DWORD", 0 "IDLang"="REG_DWORD", 0 "IgnoreMisFiles"="REG_DWORD", 1 "InstallID"="REG_SZ", "392E1F6F1FF35BFF17795243EEF9B66A" "LastAnalizeDatei"="REG_BINARY, .... "LastAnalizeRes"="REG_SZ", "" "LastBackupDatei"="REG_BINARY, .... "LastDefragDatei"="REG_BINARY, .... "LastFixDatei"="REG_BINARY, .... "LastScanDatei"="REG_BINARY, .... "Partner"="REG_SZ", "from_stw" "ProxyHost"="REG_SZ", "" "ProxyLogin"="REG_SZ", "" "ProxyPassw"="REG_SZ", "" "ProxyPort"="REG_SZ", "" "SerialNum"="REG_SZ", "" "Subtrack"="REG_SZ", "" "TrialFix"="REG_DWORD", 1 "UseProxy"="REG_DWORD", 0 [HKEY_CURRENT_USER\Software\RegistryCleanerPro\Excludes] [HKEY_CURRENT_USER\Software\RegistryCleanerPro\LastDefragRes] "ItemsCount"="REG_DWORD", 0 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/24/17 Scan Time: 1:30 PM Logfile: mbamRegistryCleanerPro.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1584 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 366305 Time Elapsed: 6 min, 38 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\REGISTRYCLEANERPRO\REGISTRYCLEANERPRO.EXE, Quarantined, [1897], [369663],1.0.1584 Module: 1 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\REGISTRYCLEANERPRO\REGISTRYCLEANERPRO.EXE, Quarantined, [1897], [369663],1.0.1584 Registry Key: 1 Rogue.RegistryCleanerPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RegistryCleanerPro, Delete-on-Reboot, [13781], [171218],1.0.1584 Registry Value: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 2 Rogue.RegistryCleanerPro, C:\PROGRAM FILES (X86)\RegistryCleanerPro, Delete-on-Reboot, [13781], [171218],1.0.1584 Rogue.RegistryCleanerPro, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\REGISTRYCLEANERPRO, Delete-on-Reboot, [13781], [171855],1.0.1584 File: 6 PUP.Optional.oTweak, C:\PROGRAM FILES (X86)\REGISTRYCLEANERPRO\REGISTRYCLEANERPRO.EXE, Delete-on-Reboot, [1897], [369663],1.0.1584 Rogue.RegistryCleanerPro, C:\USERS\{username}\DESKTOP\REGISTRYCLEANERPRO.LNK, Delete-on-Reboot, [13781], [199819],1.0.1584 PUP.Optional.oTweak, C:\USERS\{username}\DESKTOP\REGISTRYCLEANERPRO.EXE, Delete-on-Reboot, [1897], [369663],1.0.1584 Rogue.RegistryCleanerPro, C:\Program Files (x86)\RegistryCleanerPro\uninst.exe, Delete-on-Reboot, [13781], [171218],1.0.1584 Rogue.RegistryCleanerPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegistryCleanerPro\RegistryCleanerPro.lnk, Delete-on-Reboot, [13781], [171855],1.0.1584 Rogue.RegistryCleanerPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegistryCleanerPro\Uninstall.lnk, Delete-on-Reboot, [13781], [171855],1.0.1584 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  4. What is FlowSpirit? The Malwarebytes research team has determined that FlowSpirit is riskware. This particular one uses your computer to generate traffic to certain websites. How do I know if my computer is affected by FlowSpirit? You may see these screens while the application is running: You may also see some alarms or reports regarding outgoing connections to many different domains and your system may be very slow and unresponsive. How did FlowSpirit get on my computer? Riskware use different methods for distributing themselves. This particular one was offered as a SEO enhancer. How do I remove FlowSpirit? Our program Malwarebytes can detect and remove this riskware. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of FlowSpirit? No, Malwarebytes removes FlowSpirit completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this riskware. As you can see below the full version of Malwarebytes would have protected you against the FlowSpirit riskware. It would have warned you before the riskware could install itself, giving you a chance to stop it before it became too late. and it blocks the traffic to many of the domains the software tries to visit: Technical details for experts Note that the name and the location of the file may be different from case to case. Possible signs in FRST logs: (精灵软件) C:\Users\{username}\Desktop\jingling.exe HKCU\...\Run: [urlspace] => C:\Users\{username}\Desktop\jingling.exe [649728 2017-03-23] (精灵软件) C:\Users\{username}\AppData\Roaming\Spiritsoft FirewallRules: [{B0F3CC9A-A947-4CB2-80BF-B0F6DAB7E74B}] => (Allow) C:\Users\{username}\Desktop\jingling.exe FirewallRules: [{E87455BD-A5EB-4F45-9870-B356FAD34132}] => (Allow) C:\Users\{username}\Desktop\jingling.exe Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\Spiritsoft\urlspirit Adds the file bd.dat"="3/23/2017 11:14 AM, 13952 bytes, A Adds the file product.dat"="3/23/2017 11:14 AM, 197 bytes, A Adds the file tcfg.dat"="3/23/2017 11:14 AM, 1915 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "urlspace"="REG_SZ", "C:\Users\{username}\Desktop\jingling.exe -h" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/23/17 Scan Time: 11:28 AM Logfile: mbamFlowSpirit.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1575 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 366384 Time Elapsed: 8 min, 33 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 2 PUP.Optional.FlowSpirit, C:\USERS\{username}\DESKTOP\JINGLING.EXE, Quarantined, [8098], [121961],1.0.1575 PUP.Optional.FlowSpirit, C:\USERS\{username}\DESKTOP\JINGLING.EXE, Quarantined, [8098], [121961],1.0.1575 Module: 2 PUP.Optional.FlowSpirit, C:\USERS\{username}\DESKTOP\JINGLING.EXE, Quarantined, [8098], [121961],1.0.1575 PUP.Optional.FlowSpirit, C:\USERS\{username}\DESKTOP\JINGLING.EXE, Quarantined, [8098], [121961],1.0.1575 Registry Key: 0 (No malicious items detected) Registry Value: 1 PUP.Optional.FlowSpirit, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|urlspace, Delete-on-Reboot, [8098], [121961],1.0.1575 Data Stream: 0 (No malicious items detected) Folder: 1 PUP.Optional.FlowSpirit, C:\USERS\{username}\APPDATA\ROAMING\SPIRITSOFT\URLSPIRIT, Delete-on-Reboot, [8098], [302708],1.0.1575 File: 4 PUP.Optional.FlowSpirit, C:\USERS\{username}\DESKTOP\JINGLING.EXE, Delete-on-Reboot, [8098], [121961],1.0.1575 PUP.Optional.FlowSpirit, C:\USERS\{username}\APPDATA\ROAMING\SPIRITSOFT\URLSPIRIT\PRODUCT.DAT, Delete-on-Reboot, [8098], [302708],1.0.1575 PUP.Optional.FlowSpirit, C:\Users\{username}\AppData\Roaming\Spiritsoft\urlspirit\bd.dat, Delete-on-Reboot, [8098], [302708],1.0.1575 PUP.Optional.FlowSpirit, C:\Users\{username}\AppData\Roaming\Spiritsoft\urlspirit\tcfg.dat, Delete-on-Reboot, [8098], [302708],1.0.1575 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  5. I don't think so. Still running now?
  6. Hi 420Rancher, Please follow the instructions outlined here: and let us know how that works out for you.
  7. What is Cyboscan PC Optimizer? The Malwarebytes research team has determined that Cyboscan PC Optimizer is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with Cyboscan PC Optimizer? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, startmenu and on your desktop: and see these warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: How did Cyboscan PC Optimizer get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove Cyboscan PC Optimizer? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Cyboscan PC Optimizer? No, Malwarebytes removes Cyboscan PC Optimizer completely. The shortcut called PC Optimizer on the desktop can be deleted if it belonged to the rogue. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the Cyboscan PC Optimizer installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: (Cyboscan) C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\PC Optimizer.exe C:\Users\Public\Desktop\PC Optimizer.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyboscan PC Optimizer C:\Program Files (x86)\Cyboscan Cyboscan PC Optimizer (HKLM-x32\...\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}) (Version: 1.0.0 - Cyboscan) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer Adds the file license.rtf"="6/19/2016 4:13 AM, 37632 bytes, A Adds the file PC Optimizer.exe"="8/30/2016 12:50 AM, 6997032 bytes, A Adds the file PC Optimizer.ico"="1/13/2013 11:35 PM, 67646 bytes, A Adds the file PC Optimizer.InstallState"="3/21/2017 9:20 AM, 2012 bytes, A Adds the file Updater.exe"="7/3/2016 9:30 PM, 867368 bytes, A Adds the file VTRegScan.dll"="8/8/2016 2:24 AM, 76800 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyboscan PC Optimizer Adds the file PC Optimizer.lnk"="3/21/2017 9:20 AM, 2641 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file PC Optimizer.lnk"="3/21/2017 9:20 AM, 2623 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\AEFEF55E605FCD747AE6F967866D5E9C] "AdvertiseFlags"="REG_DWORD", 388 "Assignment"="REG_DWORD", 1 "AuthorizedLUAApp"="REG_DWORD", 0 "Clients"="REG_MULTI_SZ, ": " "DeploymentFlags"="REG_DWORD", 3 "InstanceType"="REG_DWORD", 0 "Language"="REG_DWORD", 1033 "PackageCode"="REG_SZ", "C06C709E6930A524F88E01D2F666C06A" "ProductIcon"="REG_SZ", "C:\Windows\Installer\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}\_6FEFF9B68218417F98F549.exe" "ProductName"="REG_SZ", "Cyboscan PC Optimizer" "Version"="REG_DWORD", 16777216 [HKEY_LOCAL_MACHINE\SOFTWARE\Cyboscan] "LastScan"="REG_SZ", "ALTWXVhYGoxLJgNg5Q6Ff57gBHQOECeNcoW7+g9pbkbPouq9dwyeE2" "LCV"="REG_SZ", "dudFpXj7i+z9Ndtz5/Oond5mtSPpC8dbLi/ALqEL+PGGb2KclARFwuWFSVsa3+lHk9QRaDRzEEp1MWmvBxbIY6BQAjP8eyl5oYQeCdW6qI8fzhAQt73YQRSiEcvSz6VQ==" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}] "AuthorizedCDFPrefix"="REG_SZ", "" "Comments"="REG_SZ", "" "Contact"="REG_SZ", "Cyboscan" "DisplayName"="REG_SZ", "Cyboscan PC Optimizer" "DisplayVersion"="REG_SZ", "1.0.0" "EstimatedSize"="REG_DWORD", 7857 "HelpLink"="REG_EXPAND_SZ, "https://cyboscan.com/product-support.html" "HelpTelephone"="REG_SZ", "1-800-874-5207" "InstallDate"="REG_SZ", "20170321" "InstallLocation"="REG_SZ", "" "InstallSource"="REG_SZ", "C:\Users\{username}1\AppData\Local\Temp\" "Language"="REG_DWORD", 1033 "ModifyPath"="REG_EXPAND_SZ, "MsiExec.exe /I{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}" "Publisher"="REG_SZ", "Cyboscan" "Readme"="REG_SZ", "" "Size"="REG_SZ", "" "UninstallString"="REG_EXPAND_SZ, "MsiExec.exe /I{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}" "URLInfoAbout"="REG_SZ", "https://cyboscan.com" "URLUpdateInfo"="REG_SZ", "" "Version"="REG_DWORD", 16777216 "VersionMajor"="REG_DWORD", 1 "VersionMinor"="REG_DWORD", 0 "WindowsInstaller"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/22/17 Scan Time: 9:27 AM Logfile: mbamCyboscan.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1566 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 366197 Time Elapsed: 6 min, 13 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\PC Optimizer.exe, Quarantined, [10474], [382426],1.0.1566 Module: 1 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\PC Optimizer.exe, Quarantined, [10474], [382426],1.0.1566 Registry Key: 2 PUP.Optional.Cyboscan, HKLM\SOFTWARE\CYBOSCAN, Delete-on-Reboot, [10474], [382427],1.0.1566 PUP.Optional.Cyboscan, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}, Delete-on-Reboot, [10474], [382428],1.0.1566 Registry Value: 1 PUP.Optional.Cyboscan, HKLM\SOFTWARE\CYBOSCAN|LASTSCAN, Delete-on-Reboot, [10474], [382427],1.0.1566 Data Stream: 0 (No malicious items detected) Folder: 4 PUP.Optional.Cyboscan, C:\WINDOWS\INSTALLER\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}, Delete-on-Reboot, [10474], [382425],1.0.1566 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\PROGRAM FILES (X86)\CYBOSCAN, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBOSCAN PC OPTIMIZER, Delete-on-Reboot, [10474], [382424],1.0.1566 File: 11 PUP.Optional.Cyboscan, C:\USERS\{username}\DESKTOP\CYBOSCAN SETUP.EXE, Delete-on-Reboot, [10474], [382423],1.0.1566 PUP.Optional.Cyboscan, C:\Windows\Installer\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}\_6FEFF9B68218417F98F549.exe, Delete-on-Reboot, [10474], [382425],1.0.1566 PUP.Optional.Cyboscan, C:\Windows\Installer\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}\_8CCE24101D42B6DCB5D32C.exe, Delete-on-Reboot, [10474], [382425],1.0.1566 PUP.Optional.Cyboscan, C:\Windows\Installer\{E55FEFEA-F506-47DC-A76E-9F7668D6E5C9}\_D6B2CD523FE79472C109AD.exe, Delete-on-Reboot, [10474], [382425],1.0.1566 PUP.Optional.Cyboscan, C:\PROGRAM FILES (X86)\CYBOSCAN\CYBOSCAN PC OPTIMIZER\LICENSE.RTF, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\PC Optimizer.exe, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\PC Optimizer.ico, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\PC Optimizer.InstallState, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\Updater.exe, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\Program Files (x86)\Cyboscan\Cyboscan PC Optimizer\VTRegScan.dll, Delete-on-Reboot, [10474], [382426],1.0.1566 PUP.Optional.Cyboscan, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyboscan PC Optimizer\PC Optimizer.lnk, Delete-on-Reboot, [10474], [382424],1.0.1566 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  8. What is My News Wire? The Malwarebytes research team has determined that My News Wire is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. My News Wire is a member of the Spigot family as described in the blogpost Spigot browser hijackers. How do I know if my computer is affected by My News Wire? You may see these browser extensions/add-ons: and this new default search provider: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browser(s): How did My News Wire get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove My News Wire? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of My News Wire? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the My News Wire entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the My News Wire hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.mynewswire.co/?source=-v2&uid={uid1}&uc={date}&ap=appfocus1&i_id=currentnews__1.30 SearchScopes: HKCU -> DefaultScope {629E4DAA-E816-488D-AB8A-72C4BE213E47} URL = hxxp://search.mynewswire.co/s?source=-v2&uid={uid1}&uc={date}&ap=appfocus1&i_id=currentnews__1.30&query={searchTerms} SearchScopes: HKCU -> {629E4DAA-E816-488D-AB8A-72C4BE213E47} URL = hxxp://search.mynewswire.co/s?source=-v2&uid={uid1}&uc={date}&ap=appfocus1&i_id=currentnews__1.30&query={searchTerms} FF NewTab: hxxp://search.mynewswire.co?uid={uid2}&uc={date}&ap=appfocus1&source=-v2&page=newtab&implementation_id=currentnews_0.2.0 FF Homepage: hxxp://search.mynewswire.co?uid={uid2}&uc={date}&ap=appfocus1&source=-v2&page=homepage&implementation_id=currentnews_0.2.0 FF Extension: News - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@News.xpi [2017-03-21] CHR Extension: (My News Wire) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd [2017-03-21] C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} My News Wire (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.6.0.2 - Cloud Installer) The most significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0 Adds the file background.js"="3/19/2017 4:51 PM, 15293 bytes, A Adds the file contentscript.js"="3/19/2017 4:51 PM, 1238 bytes, A Adds the file icon.png"="3/21/2017 6:08 PM, 8987 bytes, A Adds the file manifest.json"="3/21/2017 6:08 PM, 1395 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\clallljdjoonecnidmcnnnodeccbphkd Adds the file 000003.log"="3/21/2017 6:08 PM, 263 bytes, A Adds the file CURRENT"="3/21/2017 6:08 PM, 16 bytes, A Adds the file LOCK"="3/21/2017 6:08 PM, 0 bytes, A Adds the file LOG"="3/21/2017 6:21 PM, 410 bytes, A Adds the file LOG.old"="3/21/2017 6:08 PM, 184 bytes, A Adds the file MANIFEST-000001"="3/21/2017 6:08 PM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Adds the file Uninstall.exe"="3/21/2017 6:26 PM, 263168 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @News.xpi"="3/21/2017 6:24 PM, 25774 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@News\simple-storage Adds the file store.json"="3/21/2017 6:25 PM, 321 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.mynewswire.co/?source=-v2&uid={uid1}&uc={date}&ap=appfocus1&i_id=currentnews__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{629E4DAA-E816-488D-AB8A-72C4BE213E47}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{629E4DAA-E816-488D-AB8A-72C4BE213E47}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.mynewswire.co/s?source=-v2&uid={uid1}&uc={date}&ap=appfocus1&i_id=currentnews__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "My News Wire" "DisplayVersion"="REG_SZ", "2.6.0.2" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\" "Publisher"="REG_SZ", "Cloud Installer" "UninstallHomepage"="REG_SZ", "http://search.mynewswire.co/?source=-v2&uid={uid1}&uc={date}&ap=appfocus1&i_id=currentnews__1.30" "UninstallImpression"="REG_SZ", "http://imp.mynewswire.co/impression.do?source=-v2&sub_id={date}&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=appfocus1&user_id={uid1}&implementation_id=currentnews__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe" /uninstall" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/21/17 Scan Time: 6:34 PM Logfile: mbamMyNewsWire.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1556 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 365982 Time Elapsed: 8 min, 23 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [814], [373878],1.0.1556 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{629E4DAA-E816-488D-AB8A-72C4BE213E47}, Delete-on-Reboot, [2371], [368913],1.0.1556 Registry Value: 2 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{629E4DAA-E816-488D-AB8A-72C4BE213E47}|URL, Delete-on-Reboot, [2371], [368913],1.0.1556 PUP.Optional.MyNewsWire, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [3142], [360171],1.0.1556 Data Stream: 0 (No malicious items detected) Folder: 14 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Quarantined, [814], [373878],1.0.1556 PUP.Optional.MyCurrentNews, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@News\simple-storage, Quarantined, [2596], [358267],1.0.1556 PUP.Optional.MyCurrentNews, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@NEWS, Quarantined, [2596], [358267],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\_locales\en, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\html\popup, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\_metadata, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\js\popup, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\_locales, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\newtab, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\html, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\css, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\js, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0, Quarantined, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CLALLLJDJOONECNIDMCNNNODECCBPHKD, Quarantined, [2371], [362981],1.0.1556 File: 19 PUP.Optional.Spigot, C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe, Delete-on-Reboot, [814], [373878],1.0.1556 PUP.Optional.MyNewsWire, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [3142], [360167],1.0.1556 PUP.Optional.MyNewsWire, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [3142], [360169],1.0.1556 PUP.Optional.MyCurrentNews, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@News\simple-storage\store.json, Delete-on-Reboot, [2596], [358267],1.0.1556 PUP.Optional.MyCurrentNews, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@NEWS.XPI, Delete-on-Reboot, [2596], [358285],1.0.1556 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CLALLLJDJOONECNIDMCNNNODECCBPHKD\2.0_0\BACKGROUND.JS, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\css\description.css, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\css\popup.css, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\html\popup\description.html, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\html\popup\popup.html, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\js\popup\popup.js, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\js\userNewTab.js, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\newtab\newtab.html, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\_locales\en\messages.json, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\_metadata\computed_hashes.json, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\_metadata\verified_contents.json, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\contentscript.js, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\icon.png, Delete-on-Reboot, [2371], [362981],1.0.1556 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\clallljdjoonecnidmcnnnodeccbphkd\2.0_0\manifest.json, Delete-on-Reboot, [2371], [362981],1.0.1556 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  9. What is EasyFileConvert? The Malwarebytes research team has determined that EasyFileConvert is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. EasyFileConvert is a Mindspark/Ask toolbar now known as IAC Applications. How do I know if my computer is affected by EasyFileConvert? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: this type of warning during install: and this new startpage in the affected browsers: How did EasyFileConvert get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove EasyFileConvert? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of EasyFileConvert? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the EasyFileConvert entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the EasyFileConvert hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/easyfileconvert/ttab02/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/easyfileconvert/ttab02/index.html?coId={coid2}&subId&ln=en&n={n2}&ptb={ptb2}&st=tab&p2={p22}&si FF Extension: EasyFileConvert - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_hpMembers_@free.easyfileconvert.com [2017-03-20] CHR Extension: (EasyFileConvert) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo [2017-03-20] C:\Users\{username}\AppData\Local\EasyFileConvertTooltab EasyFileConvert Internet Explorer Homepage and New Tab (HKCU\...\EasyFileConvertTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION The most significant changes made by the installlers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\EasyFileConvertTooltab Adds the file TooltabExtension.dll"="12/22/2016 5:55 PM, 266864 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0 Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\EasyFileConvert_hp Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com Adds the file bootstrap.js"="3/20/2017 9:53 AM, 24730 bytes, A Adds the file chrome.manifest"="3/20/2017 9:53 AM, 135 bytes, A Adds the file chrome.manifest.restartless"="3/20/2017 9:53 AM, 135 bytes, A Adds the file install.rdf"="3/20/2017 9:53 AM, 1431 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\chrome Adds the file ffxtbr.jar"="3/20/2017 9:53 AM, 348229 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\META-INF Adds the file manifest.mf"="3/20/2017 9:53 AM, 680 bytes, A Adds the file mozilla.rsa"="3/20/2017 9:53 AM, 4194 bytes, A Adds the file mozilla.sf"="3/20/2017 9:53 AM, 121 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\EasyFileConvert] "Start Page"="REG_SZ", "http://hp.myway.com/easyfileconvert/ttab02/index.html?n={n1}&p2={p23}&ptb={ptb1}&coid={coid1}" "UnInstallSurveyUrl"="REG_SZ", "http://@{downloadDomain}.dl.myway.com/uninstall.jhtml?surveyUrl=http%3A%2F%2Fwww.research.net%2Fr%2%3F%3D{ptb1}%26ptb%3&quot;!!~~~~~~~~~~ie-sucks~~~~~~~~~~~~!! [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://hp.myway.com/easyfileconvert/ttab02/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\EasyFileConvertTooltab Uninstall Internet Explorer] "DisplayName"="REG_SZ", "EasyFileConvert Internet Explorer Homepage and New Tab" "HelpLink"="REG_SZ", "http://support.mindspark.com/" "Publisher"="REG_SZ", "Mindspark Interactive Network, Inc." "UninstallString"="REG_SZ", "Rundll32.exe "C:\Users\{username}\AppData\Local\EasyFileConvertTooltab\TooltabExtension.dll" U uninstall:EasyFileConvert" "URLInfoAbout"="REG_SZ", "http://support.mindspark.com/" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/20/17 Scan Time: 10:06 AM Logfile: mbamEasYFileConvert.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1543 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 365581 Time Elapsed: 6 min, 50 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\EASYFILECONVERTTOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [341], [301125],1.0.1543 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\EasyFileConvertTooltab Uninstall Internet Explorer, Delete-on-Reboot, [341], [301125],1.0.1543 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\EasyFileConvertTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [341], [352442],1.0.1543 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [341], [293497],1.0.1543 Data Stream: 0 (No malicious items detected) Folder: 89 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\EasyFileConvertTooltab, Delete-on-Reboot, [1052], [356944],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\META-INF, Quarantined, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\chrome, Quarantined, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_HPMEMBERS_@FREE.EASYFILECONVERT.COM, Quarantined, [1052], [371671],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\abstractbutton\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\thirdparty\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\uninstall\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\weather\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\weather\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\weather\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\generic\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\html, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\alert\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\link\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\weather, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\abstractbutton, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\html, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\rss\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\rss\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare\icons, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\images, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\rss, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\radioWrapper, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\thirdparty, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\html, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\html, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\foreground, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\uninstall, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\generic, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\weather, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\background, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\html, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\alert, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\html, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\link, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\rss, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\window, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\css, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\adapter, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\libs, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\_metadata, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0, Quarantined, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MAFFOOJMAAFJMMOHKHHCLGJJMGHLIFJO, Quarantined, [341], [301932],1.0.1543 File: 287 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\EASYFILECONVERTTOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [341], [301125],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [319354],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [1052], [356946],1.0.1543 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_easyfileconvert.dl.myway.com_0.localstorage, Delete-on-Reboot, [341], [240305],1.0.1543 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_easyfileconvert.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [341], [240306],1.0.1543 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\_HPMEMBERS_@FREE.EASYFILECONVERT.COM\BOOTSTRAP.JS, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\chrome\ffxtbr.jar, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\META-INF\manifest.mf, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\META-INF\mozilla.rsa, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\META-INF\mozilla.sf, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\chrome.manifest, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\chrome.manifest.restartless, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions\_hpMembers_@free.easyfileconvert.com\install.rdf, Delete-on-Reboot, [1052], [371671],1.0.1543 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MAFFOOJMAAFJMMOHKHHCLGJJMGHLIFJO\12.202.10.29521_0\MANIFEST.JSON, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\menu\README.txt, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\bs.30.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\common.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\dynamic.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\enableDetect.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\global.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\messageEventListener.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\navRedirector.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\paramReplacer.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\PartnerId.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\set.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\foreground\button.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\background\searchBox.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\css\supertab.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\html\supertab.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js\reporting.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js\supertab.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\components\supertab\js\__utm.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\arrowSprite.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\icon128.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\icon16.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\icon19disabled.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\icon19on.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\icon48.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230488678.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230488714.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230488717.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230488753.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230488770.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230539377.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\230720518.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\down_arrow.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\magnifying_glass.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\search_button.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\tvf_icon_guide.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\tvf_logo.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\images\wrench.png, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\newTabInitialize.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\chromeStorage.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\chromeUtils.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\companionSWUtils.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\exeManager.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\exeManagerNMD.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\exePackageManager.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\focusManager.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\globalBlacklistManager.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\messaging.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\mutation_summary-min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\mutation_summary.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\newTabInfo.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\options.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\readLocalStorage.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\reservespaceifenabled.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\scriptInjector.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\searchContext.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\settingsOverrides.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\toolbarCookieParser.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\toolbarPreinit.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\URILoaderContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\webTooltabAPI.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\Widget.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\widgetFactory.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\js\widgetWindowManager.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\cache.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\ce.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\debug.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\native\ss.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\activePing.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\buttonLogger.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\competitorDnsList.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\console.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\httpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\HttpURL.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\internationalSearch.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\rsvp-latest.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\testHttpTransport.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\unifiedLogger.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\unifiedLogging.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\universalConsole.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\shared\utils.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\_metadata\computed_hashes.json, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\_metadata\verified_contents.json, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spent.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\bg.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\buildVars, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\buildVars.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\companionSW.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\config.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\contentScript.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\contentScript.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\debug.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\debug.jade, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\extension_toolbar_api.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\initWidgetWindow.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\newTabContentScript.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\options.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spent.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spent.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spent2.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spent2.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spentJ.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spentK.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\spentK.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\startup.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\stub.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\stubby.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\superFrame.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\toolbar.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\toolbar.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\toolbarUI.css, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\toolbarUI.html, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\toolbarUI.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\url.js, Delete-on-Reboot, [341], [301932],1.0.1543 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\maffoojmaafjmmohkhhclgjjmghlifjo\12.202.10.29521_0\webtooltab.cs.js, Delete-on-Reboot, [341], [301932],1.0.1543 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  10. What is InternetSpeedPilot? The Malwarebytes research team has determined that InternetSpeedPilot is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. InternetSpeedPilot is a member of the Spigot family as described in the blogpost Spigot browser hijackers. How do I know if my computer is affected by InternetSpeedPilot? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: these warnings during install: this new default search provider: and this new startpage in the affected browser(s): How did InternetSpeedPilot get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove InternetSpeedPilot? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of InternetSpeedPilot? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the InternetSpeedPilot entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the InternetSpeedPilot hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.internetspeedpilot.com/?source=-bb8&uid={uid1}&uc=20170317&ap=&i_id=speedtest__1.30 SearchScopes: HKCU -> DefaultScope {3F5A5BA6-E379-41ED-9F33-B612ADC0F5D1} URL = hxxp://search.internetspeedpilot.com/s?source=-bb8&uid={uid1}&uc=20170317&ap=&i_id=speedtest__1.30&query={searchTerms} SearchScopes: HKCU -> {3F5A5BA6-E379-41ED-9F33-B612ADC0F5D1} URL = hxxp://search.internetspeedpilot.com/s?source=-bb8&uid={uid1}&uc=20170317&ap=&i_id=speedtest__1.30&query={searchTerms} FF NewTab: hxxp://search.internetspeedpilot.com?uid=3f47c94a-162d-4706-9adb-f2c13e47d883&uc=20170317&ap=&source=tt&page=newtab&implementation_id=speedtest_0.2.0 FF Homepage: hxxp://search.internetspeedpilot.com?uid=3f47c94a-162d-4706-9adb-f2c13e47d883&uc=20170317&ap=&source=tt&page=homepage&implementation_id=speedtest_0.2.0 FF Extension: Speedtest - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\@Speedtest.xpi [2017-03-17] CHR Extension: (Internet Speed Pilot) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh [2017-03-17] C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Internet Speed Pilot (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.6.0.2 - Cloud Installer) Most significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0 Adds the file background.js"="11/11/2016 3:32 PM, 15408 bytes, A Adds the file contentscript.js"="11/11/2016 3:32 PM, 1238 bytes, A Adds the file icon.png"="3/17/2017 11:32 AM, 2458 bytes, A Adds the file manifest.json"="3/17/2017 11:32 AM, 1404 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\dadnfmoeipnlmdlfoioabgopkajneldh Adds the file 000003.log"="3/17/2017 11:32 AM, 248 bytes, A Adds the file CURRENT"="3/17/2017 11:32 AM, 16 bytes, A Adds the file LOCK"="3/17/2017 11:32 AM, 0 bytes, A Adds the file LOG"="3/17/2017 11:32 AM, 184 bytes, A Adds the file MANIFEST-000001"="3/17/2017 11:32 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Adds the file Uninstall.exe"="3/17/2017 11:25 AM, 263168 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file @Speedtest.xpi"="3/17/2017 11:29 AM, 20651 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Speedtest\simple-storage Adds the file store.json"="3/17/2017 11:30 AM, 319 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.internetspeedpilot.com/?source=-bb8&uid={uid1}&uc=20170317&ap=&i_id=speedtest__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" = REG_SZ, "{3F5A5BA6-E379-41ED-9F33-B612ADC0F5D1}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3F5A5BA6-E379-41ED-9F33-B612ADC0F5D1}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.internetspeedpilot.com/s?source=-bb8&uid={uid1}&uc=20170317&ap=&i_id=speedtest__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "Internet Speed Pilot" "DisplayVersion"="REG_SZ", "2.6.0.2" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\" "Publisher"="REG_SZ", "Cloud Installer" "UninstallHomepage"="REG_SZ", "http://search.internetspeedpilot.com/?source=-bb8&uid={uid1}&uc=20170317&ap=&i_id=speedtest__1.30" "UninstallImpression"="REG_SZ", "http://imp.internetspeedpilot.com/impression.do?source=-bb8&sub_id=20170317&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=&user_id={uid1}&implementation_id=speedtest__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe" /uninstall" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/17/17 Scan Time: 11:42 AM Logfile: mbamInternetSpeedPilot.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1522 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 365272 Time Elapsed: 7 min, 28 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [813], [373878],1.0.1522 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3F5A5BA6-E379-41ED-9F33-B612ADC0F5D1}, Delete-on-Reboot, [2369], [368913],1.0.1522 Registry Value: 2 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [2369], [373048],1.0.1522 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3F5A5BA6-E379-41ED-9F33-B612ADC0F5D1}|URL, Delete-on-Reboot, [2369], [368913],1.0.1522 Data Stream: 0 (No malicious items detected) Folder: 14 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Quarantined, [813], [373878],1.0.1522 PUP.Optional.YourSpeedTestCenter, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Speedtest\simple-storage, Quarantined, [11557], [182698],1.0.1522 PUP.Optional.YourSpeedTestCenter, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\JETPACK\@SPEEDTEST, Quarantined, [11557], [182698],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\_locales\en, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\html\popup, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\_metadata, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\js\popup, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\_locales, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\newtab, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\html, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\css, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\js, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0, Quarantined, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\DADNFMOEIPNLMDLFOIOABGOPKAJNELDH, Quarantined, [2369], [362981],1.0.1522 File: 19 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [2369], [361537],1.0.1522 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\PREFS.JS, Removal Failed, [2369], [361538],1.0.1522 PUP.Optional.Spigot, C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe, Delete-on-Reboot, [813], [373878],1.0.1522 PUP.Optional.YourSpeedTestCenter, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NCH5MQSA.DEFAULT\EXTENSIONS\@SPEEDTEST.XPI, Delete-on-Reboot, [11557], [182771],1.0.1522 PUP.Optional.YourSpeedTestCenter, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\jetpack\@Speedtest\simple-storage\store.json, Delete-on-Reboot, [11557], [182698],1.0.1522 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\DADNFMOEIPNLMDLFOIOABGOPKAJNELDH\3.0_0\BACKGROUND.JS, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\css\description.css, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\css\popup.css, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\html\popup\description.html, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\html\popup\popup.html, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\js\popup\popup.js, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\js\userNewTab.js, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\newtab\newtab.html, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\_locales\en\messages.json, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\_metadata\computed_hashes.json, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\_metadata\verified_contents.json, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\contentscript.js, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\icon.png, Delete-on-Reboot, [2369], [362981],1.0.1522 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dadnfmoeipnlmdlfoioabgopkajneldh\3.0_0\manifest.json, Delete-on-Reboot, [2369], [362981],1.0.1522 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  11. What is PC Health Advisor? The Malwarebytes research team has determined that PC Health Advisor is a "system optimizer". These so-called "system optimizers" sometimes use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with PC Health Advisor? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, startmenu, and on your desktop: and see these warnings during install: and this screen when you try to remediate the alleged problems: You may see this entry in your list of installed programs: How did PC Health Advisor get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from an affiliate site. How do I remove PC Health Advisor? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of PC Health Advisor? No, Malwarebytes removes PC Health Advisor completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the PC Health Advisor installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domains and some of their affiliates. Technical details for experts You may see these entries in FRST logs: (ParetoLogic) C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe (Digital Care Solutions) C:\Program Files\BDServices\BitDefenderCOM.exe R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1028096 2016-12-12] (Digital Care Solutions) [File not signed] S3 scan; C:\Program Files\BDServices\scan.dll [627688 2016-12-12] (Bitdefender) R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [485512 2016-12-12] (BitDefender S.R.L.) C:\Users\{username}\AppData\Roaming\ParetoLogic C:\Windows\System32\Tasks\PC Health Advisor Startup C:\Program Files\BDServices C:\Windows\System32\Tasks\PC Health Advisor Update C:\Windows\System32\Tasks\PC Health Advisor C:\Windows\System32\Tasks\PC Health Advisor Defrag C:\Users\{username}\Desktop\ParetoLogic PC Health Advisor.lnk C:\Windows\Tasks\PC Health Advisor Update.job C:\Windows\Tasks\PC Health Advisor Startup.job C:\Windows\Tasks\PC Health Advisor Defrag.job C:\Windows\Tasks\PC Health Advisor.job C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic C:\ProgramData\ParetoLogic C:\Program Files (x86)\ParetoLogic ParetoLogic PC Health Advisor (HKLM-x32\...\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}) (Version: 3.2.8.0 - ParetoLogic, Inc.) Task: {6ABE739A-C6A0-47ED-B812-C3A6BC0361C3} - System32\Tasks\PC Health Advisor => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe [2017-01-18] (ParetoLogic) Task: {7E46AA87-95F8-4504-8034-B0F3724BE6B0} - System32\Tasks\PC Health Advisor Startup => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe [2017-01-18] (ParetoLogic) Task: {90E98E78-6DBD-4513-8FA6-FD1767EDC04F} - System32\Tasks\PC Health Advisor Update => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe [2017-01-18] (ParetoLogic) Task: {DF8FAF9B-104D-438F-955F-57D3CECF7060} - System32\Tasks\PC Health Advisor Defrag => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe [2017-01-18] (ParetoLogic) Task: C:\Windows\Tasks\PC Health Advisor Defrag.job => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe Task: C:\Windows\Tasks\PC Health Advisor Startup.job => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe1C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe Task: C:\Windows\Tasks\PC Health Advisor Update.job => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe Task: C:\Windows\Tasks\PC Health Advisor.job => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe () C:\Program Files (x86)\ParetoLogic\PCHA\LiteZip.dll () C:\Program Files (x86)\ParetoLogic\PCHA\ExtensionManager.dll () C:\Program Files (x86)\ParetoLogic\PCHA\CommonLoggingExtension.pxt () C:\Program Files (x86)\ParetoLogic\PCHA\CommonSpecialist.pxt () C:\Program Files (x86)\ParetoLogic\PCHA\RegHookSpecialist.pxt () C:\Program Files (x86)\ParetoLogic\PCHA\Utility.pxt () C:\Program Files (x86)\ParetoLogic\PCHA\LiteUnzip.dll The most significant alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\ParetoLogic\PCHA Adds the file 7ZipDLL.dll"="1/18/2017 10:48 PM, 563712 bytes, A Adds the file colors.xml"="1/18/2017 10:48 PM, 5980 bytes, A Adds the file CommonLoggingExtension.pxt"="1/18/2017 10:48 PM, 176640 bytes, A Adds the file CommonSpecialist.pxt"="1/18/2017 10:48 PM, 177664 bytes, A Adds the file DC_offer.exe"="1/18/2017 10:48 PM, 5382144 bytes, A Adds the file ExtensionManager.dll"="1/18/2017 10:48 PM, 117760 bytes, A Adds the file HandleUpdate.dll"="1/18/2017 10:48 PM, 1802752 bytes, A Adds the file libeay32.dll"="1/18/2017 10:48 PM, 2047488 bytes, A Adds the file License.rdat"="3/16/2017 9:05 AM, 0 bytes, A Adds the file License_Time.rdat"="3/16/2017 9:05 AM, 48 bytes, A Adds the file LiteUnzip.dll"="1/18/2017 10:48 PM, 47616 bytes, A Adds the file LiteZip.dll"="1/18/2017 10:48 PM, 39936 bytes, A Adds the file LogSettings.xml"="1/18/2017 10:48 PM, 992 bytes, A Adds the file msvcp120.dll"="1/18/2017 10:48 PM, 455328 bytes, A Adds the file msvcr120.dll"="1/18/2017 10:48 PM, 970912 bytes, A Adds the file MyResources.dll"="1/18/2017 10:49 PM, 590848 bytes, A Adds the file noapp.exe"="1/18/2017 10:49 PM, 1938944 bytes, A Adds the file PCHA.exe"="1/18/2017 10:49 PM, 4653048 bytes, A Adds the file privacy.db"="1/18/2017 10:48 PM, 44832 bytes, A Adds the file RB.rdat"="3/16/2017 9:05 AM, 48 bytes, A Adds the file RegHookSpecialist.pxt"="1/18/2017 10:48 PM, 166912 bytes, A Adds the file SandBoxer.dll"="1/18/2017 10:48 PM, 230912 bytes, A Adds the file settings.xml"="1/18/2017 10:48 PM, 1145 bytes, A Adds the file sqlite3.dll"="1/18/2017 10:48 PM, 333043 bytes, A Adds the file ssleay32.dll"="1/18/2017 10:48 PM, 498176 bytes, A Adds the file uninstall.exe"="1/18/2017 10:49 PM, 260360 bytes, A Adds the file UNS.xml"="1/18/2017 10:48 PM, 950 bytes, A Adds the file Utility.pxt"="1/18/2017 10:48 PM, 928256 bytes, A Adds the file whitelist.dat"="1/18/2017 10:48 PM, 7528 bytes, A Adds the folder C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML Adds the file 0_days.htm"="1/18/2017 10:48 PM, 2671 bytes, A Adds the file 1_days.htm"="1/18/2017 10:48 PM, 2691 bytes, A Adds the file 15_days.htm"="1/18/2017 10:48 PM, 2765 bytes, A Adds the file 2_days.htm"="1/18/2017 10:48 PM, 2645 bytes, A Adds the file 30_days.htm"="1/18/2017 10:48 PM, 2684 bytes, A Adds the file 5_days.htm"="1/18/2017 10:48 PM, 2687 bytes, A Adds the file main.css"="1/18/2017 10:48 PM, 2051 bytes, A Adds the file main_error.css"="1/18/2017 10:48 PM, 4223 bytes, A Adds the folder C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images Adds the folder C:\Program Files (x86)\ParetoLogic\PCHA\HTML Adds the folder C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images Adds the folder C:\Program Files (x86)\ParetoLogic\PCHA\images Adds the folder C:\ProgramData\ParetoLogic\PC Health Advisor Adds the file License.rdat"="3/16/2017 9:06 AM, 0 bytes, A Adds the file License_FirstRun.rdat"="3/16/2017 9:06 AM, 48 bytes, A Adds the file License_Time.rdat"="3/16/2017 9:06 AM, 48 bytes, A Adds the file RB.rdat"="3/16/2017 9:06 AM, 48 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic\PC Health Advisor Adds the file ParetoLogic PC Health Advisor.lnk"="3/16/2017 9:05 AM, 1145 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\ParetoLogic\PC Health Advisor In the existing folder C:\Users\{username}\Desktop Adds the file ParetoLogic PC Health Advisor.lnk"="3/16/2017 9:05 AM, 1097 bytes, A In the existing folder C:\Windows\System32\drivers Adds the file Trufos.sys"="12/12/2016 6:42 PM, 485512 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file PC Health Advisor"="3/16/2017 9:05 AM, 3318 bytes, A Adds the file PC Health Advisor Defrag"="3/16/2017 9:05 AM, 3286 bytes, A Adds the file PC Health Advisor Startup"="3/16/2017 9:06 AM, 2616 bytes, A Adds the file PC Health Advisor Update"="3/16/2017 9:05 AM, 3318 bytes, A In the existing folder C:\Windows\Tasks Adds the file PC Health Advisor Defrag.job"="3/16/2017 9:05 AM, 408 bytes, A Adds the file PC Health Advisor Startup.job"="3/16/2017 9:05 AM, 428 bytes, A Adds the file PC Health Advisor Update.job"="3/16/2017 9:05 AM, 438 bytes, A Adds the file PC Health Advisor.job"="3/16/2017 9:05 AM, 390 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures] "PC Health Advisor Defrag.job"="REG_BINARY, ................................ "PC Health Advisor Defrag.job.fp"="REG_DWORD", 1563359978 "PC Health Advisor Startup.job"="REG_BINARY, ................................ "PC Health Advisor Startup.job.fp"="REG_DWORD", -1319655084 "PC Health Advisor Update.job"="REG_BINARY, ................................ "PC Health Advisor Update.job.fp"="REG_DWORD", 111415083 "PC Health Advisor.job"="REG_BINARY, ................................ "PC Health Advisor.job.fp"="REG_DWORD", 1838827531 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost] "bdx"="REG_MULTI_SZ, "scan sysagent " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\bdx] "AuthenticationCapabilities"="REG_DWORD", 0 "AuthenticationLevel"="REG_DWORD", 2 "CoInitializeSecurityParam"="REG_DWORD", 1 "DefaultRpcStackSize"="REG_DWORD", 1024 "ImpersonationLevel"="REG_DWORD", 3 [HKEY_LOCAL_MACHINE\SOFTWARE\Softwin\BitDefender Threat Scanner] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\BDServices] "InstallDir"="REG_SZ", "C:\Program Files\BDServices\" "Uninstall"="REG_SZ", "C:\Program Files\BDServices\uninstall.exe" "Version"="REG_DWORD", 8 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\BDServices\apps\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}] "(Default)"="REG_SZ", "" "launch"="REG_SZ", "C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe" "shutdown"="REG_SZ", ""C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe" -shutdown" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe" "DisplayName"="REG_SZ", "ParetoLogic PC Health Advisor" "DisplayVersion"="REG_SZ", "3.2.8.0" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\ParetoLogic\PCHA" "Publisher"="REG_SZ", "ParetoLogic, Inc." "UninstallString"="REG_SZ", "C:\Program Files (x86)\ParetoLogic\PCHA\uninstall.exe" "URLInfoAbout"="REG_SZ", "http://www.paretologic.com" "VersionMajor"="REG_DWORD", 3 "VersionMinor"="REG_DWORD", 2 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ParetoLogic\PC Health Advisor] "AutoScan"="REG_DWORD", 0 "Desktop"="REG_DWORD", 1 "InstallTime"="REG_QWORD, .... "Login"="REG_DWORD", 1 "Quick"="REG_DWORD", 0 "ShowWebPageAfterScanLicense"="REG_DWORD", 7 "Silent"="REG_DWORD", 0 "Updates"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BitDefenderCOM] "DependOnService"="REG_MULTI_SZ, "RPCSS " "DisplayName"="REG_SZ", "BitDefenderCOM" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files\BDServices\BitDefenderCom.exe"" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 [HKEY_LOCAL_MACHINE\SYSTEM\gzflt] [HKEY_LOCAL_MACHINE\SYSTEM\Trufos] [HKEY_CURRENT_USER\Software\ParetoLogic\PC Health Advisor] "DUPLICATE_SCAN_RADIO"="REG_DWORD", 1 "FROMSCHEDULE"="REG_DWORD", 1 "Height"="REG_DWORD", 580 "INSTALLDATE"="REG_SZ", "08:07:40 16-03-2017" "INSTALLDATELOCAL"="REG_SZ", "09:07:40 16-03-2017" "LaunchOnStartup"="REG_DWORD", 1 "MALWARE_COUNT"="REG_DWORD", 0 "OUTDATED_COUNT"="REG_DWORD", 66 "RunCount"="REG_DWORD", 1 "UPDATESTATE"="REG_DWORD", 1 "Width"="REG_DWORD", 800 "XPos"="REG_DWORD", 427 "YPos"="REG_DWORD", 160 [HKEY_CURRENT_USER\Software\ParetoLogic\PC Health Advisor\HomeScreenIcons] "0"="REG_SZ", "Browser Object Manager" "1"="REG_SZ", "Process Manager" "2"="REG_SZ", "Startup Manager" "3"="REG_SZ", "File Extension Manager" "4"="REG_SZ", "Duplicate Finder" "5"="REG_SZ", "Defrag" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/16/17 Scan Time: 9:28 AM Logfile: mbamPCHA.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1513 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 365015 Time Elapsed: 2 min, 23 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\PCHA.EXE, Quarantined, [2431], [366058],1.0.1513 Module: 9 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\COMMONLOGGINGEXTENSION.PXT, Quarantined, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\REGHOOKSPECIALIST.PXT, Quarantined, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\LITEZIP.DLL, Quarantined, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\EXTENSIONMANAGER.DLL, Quarantined, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\PCHA.EXE, Quarantined, [2431], [366058],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\LITEUNZIP.DLL, Quarantined, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\UTILITY.PXT, Quarantined, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\MYRESOURCES.DLL, Quarantined, [2431], [366058],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\COMMONSPECIALIST.PXT, Quarantined, [2431], [366050],1.0.1513 Registry Key: 12 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{6ABE739A-C6A0-47ED-B812-C3A6BC0361C3}, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7E46AA87-95F8-4504-8034-B0F3724BE6B0}, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{90E98E78-6DBD-4513-8FA6-FD1767EDC04F}, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DF8FAF9B-104D-438F-955F-57D3CECF7060}, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Health Advisor, Delete-on-Reboot, [2431], [366055],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\WOW6432NODE\BDSERVICES\APPS\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}, Delete-on-Reboot, [2431], [366345],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Health Advisor Defrag, Delete-on-Reboot, [2431], [366055],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Health Advisor Startup, Delete-on-Reboot, [2431], [366055],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\PC Health Advisor Update, Delete-on-Reboot, [2431], [366055],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\WOW6432NODE\PARETOLOGIC\PC Health Advisor, Delete-on-Reboot, [2431], [366346],1.0.1513 PUP.Optional.ParetoLogic, HKCU\SOFTWARE\PARETOLOGIC\PC Health Advisor, Delete-on-Reboot, [2431], [366347],1.0.1513 Registry Value: 4 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{6ABE739A-C6A0-47ED-B812-C3A6BC0361C3}|PATH, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7E46AA87-95F8-4504-8034-B0F3724BE6B0}|PATH, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{90E98E78-6DBD-4513-8FA6-FD1767EDC04F}|PATH, Delete-on-Reboot, [2431], [366056],1.0.1513 PUP.Optional.ParetoLogic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DF8FAF9B-104D-438F-955F-57D3CECF7060}|PATH, Delete-on-Reboot, [2431], [366056],1.0.1513 Data Stream: 0 (No malicious items detected) Folder: 28 PUP.Optional.ParetoLogic, C:\PROGRAMDATA\ParetoLogic\PC Health Advisor, Delete-on-Reboot, [2431], [366052],1.0.1513 PUP.Optional.ParetoLogic, C:\USERS\{username}\APPDATA\ROAMING\ParetoLogic\PC Health Advisor, Delete-on-Reboot, [2431], [366052],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\process, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tab icons, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\scanning, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\defrag, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PARETOLOGIC\PC HEALTH ADVISOR, Delete-on-Reboot, [2431], [366051],1.0.1513 File: 319 PUP.Optional.ParetoLogic, C:\ProgramData\ParetoLogic\PC Health Advisor\License.rdat, Delete-on-Reboot, [2431], [366052],1.0.1513 PUP.Optional.ParetoLogic, C:\ProgramData\ParetoLogic\PC Health Advisor\License_FirstRun.rdat, Delete-on-Reboot, [2431], [366052],1.0.1513 PUP.Optional.ParetoLogic, C:\ProgramData\ParetoLogic\PC Health Advisor\License_Time.rdat, Delete-on-Reboot, [2431], [366052],1.0.1513 PUP.Optional.ParetoLogic, C:\ProgramData\ParetoLogic\PC Health Advisor\RB.rdat, Delete-on-Reboot, [2431], [366052],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\COMMONLOGGINGEXTENSION.PXT, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\REGHOOKSPECIALIST.PXT, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\LITEZIP.DLL, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\EXTENSIONMANAGER.DLL, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\PCHA.EXE, Delete-on-Reboot, [2431], [366058],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\LITEUNZIP.DLL, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\UTILITY.PXT, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\MYRESOURCES.DLL, Delete-on-Reboot, [2431], [366058],1.0.1513 PUP.Optional.ParetoLogic, C:\PROGRAM FILES (X86)\PARETOLOGIC\PCHA\COMMONSPECIALIST.PXT, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\10x10.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\10x10tile.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\contentwrapper.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\error_internet.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\footerbarfill.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\info_bubble.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\pcha_background.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\tile_footerbarbase.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\tile_subheadbarbase.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\images\tile_titlebarbase.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\0_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\15_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\1_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\2_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\30_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\5_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\main.css, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\bin\HTML\main_error.css, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\10x10.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\10x10tile.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\contentwrapper.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\error_internet.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\footerbarfill.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\info_bubble.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\pcha_background.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\tile_footerbarbase.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\tile_subheadbarbase.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\images\tile_titlebarbase.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\0_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\15_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\1_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\2_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\30_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\5_days.htm, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\container_content_bkimg.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\container_content_leftimg.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\container_content_rightimg.gif, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\error_connect.html, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\main.css, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\main_error.css, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HTML\package_titlebar_bkimg.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_bho_mgr.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_defrag.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_defrag_schedule.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_driver.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_extmgr.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_generalsettings.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_icons.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_ignore.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_optimize.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_privacy.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_process_mgr.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_registry.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_restore.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_scansettings.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_schedule.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_startup_mgr.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_update.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_about.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_bho.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_clean.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_defrag.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_disk.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_duplicate.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_extmgr.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_optimize.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_privacy.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_process.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_processes.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_registry.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_restore.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_settings.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_startup.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_summary.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_defrag_schedule.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_general.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_icons.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_ignore.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_privacy.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_registry.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_scan.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_schedule.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\settings_update.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\startbg.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\startbg_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\update_later.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\update_later_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\update_now.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\update_now_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\vdb.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\button_duplicate.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\buttons and headers\header_driver.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\defrag\c_frag.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\defrag\c_unfrag.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\defrag\c_unknown.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\defrag\c_unmove.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\close.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\close_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\collapse.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\delete.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\expand.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\open.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\progress_glow.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\recycle.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\general\x.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\bho.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\dup_audio.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\dup_doc.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\dup_image.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\dup_other.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\dup_video.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\ig_drivers.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\ig_proc.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\ig_reg.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_3rd.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_browser.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_email.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_fs.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_im.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_multi.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_office.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_other.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\priv_windows.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_apppath.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_com.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_dll.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_empty.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_extensions.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_filepath.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_font.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_help.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_shortcut.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_startup.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\reg_uninstall.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\group\startup.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_high.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_high_short.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_low.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_low_short.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_medium.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_medium_short.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_unrated.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\health rating\pchealth_unrated_short.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\button_outline.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\no_1.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\no_2.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\no_3.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\no_4.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\no_5.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\home settings\no_6.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\cd.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\cpu.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\disk.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\display.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\driver_outdated.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\driver_uptodate.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\floppy.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\mouse_key.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\other.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\outdated.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\power.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\printer.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\software.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\system.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\uptodate.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\drivers\usb.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\process\bho.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\process\process.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\process\startup.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_malware16.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_malware24.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_malware32.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_system16.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_system24.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_system32.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_unknown16.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_unknown24.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_unknown32.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_unwanted16.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_unwanted24.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_unwanted32.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_userapp16.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_userapp24.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\recommendations\rec_userapp32.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\list\other.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs\active_tab_left.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs\active_tab_right.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs\active_tab_stretch.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs\tab_left.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs\tab_right.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\tabs\tab_stretch.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\bg.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\bg_logo.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\left_stretch.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\lower_left.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\lower_right.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\lower_stretch.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\nav_back.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\nav_bg.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\nav_forward.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\right_stretch.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\upper_left.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\upper_right.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Main\upper_stretch.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\add_check.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\add_error.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\add_unknown.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\scan.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\small_driver.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\small_md5.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\small_privacy.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\progress\small_registry.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\drivers_green.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\drivers_red.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\drivers_yellow.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\malware_green.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\malware_red.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\privacy_green.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\privacy_red.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\processes_green.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\processes_red.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\registry_green.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\registry_red.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\startup_green.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\results page\startup_red.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\scanning\driver.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\scanning\privacy.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\scanning\process.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\scanning\registry.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\1.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\10.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\11.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\12.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\13.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\14.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\15.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\16.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\17.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\18.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\19.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\2.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\20.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\21.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\22.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\23.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\24.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\25.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\3.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\4.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\5.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\6.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\7.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\8.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\Start Anim\9.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tab icons\nav-disk.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tab icons\nav-optimize.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tab icons\nav-scan.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tab icons\nav-settings.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons\help_down.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons\help_normal.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons\help_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons\info_down.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons\info_normal.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\top nav icons\info_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\detected_items.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\email_logo.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\info.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\register.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\register_over.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\registration.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tfn_email.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\tfn_frame.png, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\images\warning.jpg, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\7ZipDLL.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\colors.xml, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\DC_offer.exe, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\HandleUpdate.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\libeay32.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\License.rdat, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\License_Time.rdat, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\LogSettings.xml, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\msvcp120.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\msvcr120.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\noapp.exe, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\privacy.db, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\RB.rdat, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\SandBoxer.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\settings.xml, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\sqlite3.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\ssleay32.dll, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\uninstall.exe, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\UNS.xml, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Program Files (x86)\ParetoLogic\PCHA\whitelist.dat, Delete-on-Reboot, [2431], [366050],1.0.1513 PUP.Optional.ParetoLogic, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic\PC Health Advisor\ParetoLogic PC Health Advisor.lnk, Delete-on-Reboot, [2431], [366051],1.0.1513 PUP.Optional.ParetoLogic, C:\USERS\{username}\DESKTOP\PARETOLOGIC PC HEALTH ADVISOR.LNK, Delete-on-Reboot, [2431], [366049],1.0.1513 PUP.Optional.ParetoLogic, C:\USERS\{username}\DESKTOP\PARETOLOGIC PC HEALTH ADVISOR.EXE, Delete-on-Reboot, [2431], [366058],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\TASKS\PC HEALTH ADVISOR DEFRAG.JOB, Delete-on-Reboot, [2431], [366053],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\TASKS\PC HEALTH ADVISOR UPDATE.JOB, Delete-on-Reboot, [2431], [366053],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\TASKS\PC HEALTH ADVISOR.JOB, Delete-on-Reboot, [2431], [366053],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\TASKS\PC HEALTH ADVISOR STARTUP.JOB, Delete-on-Reboot, [2431], [366053],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\SYSTEM32\TASKS\PC Health Advisor, Delete-on-Reboot, [2431], [366054],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\SYSTEM32\TASKS\PC Health Advisor Defrag, Delete-on-Reboot, [2431], [366054],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\SYSTEM32\TASKS\PC Health Advisor Startup, Delete-on-Reboot, [2431], [366054],1.0.1513 PUP.Optional.ParetoLogic, C:\WINDOWS\SYSTEM32\TASKS\PC Health Advisor Update, Delete-on-Reboot, [2431], [366054],1.0.1513 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  12. What is Advanis? The Malwarebytes research team has determined that Advanis is a Tech Support Scam. These so-called "Tech Support Scammers" try to trick you into calling their phone number for various reasons, all of which turn out to be fraudulent in the end. How do I know if my computer is affected by Advanis? You will see this screen as soon as the install has completed and when you reboot: and you may see this entry in your list of installed software: How did Advanis get on my computer? Tech Support Scammers use different methods for distributing themselves. This particular one was downloaded by a trojan. How do I remove Advanis? Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application, but due to the nature of the infection this will require a few extra steps. To minimize the screenlocker use the backspace key on your keyboard. The minimized screen will be titled "Market Tools". Alternatively you can switch user accounts on your computer. Once you have able to use your computer normally, continue with the instructions below. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Advanis? No, Malwarebytes removes Advanis completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Tech Support Scam. and we would have blocked the download of the installer: Technical details for experts You may see these entries in FRST logs: () C:\Windows\Advanis\MT\MT.exe HKCU\...\Run: [MT] => C:\Windows\Advanis\MT\MT.exe [1155072 2017-03-14] () C:\Windows\Advanis MT (HKLM-x32\...\MT) (Version: 4.3.2.6 - Advanis) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Windows\Advanis\MT Adds the file MT.exe"="3/14/2017 10:55 AM, 1155072 bytes, A Adds the file Uninstall.exe"="3/15/2017 9:00 AM, 468005 bytes, A Adds the file Uninstall.ini"="3/15/2017 9:00 AM, 2295 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MT] "DisplayIcon"="REG_SZ", "C:\Windows\Advanis\MT\Uninstall.exe" "DisplayName"="REG_SZ", "MT" "DisplayVersion"="REG_SZ", "4.3.2.6" "EstimatedSize"="REG_DWORD", 1585 "HelpLink"="REG_SZ", "support@advanis.net" "InstallDate"="REG_SZ", "20170315" "InstallLocation"="REG_SZ", "C:\Windows\Advanis\MT\" "InstallSource"="REG_SZ", "C:\Users\{username}\Desktop\" "Language"="REG_DWORD", 1033 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Advanis" "UninstallString"="REG_SZ", "C:\Windows\Advanis\MT\Uninstall.exe" "URLInfoAbout"="REG_SZ", "www.Advanis.net" "VersionMajor"="REG_DWORD", 4 "VersionMinor"="REG_DWORD", 3 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "MT"="REG_SZ", "C:\Windows\Advanis\MT\MT.exe" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/15/17 Scan Time: 9:10 AM Logfile: mbamAdvanis.txt Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.1507 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 364672 Time Elapsed: 1 min, 12 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Trojan.TechSupportScam, C:\WINDOWS\ADVANIS\MT\MT.EXE, Quarantined, [125], [380134],1.0.1507 Module: 1 Trojan.TechSupportScam, C:\WINDOWS\ADVANIS\MT\MT.EXE, Quarantined, [125], [380134],1.0.1507 Registry Key: 0 (No malicious items detected) Registry Value: 1 Trojan.TechSupportScam, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MT, Delete-on-Reboot, [125], [380134],1.0.1507 Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 2 Trojan.TechSupportScam, C:\WINDOWS\ADVANIS\MT\MT.EXE, Delete-on-Reboot, [125], [380134],1.0.1507 Trojan.TechSupportScam, C:\USERS\{username}\DESKTOP\SETUP (14).EXE, Delete-on-Reboot, [125], [380135],1.0.1507 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  13. The rootkit described above behaves even more aggressive if your IP address is from the US (there may be others where it behaves this way). You can recognize this more effectful approach by this warning when you try to run Malwarebytes. To get rid of this rootkit you will have to follow the procedure outlined below: Download the standalone Malwarebytes Anti-Rootkit BETA Run the installer and choose a destination folder. Once the installation is complete click "Next" to proceed. Then click "Update" to get the latest definitions. Once the database has been updated click "Next". Then click "Scan" to start scanning the infected system. This is the main target of this scan. Once the scan is finished click "Cleanup" to remove the rootkit and the asssociated files. When removal is complete, you will be prompted to reboot the system. Click "Yes" to confirm or reboot manually. After the reboot try running Malwarebytes to confirm that it works properly again and run a "Threat Scan" to get any leftovers.
  14. What is Adware.Yelloader? The Malwarebytes research team has determined that Adware.Yelloader is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by Adware.Yelloader? This adware is installed as a rootkit, so you may notice no other signs besides the unexplainable advertisements. This one also disables a long list of security programs. Doctor Web Ltd. Check Point Software Technologies Ltd. VIRUSBLOKADA ODO Beijing Kingsoft Security software Co., Ltd Qihoo 360 Software(Beijing) Company Limited Doctor Web System Healer Tech Sp.Zo.o. Safer Networking Ltd. BrightFort LLC Enigma Software Group USA, LLC Gridinsoft, LLC Auslogics Labs Pty Ltd Datpol Janusz Siemienowicz Zemana Ltd. Piriform Ltd IObit Information Technology Check Point VIRUSBLOKADA Sophos ThreatTrack Blue Coat Glarysoft SurfRight Computer Associates International Shanghai 2345 Network Beijing Kingsoft Security Beijing Rising Information Qihoo 360 Software Malwarebytes Symantec How did Adware.Yelloader get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove Adware.Yelloader? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, make sure that you enable the Scan for rootkits option on the Protection tab under Scan Options. Then select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Adware.Yelloader? No, Malwarebytes removes Adware.Yelloader completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the Adware.Yelloader adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: (ct Corp.) C:\Users\{username}\AppData\Local\Temp\20170313\ct.exe R2 windowsmanagementservice; C:\Users\{username}\AppData\Local\Temp\20170313\ct.exe [724480 2017-02-22] (ct Corp.) [File not signed] Visible alterations made by the installer: Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\windowsmanagementservice] "DelayedAutostart"="REG_DWORD", 1 "Description"="REG_SZ", "Provide management service for system." "DisplayName"="REG_SZ", "Windows Management Service" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Users\{username}1\AppData\Local\Temp\20170313\ct.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/13/17 Scan Time: 2:35 PM Logfile: mbamAdwareRootkit.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.75 Update Package Version: 1.0.1490 License: Trial -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 321362 Time Elapsed: 2 min, 27 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 1 Adware.Yelloader, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\windowsmanagementservice, Delete-on-Reboot, [4873], [377105],1.0.1490 Registry Value: 1 Trojan.Clicker, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE|IMAGEPATH, Delete-on-Reboot, [43], [377141],1.0.1490 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 1 Trojan.Clicker, C:\USERS\{username}\APPDATA\LOCAL\TEMP\20170313, Delete-on-Reboot, [43], [377133],1.0.1490 File: 7 Adware.Yelloader, C:\USERS\{username}\APPDATA\LOCAL\TEMP\20170313\CT.EXE, Delete-on-Reboot, [4873], [377105],1.0.1490 Adware.Yelloader, C:\USERS\{username}\APPDATA\LOCAL\TEMP\20170313\CT.EXE, Delete-on-Reboot, [4873], [377105],1.0.1490 Adware.Yelloader, C:\USERS\{username}\DESKTOP\S5-20150702.EXE, Delete-on-Reboot, [4873], [377100],1.0.1490 Rootkit.Agent.PUA, C:\USERS\{username}\APPDATA\LOCAL\TEMP\20170313\DRMKPRO64.SYS, Delete-on-Reboot, [8263], [375178],1.0.1490 Adware.Yelloader, C:\USERS\{username}\APPDATA\LOCAL\TEMP\20170313\NVVSVC.EXE, Delete-on-Reboot, [4873], [377104],1.0.1490 Trojan.Clicker, C:\USERS\{username}\APPDATA\LOCAL\TEMP\20170313\CT.ZIP, Delete-on-Reboot, [43], [377133],1.0.1490 Adware.Yelloader, C:\USERS\{username}\DESKTOP\ROOTKIT\S5-20150702.ZIP, Delete-on-Reboot, [4873], [377100],1.0.1490 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.