Metallica

Moderators
  • Content count

    1,812
  • Joined

  • Last visited

About Metallica

  • Rank
    Master of PUPs
  • Birthday 05/19/1963

Contact Methods

  • ICQ
    0

Profile Information

  • Location
    Netherlands

Recent Profile Visitors

154,202 profile views
  1. What is BetterAds? The Malwarebytes research team has determined that BetterAds is adware. These adware applications display advertisements not originating from the sites you are browsing. This one uses a proxy service to show you advertisements How do I know if my computer is affected by BetterAds? You may see this entry in your list of installed programs and features: these proxy settings: and this service running after install: How did BetterAds get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove BetterAds? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of BetterAds? No, Malwarebytes removes BetterAds completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the BetterAds adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks the download of the installer: Technical details for experts Possible signs in FRST logs: () C:\Windows\src_srv\winsrcsrv.exe ProxyEnable: [.DEFAULT] => Proxy is enabled. ProxyServer: [.DEFAULT] => 127.0.0.1:8003 ProxyEnable: [S-1-5-19] => Proxy is enabled. ProxyServer: [S-1-5-19] => 127.0.0.1:8003 ProxyEnable: [S-1-5-20] => Proxy is enabled. ProxyServer: [S-1-5-20] => 127.0.0.1:8003 ProxyEnable: [S-1-5-21-1350903546-318028887-1286703239-1003] => Proxy is enabled. ProxyServer: [S-1-5-21-1350903546-318028887-1286703239-1003] => 127.0.0.1:8003 ManualProxies: 1127.0.0.1:8003 R2 srcsrv; C:\Windows\src_srv\winsrcsrv.exe [16384 2017-04-04] () [File not signed] C:\Windows\unins000.exe C:\Windows\unins000.dat C:\Windows\src_srv BetterAds version 1 (HKLM-x32\...\{376CA350-6C34-4F10-B8DC-586F8CA03009}_is1) (Version: 1 - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- In the existing folder C:\Windows Adds the file unins000.dat"="4/27/2017 11:26 AM, 3835 bytes, A Adds the file unins000.exe"="4/27/2017 11:26 AM, 719521 bytes, A Adds the folder C:\Windows\src_srv Adds the file accept_cert.exe"="1/29/2017 2:47 AM, 12800 bytes, A Adds the file Ionic.Zip.dll"="1/25/2016 7:55 PM, 455680 bytes, A Adds the file rootCert.pfx"="4/27/2017 11:26 AM, 2702 bytes, A Adds the file Trusted.Web.Proxy.dll"="4/4/2017 12:35 PM, 137728 bytes, A Adds the file winsrcsrv.exe"="4/4/2017 12:35 PM, 16384 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\MY\Certificates\4983F9188BB4EAB0C10302EDDFF162915E3D1E33] "Blob"="REG_BINARY, ........l...........{AF467404-4868-47C4-A722-37FBAD22544E}..Microsoft Enhanced Cryptographic Provider v1.0......................................<.DO_NOT_TRUST_TitaniumProxy-CE. .....................................................................................................................................................................................>................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4983F9188BB4EAB0C10302EDDFF162915E3D1E33] "Blob"="REG_BINARY, \...............l...........{AF467404-4868-47C4-A722-37FBAD22544E}..Microsoft Enhanced Cryptographic Provider v1.0.................... .....................................................<.DO_NOT_TRUST_TitaniumProxy-CE............... .....................................................................................................................................................................................>................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\betterads] "userID"="REG_SZ", "ca14663b-b073-4b30-8318-38da6354a93f" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\mbs_install] "channel"="REG_SZ", "amonetize_2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{376CA350-6C34-4F10-B8DC-586F8CA03009}_is1] "DisplayName"="REG_SZ", "BetterAds version 1" "DisplayVersion"="REG_SZ", "1" "EstimatedSize"="REG_DWORD", 1299 "HelpLink"="REG_SZ", "http://www.betteradssoftware.com/" "Inno Setup: App Path"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "(Default)" "Inno Setup: Language"="REG_SZ", "english" "Inno Setup: Setup Version"="REG_SZ", "5.5.5 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170427" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Windows\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Windows\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.betteradssoftware.com/" "URLUpdateInfo"="REG_SZ", "http://www.betteradssoftware.com/" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\srcsrv] "DisplayName"="REG_SZ", "SrcSrv" "ErrorControl"="REG_DWORD", 1 "FailureActions"="REG_BINARY, ...................... "ImagePath"="REG_EXPAND_SZ, "C:\Windows\src_srv\winsrcsrv.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 [HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\4983F9188BB4EAB0C10302EDDFF162915E3D1E33] "Blob"="REG_BINARY, .................. ...............................................................\....... .....................................................................................................................................................................................>................................................................................................................................................................................................................................................ [HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\REQUEST] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = REG_DWORD, 1 "ProxyServer"="REG_SZ", "127.0.0.1:8003" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable"="REG_DWORD", 1 "ProxyServer"="REG_SZ", "127.0.0.1:8003" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable"="REG_DWORD", 1 "ProxyServer"="REG_SZ", "127.0.0.1:8003" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = REG_DWORD, 1 "ProxyServer"="REG_SZ", "127.0.0.1:8003" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/27/17 Scan Time: 11:38 AM Logfile: mbamBetterAds.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1818 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 328803 Time Elapsed: 4 min, 6 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Adware.BetterAds.PrxySvrRST, C:\Windows\src_srv\winsrcsrv.exe, Quarantined, [6542], [392905],1.0.1818 Module: 1 Adware.BetterAds.PrxySvrRST, C:\Windows\src_srv\winsrcsrv.exe, Quarantined, [6542], [392905],1.0.1818 Registry Key: 5 Adware.BetterAds.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\srcsrv, Delete-on-Reboot, [6542], [392905],1.0.1818 Adware.BetterAds.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Delete-on-Reboot, [6542], [-1],0.0.0 PUP.Optional.BetterAds, HKLM\SOFTWARE\WOW6432NODE\betterads, Delete-on-Reboot, [476], [383836],1.0.1818 PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\MBS_INSTALL, Delete-on-Reboot, [6], [392968],1.0.1818 PUP.Optional.BetterAds, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{376CA350-6C34-4F10-B8DC-586F8CA03009}_is1, Delete-on-Reboot, [476], [383837],1.0.1818 Registry Value: 13 Adware.BetterAds.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [6542], [-1],0.0.0 Adware.BetterAds.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SRCSRV|IMAGEPATH, Delete-on-Reboot, [6542], [392906],1.0.1818 PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\MBS_INSTALL|CHANNEL, Delete-on-Reboot, [6], [392968],1.0.1818 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 1 Adware.BetterAds.PrxySvrRST, C:\WINDOWS\SRC_SRV, Delete-on-Reboot, [6542], [392905],1.0.1818 File: 6 PUP.Optional.BetterAds, C:\USERS\{username}\DESKTOP\SRC_SRV_AMONETIZE.EXE, Delete-on-Reboot, [476], [391675],1.0.1818 Adware.BetterAds.PrxySvrRST, C:\WINDOWS\SRC_SRV\TRUSTED.WEB.PROXY.DLL, Delete-on-Reboot, [6542], [392905],1.0.1818 Adware.BetterAds.PrxySvrRST, C:\Windows\src_srv\accept_cert.exe, Delete-on-Reboot, [6542], [392905],1.0.1818 Adware.BetterAds.PrxySvrRST, C:\Windows\src_srv\Ionic.Zip.dll, Delete-on-Reboot, [6542], [392905],1.0.1818 Adware.BetterAds.PrxySvrRST, C:\Windows\src_srv\rootCert.pfx, Delete-on-Reboot, [6542], [392905],1.0.1818 Adware.BetterAds.PrxySvrRST, C:\Windows\src_srv\winsrcsrv.exe, Delete-on-Reboot, [6542], [392905],1.0.1818 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  2. What is Privacy Plus? The Malwarebytes research team has determined that Privacy Plus is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with Privacy Plus? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, startmenu and on your desktop: and see these warnings during install: and these screens during "operations": You may see this entry in your list of installed programs: and these tasks in your Task Scheduler: How did Privacy Plus get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove PrivacyPlus? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Privacy Plus? No, Malwarebytes removes PrivacyPlus completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the PrivacyPlus installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: (Privacy Plus) C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe HKCU\...\Run: [PrivacyPlus] => C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe [6331712 2017-01-16] (Privacy Plus) C:\Windows\System32\Tasks\PrivacyPlus_Popup3 C:\Windows\System32\Tasks\PrivacyPlus_Popup C:\Users\{username}\AppData\Local\PrivacyPlus C:\Windows\System32\Tasks\PrivacyPlus_Master C:\Users\{username}\Desktop\Privacy Plus.lnk C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Privacy Plus C:\Program Files (x86)\Privacy Plus Privacy Plus (HKLM-x32\...\Privacy Plus) (Version: 3.2.9 - Privacy Plus) Task: {761FF17A-25EE-4512-8547-49807E32DF44} - System32\Tasks\PrivacyPlus_Popup => C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe [2017-01-16] (Privacy Plus) Task: {9F6002A8-2981-4167-A062-112F9A02BDB0} - System32\Tasks\PrivacyPlus_Master => C:\Program Files (x86)\Privacy Plus\InstAct.exe [2017-01-16] () Task: {F0C4BD9F-CDD0-4948-8B3F-BB1C6E958F3F} - System32\Tasks\PrivacyPlus_Popup3 => C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe [2017-01-16] (Privacy Plus) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Privacy Plus Adds the file Esent.Interop.dll"="11/19/2015 2:16 PM, 326656 bytes, A Adds the file InstAct.exe"="1/16/2017 7:56 AM, 36160 bytes, A Adds the file InstAct.exe.config"="8/20/2015 12:34 PM, 232 bytes, A Adds the file Microsoft.Win32.TaskScheduler.dll"="11/19/2015 2:16 PM, 322560 bytes, A Adds the file Newtonsoft.Json.dll"="11/19/2015 2:16 PM, 494080 bytes, A Adds the file PrivacyEngine.dll"="1/16/2017 7:54 AM, 125952 bytes, A Adds the file PrivacyEngine.dll.config"="11/19/2015 2:16 PM, 229 bytes, A Adds the file PrivacyPlus.exe"="1/16/2017 7:56 AM, 6331712 bytes, A Adds the file PrivacyPlus.exe.config"="11/19/2015 2:16 PM, 231 bytes, A Adds the file Push.exe"="1/16/2017 7:57 AM, 25408 bytes, A Adds the file Push.exe.config"="12/12/2016 7:24 AM, 224 bytes, A Adds the file schedc.exe"="1/16/2017 7:56 AM, 30016 bytes, A Adds the file schedc.exe.config"="11/19/2015 2:16 PM, 232 bytes, A Adds the file schedc10.exe"="1/16/2017 7:56 AM, 32576 bytes, A Adds the file schedc10.exe.config"="11/19/2015 2:16 PM, 232 bytes, A Adds the file Setup.dll"="1/16/2017 7:54 AM, 67584 bytes, A Adds the file Setup.dll.config"="8/18/2015 7:10 AM, 229 bytes, A Adds the file System.Data.SQLite.dll"="11/19/2015 2:16 PM, 1175552 bytes, A Adds the file TaskTools.exe"="1/16/2017 7:56 AM, 61760 bytes, A Adds the file TaskTools.exe.config"="11/19/2015 2:16 PM, 231 bytes, A Adds the file uninstall.exe"="1/16/2017 7:57 AM, 198664 bytes, A Adds the file updater.exe"="1/16/2017 7:56 AM, 507200 bytes, A Adds the file updater.ini"="4/26/2017 9:09 AM, 366 bytes, A Adds the file Util.dll"="1/16/2017 7:54 AM, 233984 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\ar Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 37376 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\da Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 32256 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\de Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 34816 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\es Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 33792 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\fil-PH Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 31744 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\fr Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 34304 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\he Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 32768 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\it Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 33792 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\ja Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 36352 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\nl Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 32768 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\no Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 32256 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\pt Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 33280 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\ru Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 39936 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\se-FI Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 33280 bytes, A Adds the folder C:\Program Files (x86)\Privacy Plus\sv Adds the file PrivacyPlus.resources.dll"="1/16/2017 7:54 AM, 32256 bytes, A Adds the folder C:\Users\{username}\AppData\Local\PrivacyPlus Adds the file chcookies.txt"="4/26/2017 9:12 AM, 2928 bytes, A Adds the file cla"="4/26/2017 9:09 AM, 94 bytes, A Adds the file debug.log"="4/26/2017 9:10 AM, 900 bytes, A Adds the file ffcookies.txt"="4/26/2017 9:12 AM, 7432 bytes, A Adds the file iecookies.txt"="4/26/2017 9:12 AM, 1544 bytes, A Adds the file log.rtf"="4/26/2017 9:10 AM, 1286 bytes, A Adds the file lsttick"="4/26/2017 9:10 AM, 8 bytes, A Adds the file PrivacyPlus.settings"="4/26/2017 9:10 AM, 1840 bytes, A Adds the file report.txt"="4/26/2017 9:10 AM, 92 bytes, A Adds the file wndstate.tmp"="4/26/2017 9:10 AM, 5 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Privacy Plus Adds the file Privacy Plus.lnk"="4/26/2017 9:09 AM, 1086 bytes, A Adds the file Uninstall Privacy Plus.lnk"="4/26/2017 9:09 AM, 858 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file Privacy Plus.lnk"="4/26/2017 9:09 AM, 1050 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file PrivacyPlus_Master"="4/26/2017 9:09 AM, 3008 bytes, A Adds the file PrivacyPlus_Popup"="4/26/2017 9:10 AM, 3472 bytes, A Adds the file PrivacyPlus_Popup3"="4/26/2017 9:10 AM, 3738 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Privacy Plus] " "="REG_SZ", "C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Privacy Plus] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe" "DisplayName"="REG_SZ", "Privacy Plus" "DisplayVersion"="REG_SZ", "3.2.9" "EstimatedSize"="REG_DWORD", 10042 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Privacy Plus" "QuietUninstallString"="REG_SZ", "C:\Program Files (x86)\Privacy Plus\uninstall.exe /S" "UninstallString"="REG_SZ", "C:\Program Files (x86)\Privacy Plus\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Privacy Plus\Privacy Plus] "Path"="REG_SZ", "C:\Program Files (x86)\Privacy Plus" "Version"="REG_SZ", "3.2.9" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "PrivacyPlus"="REG_SZ", ""C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe" minimized" [HKEY_CURRENT_USER\Software\Privacy Plus\Privacy Plus] "Custom1"="REG_DWORD", 0 "Custom2"="REG_DWORD", 0 "ResName"="REG_SZ", "Regular" [HKEY_CURRENT_USER\Software\PrivacyPlusValidity] "Base"="REG_SZ", "" "Bios"="REG_SZ", "" "BuyLink"="REG_SZ", "http://privacy.plus/buy?pin=" "Cpu"="REG_SZ", "" "Disk"="REG_SZ", "" "lang"="REG_SZ", "en" "NeedsRenewal"="REG_SZ", "False" "PhoneNum"="REG_SZ", "+1-877-777-5592" "Reg"="REG_SZ", "EAAAADadnLVX0uqmSJRbFp1/saYuRNTm3ilnDREdq8" "SplashTime"="REG_QWORD, .... "Support"="REG_SZ", "http://privacy.plus/support.php?pin=" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/26/17 Scan Time: 9:24 AM Logfile: mbamPrivacyPlus.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1810 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 328642 Time Elapsed: 3 min, 32 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe, Quarantined, [4248], [393197],1.0.1810 Module: 2 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe, Quarantined, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\System.Data.SQLite.dll, Quarantined, [4248], [393197],1.0.1810 Registry Key: 8 PUP.Optional.PrivacyPlus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Privacy Plus, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, HKLM\SOFTWARE\WOW6432NODE\Privacy Plus, Delete-on-Reboot, [4248], [393206],1.0.1810 PUP.Optional.PrivacyPlus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Privacy Plus, Delete-on-Reboot, [4248], [393203],1.0.1810 PUP.Optional.PrivacyPlus, HKCU\SOFTWARE\Privacy Plus, Delete-on-Reboot, [4248], [393207],1.0.1810 PUP.Optional.PrivacyPlus, HKCU\SOFTWARE\PrivacyPlusValidity, Delete-on-Reboot, [4248], [393208],1.0.1810 PUP.Optional.PrivacyPlus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\PrivacyPlus_RASAPI32, Delete-on-Reboot, [4248], [393205],1.0.1810 PUP.Optional.PrivacyPlus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\PrivacyPlus_RASMANCS, Delete-on-Reboot, [4248], [393205],1.0.1810 PUP.Optional.PrivacyPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\Privacy Plus, Delete-on-Reboot, [4248], [393203],1.0.1810 Registry Value: 1 PUP.Optional.PrivacyPlus, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PrivacyPlus, Delete-on-Reboot, [4248], [393197],1.0.1810 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 18 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\fil-PH, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\se-FI, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\ar, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\da, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\de, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\es, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\fr, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\he, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\it, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\ja, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\nl, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\no, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\pt, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\ru, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\sv, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\PROGRAM FILES (X86)\Privacy Plus, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\USERS\{username}\APPDATA\LOCAL\PrivacyPlus, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PRIVACY PLUS, Delete-on-Reboot, [4248], [393199],1.0.1810 File: 56 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\ar\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\da\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\de\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\es\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\fil-PH\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\fr\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\he\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\it\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\ja\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\nl\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\no\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\pt\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\ru\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\se-FI\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\sv\PrivacyPlus.resources.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Esent.Interop.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\InstAct.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\InstAct.exe.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Microsoft.Win32.TaskScheduler.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Newtonsoft.Json.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\PrivacyEngine.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\PrivacyEngine.dll.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\PrivacyPlus.exe.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Push.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Push.exe.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\schedc.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\schedc.exe.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\schedc10.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\schedc10.exe.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Setup.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Setup.dll.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\System.Data.SQLite.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\TaskTools.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\TaskTools.exe.config, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\uninstall.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\updater.exe, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\updater.ini, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Program Files (x86)\Privacy Plus\Util.dll, Delete-on-Reboot, [4248], [393197],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\chcookies.txt, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\cla, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\debug.log, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\ffcookies.txt, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\iecookies.txt, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\log.rtf, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\lsttick, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\PrivacyPlus.settings, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\report.txt, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Local\PrivacyPlus\wndstate.tmp, Delete-on-Reboot, [4248], [393198],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Privacy Plus\Privacy Plus.lnk, Delete-on-Reboot, [4248], [393199],1.0.1810 PUP.Optional.PrivacyPlus, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Privacy Plus\Uninstall Privacy Plus.lnk, Delete-on-Reboot, [4248], [393199],1.0.1810 PUP.Optional.PrivacyPlus, C:\USERS\{username}\DESKTOP\PRIVACY PLUS.LNK, Delete-on-Reboot, [4248], [393200],1.0.1810 PUP.Optional.PrivacyPlus, C:\USERS\{username}\DESKTOP\PRIVACYPLUSSETUP.EXE, Delete-on-Reboot, [4248], [393226],1.0.1810 PUP.Optional.PrivacyPlus, C:\WINDOWS\SYSTEM32\TASKS\PrivacyPlus_Master, Delete-on-Reboot, [4248], [393201],1.0.1810 PUP.Optional.PrivacyPlus, C:\WINDOWS\SYSTEM32\TASKS\PrivacyPlus_Popup, Delete-on-Reboot, [4248], [393201],1.0.1810 PUP.Optional.PrivacyPlus, C:\WINDOWS\SYSTEM32\TASKS\PrivacyPlus_Popup3, Delete-on-Reboot, [4248], [393201],1.0.1810 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  3. What is BeansPlayer? The Malwarebytes research team has determined that BeansPlayer is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by BeansPlayer? You may see this entry in your list of installed programs and features: this icon in your startmenu and your desktop: and this warning during install: This is the main screen of the program: How did BeansPlayer get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove BeansPlayer? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of BeansPlayer? No, Malwarebytes removes BeansPlayer completely. The shortcut called BeansPlayer on the desktop can be deleted if it belonged to the rogue. We hope our application and this guide have helped you eradicate this adware. Technical details for experts Possible signs in FRST logs: () C:\Program Files (x86)\BeansPlayer\BeansPlayer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BeansPlayer.lnk C:\Users\Public\Desktop\BeansPlayer.lnk C:\Program Files (x86)\BeansPlayer BeansPlayer version 1.0 (HKLM-x32\...\{0DB86D3A-F3B4-4541-AD28-D31249B2AF8E}_is1) (Version: 1.0 - BeansPlayer) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\BeansPlayer Adds the file bass.dll"="2/14/2017 12:14 PM, 206336 bytes, A Adds the file Bass.Net.dll"="8/25/2009 11:00 AM, 565248 bytes, A Adds the file BeansPlayer.exe"="2/15/2017 1:59 PM, 1338368 bytes, A Adds the file BeansPlayer.exe.config"="3/23/2017 1:19 PM, 1141 bytes, A Adds the file Microsoft.WindowsAPICodePack.dll"="1/28/2010 2:18 PM, 90112 bytes, A Adds the file Microsoft.WindowsAPICodePack.Shell.dll"="1/28/2010 2:18 PM, 527360 bytes, A Adds the file taglib-sharp.dll"="1/26/2010 3:47 PM, 307200 bytes, A Adds the file unins000.dat"="4/25/2017 4:04 PM, 1650 bytes, A Adds the file unins000.exe"="4/25/2017 4:04 PM, 722597 bytes, A In the existing folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs Adds the file BeansPlayer.lnk"="4/25/2017 4:04 PM, 1055 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file BeansPlayer.lnk"="4/25/2017 4:04 PM, 1043 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0DB86D3A-F3B4-4541-AD28-D31249B2AF8E}_is1] "DisplayName"="REG_SZ", "BeansPlayer version 1.0" "DisplayVersion"="REG_SZ", "1.0" "EstimatedSize"="REG_DWORD", 3659 "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\BeansPlayer" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "(Default)" "Inno Setup: Language"="REG_SZ", "english" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon" "Inno Setup: Setup Version"="REG_SZ", "5.5.8 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170425" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\BeansPlayer\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "BeansPlayer" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\BeansPlayer\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\BeansPlayer\unins000.exe"" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/25/17 Scan Time: 4:13 PM Logfile: mbamBeansPlayer.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1804 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 328342 Time Elapsed: 1 min, 30 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\BeansPlayer.exe, Quarantined, [8862], [383832],1.0.1804 Module: 2 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\bass.dll, Quarantined, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\BeansPlayer.exe, Quarantined, [8862], [383832],1.0.1804 Registry Key: 1 PUP.Optional.BeansPlayer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{0DB86D3A-F3B4-4541-AD28-D31249B2AF8E}_is1, Delete-on-Reboot, [8862], [383832],1.0.1804 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 1 PUP.Optional.BeansPlayer, C:\PROGRAM FILES (X86)\BEANSPLAYER, Delete-on-Reboot, [8862], [383832],1.0.1804 File: 10 PUP.Optional.BeansPlayer, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\BEANSPLAYER.LNK, Delete-on-Reboot, [8862], [383833],1.0.1804 PUP.Optional.BeansPlayer, C:\PROGRAM FILES (X86)\BEANSPLAYER\UNINS000.DAT, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\bass.dll, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\Bass.Net.dll, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\BeansPlayer.exe, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\BeansPlayer.exe.config, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\Microsoft.WindowsAPICodePack.dll, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\Microsoft.WindowsAPICodePack.Shell.dll, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\taglib-sharp.dll, Delete-on-Reboot, [8862], [383832],1.0.1804 PUP.Optional.BeansPlayer, C:\Program Files (x86)\BeansPlayer\unins000.exe, Delete-on-Reboot, [8862], [383832],1.0.1804 Physical Sector: 0 (No malicious items detected) (end) At Malwarebytes we use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  4. What is Easy Video Converter? The Malwarebytes research team has determined that Easy Video Converter is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. Easy Video Converter is a member of the Spigot family as described in the blogpost Spigot browser hijackers. How do I know if my computer is affected by Easy Video Converter? You may see this browser extension/add-on: and this new default search provider: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browser(s): How did Easy Video Converter get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove Easy Video Converter? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Easy Video Converter? No, Malwarebytes removes Easy Video Converter completely. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Easy Video Converter hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.easyvideoconverteraccess.com/?source=tt&uid={uid1}&uc={date}&ap=&i_id=videoconverter__1.30 SearchScopes: HKCU -> DefaultScope {A01439CC-DBB1-421C-9197-4EE4F9A8CC28} URL = hxxp://search.easyvideoconverteraccess.com/s?source=tt&uid={uid1}&uc={date}&ap=&i_id=videoconverter__1.30&query={searchTerms} SearchScopes: HKCU -> {A01439CC-DBB1-421C-9197-4EE4F9A8CC28} URL = hxxp://search.easyvideoconverteraccess.com/s?source=tt&uid={uid1}&uc={date}&ap=&i_id=videoconverter__1.30&query={searchTerms} FF NewTab: hxxp://search.easyvideoconverteraccess.com?uid={uid2}&uc={date}&ap=&source=-bb8&page=newtab&implementation_id=videoconverter_0.2.0 FF Homepage: hxxp://search.easyvideoconverteraccess.com?uid={uid2}&uc={date}&ap=&source=-bb8&page=homepage&implementation_id=videoconverter_0.2.0 FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2017-02-01] [not signed] FF Extension: VideoConverter - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default-1491393116824\Extensions\@VideoConverter.xpi [2017-04-24] FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2017-04-24] [not signed] C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Easy Video Converter Access (HKCU\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 2.6.0.2 - Cloud Installer) Changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8} Adds the file Uninstall.exe"="4/24/2017 10:42 AM, 263168 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default-1491393116824\extensions Adds the file @VideoConverter.xpi"="4/24/2017 10:43 AM, 23421 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default-1491393116824\jetpack\@VideoConverter\simple-storage Adds the file store.json"="4/24/2017 10:43 AM, 331 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://search.easyvideoconverteraccess.com/?source=tt&uid={uid3}&uc={date}&ap=&i_id=videoconverter__1.30" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6F4023D3-7DD6-43A7-BFA6-03A108368BB6}] "DisplayName"="REG_SZ", "Search" "SuggestionsURL"="REG_SZ", "https://ie.search.yahoo.com/os?appid=ie8&command={searchTerms}" "URL"="REG_SZ", "http://search.easyvideoconverteraccess.com/s?source=tt&uid={uid3}&uc={date}&ap=&i_id=videoconverter__1.30&query={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{28e56cfb-e30e-4f66-85d8-339885b726b8}] "DisplayName"="REG_SZ", "Easy Video Converter Access" "DisplayVersion"="REG_SZ", "2.6.0.2" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\" "Publisher"="REG_SZ", "Cloud Installer" "UninstallHomepage"="REG_SZ", "http://search.easyvideoconverteraccess.com/?source=tt&uid={uid3}&uc={date}&ap=&i_id=videoconverter__1.30" "UninstallImpression"="REG_SZ", "http://imp.easyvideoconverteraccess.com/impression.do?source=tt&sub_id={date}&useragent=Mozilla%2F5.0+(Windows+NT+6.1%3B+WOW64%3B+Trident%2F7.0%3B+rv%3A11.0)+like+Gecko&traffic_source=&user_id={uid3}&implementation_id=videoconverter__1.30&event={exEvent}" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe" /uninstall" Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/24/17 Scan Time: 10:45 AM Logfile: mbam2.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1795 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 328087 Time Elapsed: 2 min, 13 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.Spigot, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [627], [373878],1.0.1795 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6F4023D3-7DD6-43A7-BFA6-03A108368BB6}, Delete-on-Reboot, [1976], [368913],1.0.1795 Registry Value: 1 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6F4023D3-7DD6-43A7-BFA6-03A108368BB6}|URL, Delete-on-Reboot, [1976], [368913],1.0.1795 Registry Data: 1 PUP.Optional.Spigot.Generic, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [1976], [373048],1.0.1795 Data Stream: 0 (No malicious items detected) Folder: 3 PUP.Optional.Spigot, C:\USERS\{username}\APPDATA\ROAMING\{28e56cfb-e30e-4f66-85d8-339885b726b8}, Delete-on-Reboot, [627], [373878],1.0.1795 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default-1491393116824\jetpack\@VideoConverter\simple-storage, Delete-on-Reboot, [1976], [364587],1.0.1795 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X82GPANI.DEFAULT-1491393116824\JETPACK\@VIDEOCONVERTER, Delete-on-Reboot, [1976], [364587],1.0.1795 File: 5 PUP.Optional.Spigot, C:\Users\{username}\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Uninstall.exe, Delete-on-Reboot, [627], [373878],1.0.1795 PUP.Optional.Spigot.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default-1491393116824\jetpack\@VideoConverter\simple-storage\store.json, Delete-on-Reboot, [1976], [364587],1.0.1795 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X82GPANI.DEFAULT-1491393116824\PREFS.JS, Replaced, [1976], [361537],1.0.1795 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X82GPANI.DEFAULT-1491393116824\PREFS.JS, Replaced, [1976], [361538],1.0.1795 PUP.Optional.Spigot.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X82GPANI.DEFAULT-1491393116824\EXTENSIONS\@VIDEOCONVERTER.XPI, Delete-on-Reboot, [1976], [364614],1.0.1795 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  5. What is Kitty? The Malwarebytes research team has determined that Kitty is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by Kitty? You may see this entry (Kitty) in your list of services: How did Kitty get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove Kitty? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Kitty? No, Malwarebytes removes Kitty completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the Kitty adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: (kitty.exe) C:\Users\{username}\AppData\Local\Kitty\cat.exe R2 Kitty; C:\Users\{username}\AppData\Local\Kitty\cat.exe [357376 2017-04-21] (kitty.exe) [File not signed] C:\Users\{username}\AppData\Local\Kitty Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Kitty Adds the file cat.exe"="4/21/2017 9:15 AM, 357376 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Kitty] "DisplayName"="REG_SZ", "Kitty" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Users\{username}\AppData\Local\Kitty\cat.exe -s" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/21/17 Scan Time: 9:34 AM Logfile: mbamKittyCat.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1773 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 327874 Time Elapsed: 1 min, 22 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Adware.Elex, C:\USERS\{username}\APPDATA\LOCAL\KITTY\CAT.EXE, Quarantined, [2], [391575],1.0.1773 Module: 1 Adware.Elex, C:\USERS\{username}\APPDATA\LOCAL\KITTY\CAT.EXE, Quarantined, [2], [391575],1.0.1773 Registry Key: 1 Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Kitty, Delete-on-Reboot, [2], [391575],1.0.1773 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 1 Adware.Elex, C:\USERS\{username}\APPDATA\LOCAL\KITTY, Delete-on-Reboot, [2], [390136],1.0.1773 File: 2 Adware.Elex, C:\USERS\{username}\APPDATA\LOCAL\KITTY\CAT.EXE, Delete-on-Reboot, [2], [391575],1.0.1773 Adware.Elex, C:\USERS\{username}\DESKTOP\KITTY.EXE, Delete-on-Reboot, [2], [391575],1.0.1773 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  6. What is YeaDesktop? The Malwarebytes research team has determined that YeaDesktop is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by YeaDesktop? You may see this entry in your list of installed programs and features: and this warning when you try to uninstall: How did YeaDesktop get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove YeaDesktop? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of YeaDesktop? No, Malwarebytes removes YeaDesktop completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the YeaDesktop adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks some of the connections the adware tries to make: Technical details for experts Possible signs in FRST logs: () C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe HKCU\...\Run: [YeaDesktop] => C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe [2903552 2017-04-12] () C:\Program Files (x86)\YeaDesktop C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop 1.0.0.1 (HKLM-x32\...\YeaDesktop) (Version: 1.0.0.1 - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\YeaDesktop Adds the file config.xml"="4/20/2017 10:12 AM, 1488 bytes, A Adds the file HelpTool.dll"="4/11/2017 5:18 PM, 1526272 bytes, A Adds the file unins000.dat"="4/20/2017 10:12 AM, 23045 bytes, A Adds the file unins000.exe"="4/20/2017 10:12 AM, 961334 bytes, A Adds the file YeaDesktop.exe"="4/12/2017 9:56 AM, 2903552 bytes, A Adds the folder C:\Program Files (x86)\YeaDesktop\common Adds the file apphoverbk.png"="1/17/2017 4:31 PM, 355 bytes, A Adds the file BkgSelectedHover.png"="1/17/2017 4:31 PM, 364 bytes, A Adds the file BkgSelectedNormal.png"="1/17/2017 4:31 PM, 255 bytes, A Adds the file BkgSelectedPressed.png"="1/17/2017 4:31 PM, 366 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop Adds the file Uninstall YeaDesktop.lnk"="4/20/2017 10:12 AM, 1039 bytes, A Adds the file YeaDesktop.lnk"="4/20/2017 10:12 AM, 1049 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION] "YeaDesktop.exe"="REG_DWORD", 11001 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YeaDesktop] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe" "DisplayName"="REG_SZ", "1.0.0.1" "DisplayVersion"="REG_SZ", "1.0.0.1" "EstimatedSize"="REG_DWORD", 5259 "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\YeaDesktop" "Inno Setup: Icon Group"="REG_SZ", "YeaDesktop" "Inno Setup: Language"="REG_SZ", "default" "Inno Setup: Setup Version"="REG_SZ", "5.4.2.ee2 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170420" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\YeaDesktop\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\YeaDesktop\unins000.exe" /SILENT" "UninstallDataFile"="REG_SZ", "C:\Program Files (x86)\YeaDesktop\unins000.dat" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\YeaDesktop\unins000.exe"" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "YeaDesktop"="REG_SZ", "C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe /autostart" [HKEY_CURRENT_USER\Software\YeaDesktop] "InsM"="REG_DWORD", 1 "InsTM"="REG_QWORD, .... "Silent"="REG_DWORD", 1 "TmN"="REG_SZ", "51471" [HKEY_CURRENT_USER\Software\YeaDesktop\actv] "(Default)"="REG_SZ", "" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/20/17 Scan Time: 10:29 AM Logfile: mbamYeaDesktop.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.103 Update Package Version: 1.0.1766 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 327575 Time Elapsed: 1 min, 27 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, Quarantined, [1444], [391396],1.0.1766 Module: 1 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, Quarantined, [1444], [391396],1.0.1766 Registry Key: 2 PUP.Optional.YeaDesktop, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\YeaDesktop, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, HKCU\SOFTWARE\YeaDesktop, Delete-on-Reboot, [1444], [391400],1.0.1766 Registry Value: 1 PUP.Optional.YeaDesktop, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|YeaDesktop, Delete-on-Reboot, [1444], [391396],1.0.1766 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 3 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\PROGRAM FILES (X86)\YeaDesktop, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\YEADESKTOP, Delete-on-Reboot, [1444], [391395],1.0.1766 File: 13 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\apphoverbk.png, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedHover.png, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedNormal.png, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\common\BkgSelectedPressed.png, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\config.xml, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\HelpTool.dll, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\unins000.dat, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\unins000.exe, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe, Delete-on-Reboot, [1444], [391396],1.0.1766 PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\Uninstall YeaDesktop.lnk, Delete-on-Reboot, [1444], [391395],1.0.1766 PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\YeaDesktop.lnk, Delete-on-Reboot, [1444], [391395],1.0.1766 PUP.Optional.YeaDesktop, C:\USERS\{username}\DESKTOP\YEADESKTOP_51471.EXE, Delete-on-Reboot, [1444], [391393],1.0.1766 PUP.Optional.YeaDesktop, C:\USERS\{username}\APPDATA\LOCAL\TEMP\YEAPUSERINFO.INI, Delete-on-Reboot, [1444], [391398],1.0.1766 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  7. What is setupsk? The Malwarebytes research team has determined that setupsk is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one sets a proxy port on visits to certain domains and IPs. How do I know if my computer is affected by setupsk? You may see this entry in your list of installed software: and these warnings during install: these Scheduled Tasks: How did setupsk get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software. How do I remove setupsk? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of setupsk? No, Malwarebytes removes setupsk completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the setupsk hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: () C:\Users\{username}\AppData\Roaming\setupsk\python\pythonw.exe HKCU\...\Run: [setupsk_upd] => C:\Users\{username}\AppData\Roaming\setupsk_upd\python\pythonw.exe [27136 2012-09-29] () HKCU\...\Run: [setupsk] => C:\Users\{username}\AppData\Roaming\setupsk\python\pythonw.exe [27136 2012-09-29] () C:\Windows\System32\Tasks\setupsk_upd C:\Windows\System32\Tasks\setupsk C:\Users\{username}\AppData\Roaming\setupsk C:\Users\{username}\AppData\Roaming\setupsk_upd setupsk (HKCU\...\setupsk) (Version: - ) Task: {2CD7F699-A883-44C4-900B-EA04AF7E4AF6} - System32\Tasks\setupsk => C:\Users\{username}\AppData\Roaming\setupsk\python\pythonw.exe [2012-09-29] () Task: {86E66202-596A-4E46-B15A-CE52C138B39C} - System32\Tasks\setupsk_upd => C:\Users\{username}\AppData\Roaming\setupsk_upd\python\pythonw.exe [2012-09-29] () Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\setupsk Adds the file httpfilter.bin"="4/19/2017 9:17 AM, 972800 bytes, A Adds the file httpfilter.bin.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the file httpfilter.py"="4/19/2017 9:17 AM, 21778 bytes, A Adds the file httpfilter.py.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the file id.txt"="4/19/2017 9:17 AM, 30 bytes, A Adds the file localconfig.json"="4/3/2017 5:21 PM, 55 bytes, A Adds the file ml.py"="4/19/2017 9:17 AM, 12861 bytes, A Adds the file ml.py.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the file rules.ini"="4/19/2017 9:17 AM, 626 bytes, A Adds the file rules.ini.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the file settings.ini"="4/19/2017 9:17 AM, 20369 bytes, A Adds the file settings.ini.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the file subid.txt"="4/19/2017 9:16 AM, 0 bytes, A Adds the file uninstall.exe"="4/19/2017 9:16 AM, 60337 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\configs Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\js Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python Adds the file msvcr100.dll"="2/19/2011 8:40 AM, 773968 bytes, A Adds the file python.exe"="9/29/2012 9:56 AM, 26624 bytes, A Adds the file python.exe.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the file python33.dll"="9/29/2012 9:55 AM, 2641408 bytes, A Adds the file pythonw.exe"="9/29/2012 9:56 AM, 27136 bytes, A Adds the file pythonw.exe.sha1"="4/19/2017 9:17 AM, 40 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\collections Adds the file __init__.py"="8/1/2012 10:05 AM, 43164 bytes, A Adds the file __main__.py"="8/1/2012 10:05 AM, 1313 bytes, A Adds the file abc.py"="8/1/2012 10:05 AM, 16686 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\collections\__pycache__ Adds the file __init__.cpython-33.pyc"="2/17/2017 6:54 PM, 69719 bytes, A Adds the file abc.cpython-33.pyc"="2/17/2017 6:54 PM, 35937 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\ctypes Adds the file __init__.py"="8/1/2012 10:05 AM, 17574 bytes, A Adds the file _endian.py"="3/25/2012 9:48 PM, 2013 bytes, A Adds the file util.py"="8/1/2012 10:05 AM, 8238 bytes, A Adds the file wintypes.py"="3/25/2012 9:48 PM, 5830 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\ctypes\__pycache__ Adds the file __init__.cpython-33.pyc"="2/17/2017 6:57 PM, 28719 bytes, A Adds the file _endian.cpython-33.pyc"="2/17/2017 6:57 PM, 3096 bytes, A Adds the file wintypes.cpython-33.pyc"="4/19/2017 9:17 AM, 8373 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\ctypes\macholib Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\ctypes\test Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\email Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\email\mime Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\encodings Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\encodings\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\http Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\json Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\logging Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\logging\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:16 AM, 82884 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages Adds the file README.txt"="5/7/2011 1:04 PM, 121 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\client Adds the file __init__.py"="2/17/2017 6:39 PM, 10460 bytes, A Adds the file _code_cache.py"="2/17/2017 6:39 PM, 5606 bytes, A Adds the file _events.py"="2/17/2017 6:39 PM, 11291 bytes, A Adds the file _generate.py"="2/17/2017 6:39 PM, 7298 bytes, A Adds the file dynamic.py"="2/17/2017 6:39 PM, 5927 bytes, A Adds the file lazybind.py"="2/17/2017 6:39 PM, 10188 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\client\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:17 AM, 10953 bytes, A Adds the file _code_cache.cpython-33.pyc"="4/19/2017 9:17 AM, 6327 bytes, A Adds the file _events.cpython-33.pyc"="4/19/2017 9:17 AM, 14040 bytes, A Adds the file _generate.cpython-33.pyc"="4/19/2017 9:17 AM, 6842 bytes, A Adds the file dynamic.cpython-33.pyc"="4/19/2017 9:17 AM, 9478 bytes, A Adds the file lazybind.cpython-33.pyc"="4/19/2017 9:17 AM, 11574 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\gen Adds the file __init__.py"="4/19/2017 9:17 AM, 56 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\gen\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:17 AM, 186 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\server Adds the file __init__.py"="2/17/2017 6:39 PM, 2390 bytes, A Adds the file automation.py"="2/17/2017 6:39 PM, 3006 bytes, A Adds the file connectionpoints.py"="2/17/2017 6:39 PM, 6201 bytes, A Adds the file inprocserver.py"="2/17/2017 6:39 PM, 4317 bytes, A Adds the file localserver.py"="2/17/2017 6:39 PM, 2392 bytes, A Adds the file register.py"="2/17/2017 6:39 PM, 14506 bytes, A Adds the file w_getopt.py"="2/17/2017 6:39 PM, 2701 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\server\__pycache__ Adds the file __init__.cpython-33.pyc"="2/17/2017 6:39 PM, 2819 bytes, A Adds the file automation.cpython-33.pyc"="2/17/2017 6:39 PM, 4934 bytes, A Adds the file connectionpoints.cpython-33.pyc"="2/17/2017 6:39 PM, 8031 bytes, A Adds the file inprocserver.cpython-33.pyc"="2/17/2017 6:39 PM, 6035 bytes, A Adds the file localserver.cpython-33.pyc"="2/17/2017 6:39 PM, 4677 bytes, A Adds the file register.cpython-33.pyc"="2/17/2017 6:39 PM, 16218 bytes, A Adds the file w_getopt.cpython-33.pyc"="2/17/2017 6:39 PM, 4056 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\test Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\test\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\tools Adds the file __init__.py"="2/17/2017 6:39 PM, 29 bytes, A Adds the file codegenerator.py"="2/17/2017 6:39 PM, 41196 bytes, A Adds the file tlbparser.py"="2/17/2017 6:39 PM, 31825 bytes, A Adds the file typedesc.py"="2/17/2017 6:39 PM, 3896 bytes, A Adds the file typedesc_base.py"="2/17/2017 6:39 PM, 5414 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\comtypes\tools\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:17 AM, 188 bytes, A Adds the file codegenerator.cpython-33.pyc"="4/19/2017 9:17 AM, 42807 bytes, A Adds the file tlbparser.cpython-33.pyc"="2/17/2017 6:39 PM, 31017 bytes, A Adds the file typedesc.cpython-33.pyc"="4/19/2017 9:17 AM, 12748 bytes, A Adds the file typedesc_base.cpython-33.pyc"="4/19/2017 9:17 AM, 18960 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\rdtypes Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\rdtypes\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\rdtypes\ANY Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\rdtypes\ANY\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\rdtypes\IN Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\site-packages\dns\rdtypes\IN\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk\python\Lib\urllib Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections Adds the file __init__.py"="8/1/2012 10:05 AM, 43164 bytes, A Adds the file __main__.py"="8/1/2012 10:05 AM, 1313 bytes, A Adds the file abc.py"="8/1/2012 10:05 AM, 16686 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections\__pycache__ Adds the file __init__.cpython-33.pyc"="2/17/2017 6:54 PM, 69719 bytes, A Adds the file abc.cpython-33.pyc"="2/17/2017 6:54 PM, 35937 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes Adds the file __init__.py"="8/1/2012 10:05 AM, 17574 bytes, A Adds the file _endian.py"="3/25/2012 9:48 PM, 2013 bytes, A Adds the file util.py"="8/1/2012 10:05 AM, 8238 bytes, A Adds the file wintypes.py"="3/25/2012 9:48 PM, 5830 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\__pycache__ Adds the file __init__.cpython-33.pyc"="2/17/2017 6:57 PM, 28719 bytes, A Adds the file _endian.cpython-33.pyc"="2/17/2017 6:57 PM, 3096 bytes, A Adds the file wintypes.cpython-33.pyc"="4/19/2017 9:16 AM, 8386 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\test Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\email Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\email\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\email\mime Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\encodings Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\encodings\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\http Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\http\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:17 AM, 165 bytes, A Adds the file client.cpython-33.pyc"="4/19/2017 9:17 AM, 45039 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\json Adds the file __init__.py"="8/1/2012 10:05 AM, 13045 bytes, A Adds the file decoder.py"="8/1/2012 10:05 AM, 13467 bytes, A Adds the file encoder.py"="8/1/2012 10:05 AM, 15441 bytes, A Adds the file scanner.py"="3/25/2012 9:48 PM, 2479 bytes, A Adds the file tool.py"="8/1/2012 10:05 AM, 935 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\json\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:17 AM, 12976 bytes, A Adds the file decoder.cpython-33.pyc"="4/19/2017 9:17 AM, 12820 bytes, A Adds the file encoder.cpython-33.pyc"="4/19/2017 9:17 AM, 15207 bytes, A Adds the file scanner.cpython-33.pyc"="4/19/2017 9:17 AM, 3042 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\logging Adds the file __init__.py"="8/1/2012 10:05 AM, 68090 bytes, A Adds the file config.py"="8/1/2012 10:05 AM, 35502 bytes, A Adds the file handlers.py"="8/1/2012 10:05 AM, 56306 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\logging\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:16 AM, 83028 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages Adds the file README.txt"="5/7/2011 1:04 PM, 121 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\client Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\client\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\gen Adds the file __init__.py"="4/19/2017 9:17 AM, 56 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\gen\__pycache__ Adds the file __init__.cpython-33.pyc"="4/19/2017 9:17 AM, 187 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\server Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\server\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\test Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\test\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\tools Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\comtypes\tools\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\rdtypes Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\rdtypes\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\rdtypes\ANY Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\rdtypes\ANY\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\rdtypes\IN Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site-packages\dns\rdtypes\IN\__pycache__ Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\urllib Adds the folder C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\urllib\__pycache__ In the existing folder C:\Windows\System32\Tasks Adds the file setupsk"="4/19/2017 9:17 AM, 3456 bytes, A Adds the file setupsk_upd"="4/19/2017 9:17 AM, 3470 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "setupsk"="REG_SZ", ""C:\Users\{username}1\AppData\Roaming\setupsk\python\pythonw.exe" "C:\Users\{username}1\AppData\Roaming\setupsk\ml.py" --APPNAME="setupsk"" "setupsk_upd"="REG_SZ", ""C:\Users\{username}1\AppData\Roaming\SETUPS~1\python\pythonw.exe" "C:\Users\{username}1\AppData\Roaming\SETUPS~1\ml.py" --APPNAME="setupsk_upd"" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\setupsk] "DisplayIcon"="REG_SZ", "C:\Users\{username}\AppData\Roaming\setupsk\uninstall.exe" "DisplayName"="REG_SZ", "setupsk" "UninstallString"="REG_SZ", "C:\Users\{username}\AppData\Roaming\setupsk\uninstall.exe" [HKEY_CURRENT_USER\Software\setupsk] "(Default)"="REG_SZ", "C:\Users\{username}\AppData\Roaming\setupsk" Most relevant part of Malwarebytes log (contact me for the full log): Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/19/17 Scan Time: 9:35 AM Logfile: mbamProxyPup.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1758 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 327671 Time Elapsed: 2 min, 12 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 6 PUP.Optional.RussAd, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\setupsk, Delete-on-Reboot, [12], [387127],1.0.1758 Adware.StartPage, HKCU\SOFTWARE\setupsk, Delete-on-Reboot, [1154], [387357],1.0.1758 PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\setupsk, Delete-on-Reboot, [57], [381377],1.0.1758 PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\setupsk_upd, Delete-on-Reboot, [57], [381377],1.0.1758 PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{2CD7F699-A883-44C4-900B-EA04AF7E4AF6}, Delete-on-Reboot, [57], [381374],1.0.1758 PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{86E66202-596A-4E46-B15A-CE52C138B39C}, Delete-on-Reboot, [57], [381374],1.0.1758 Registry Value: 4 PUP.Optional.StartPage, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|setupsk_upd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|setupsk, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{2CD7F699-A883-44C4-900B-EA04AF7E4AF6}|PATH, Delete-on-Reboot, [57], [381374],1.0.1758 PUP.Optional.StartPage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{86E66202-596A-4E46-B15A-CE52C138B39C}|PATH, Delete-on-Reboot, [57], [381374],1.0.1758 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 88 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\USERS\{username}\APPDATA\ROAMING\setupsk_upd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\Lib, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\configs, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\USERS\{username}\APPDATA\ROAMING\SETUPSK, Delete-on-Reboot, [57], [381378],1.0.1758 File: 1510 PUP.Optional.StartPage, C:\USERS\{username}\APPDATA\ROAMING\SETUPSK_UPD\PYTHON\PYTHONW.EXE, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs\select.pyd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs\unicodedata.pyd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs\_ctypes.pyd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs\_socket.pyd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\DLLs\_ssl.pyd, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections\__pycache__\abc.cpython-33.pyc, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections\__pycache__\__init__.cpython-33.pyc, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections\abc.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections\__init__.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\collections\__main__.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\dyld.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\dylib.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\fetch_macholib, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\fetch_macholib.bat, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\framework.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\README.ctypes, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ctypes\macholib\__init__.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\quopri.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\abc.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\argparse.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\base64.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\bisect.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\calendar.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\codecs.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\contextlib.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\copy.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\copyreg.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\datetime.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\decimal.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\dummy_threading.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\fnmatch.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\functools.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\genericpath.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\hashlib.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\heapq.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\hmac.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\io.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\keyword.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\linecache.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\locale.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\mimetypes.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ntpath.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\nturl2path.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\numbers.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\optparse.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\os.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\pickle.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\posixpath.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\random.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\re.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\reprlib.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\shutil.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\site.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\socket.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\sre_compile.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\sre_constants.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\sre_parse.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\ssl.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\stat.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\string.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\stringprep.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\struct.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\subprocess.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\sysconfig.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\tarfile.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\tempfile.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\textwrap.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\threading.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\token.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\tokenize.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\traceback.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\types.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\uu.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\warnings.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\weakref.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\_compat_pickle.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\_dummy_thread.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\_weakrefset.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\Lib\__future__.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\msvcr100.dll, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\python.exe, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\python\python33.dll, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\app.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\ml.py, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\path.txt, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk_upd\time.txt, Delete-on-Reboot, [57], [387141],1.0.1758 PUP.Optional.RussAd, C:\USERS\{username}\APPDATA\ROAMING\SETUPSK\UNINSTALL.EXE, Delete-on-Reboot, [12], [387127],1.0.1758 PUP.Optional.StartPage, C:\USERS\{username}\APPDATA\ROAMING\SETUPSK\ML.PY, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\configs\rules.ini, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\configs\settings.ini, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\common.js, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\common.js.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\meech.js, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\meech.js.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\orm.js, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\orm.js.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\vkopt.js, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\vkopt.js.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\vk_lib.js, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\js\vk_lib.js.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs\select.pyd, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs\unicodedata.pyd, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs\_ctypes.pyd, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs\_socket.pyd, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\DLLs\_ssl.pyd, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\msvcr100.dll, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\python.exe, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\python.exe.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\python33.dll, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\pythonw.exe, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\python\pythonw.exe.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\httpfilter.bin, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\httpfilter.bin.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\httpfilter.py, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\httpfilter.py.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\id.txt, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\localconfig.json, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\ml.py.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\rules.ini, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\rules.ini.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\settings.ini, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\settings.ini.sha1, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\subid.txt, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.StartPage, C:\Users\{username}\AppData\Roaming\setupsk\time.txt, Delete-on-Reboot, [57], [381378],1.0.1758 PUP.Optional.RussAd, C:\USERS\{username}\DESKTOP\PYTHONPROXY.EXE, Delete-on-Reboot, [12], [387127],1.0.1758 PUP.Optional.StartPage, C:\WINDOWS\SYSTEM32\TASKS\setupsk, Delete-on-Reboot, [57], [381379],1.0.1758 PUP.Optional.StartPage, C:\WINDOWS\SYSTEM32\TASKS\setupsk_upd, Delete-on-Reboot, [57], [381379],1.0.1758 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  8. What is Tables? The Malwarebytes research team has determined that Tables is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements. How do I know if my computer is affected by Tables? You may see this entry in your list of installed software: and these browser add-ons in Chrome and Opera: The extension in Firefox did not show up in the list but the files were there. How did Tables get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software. How do I remove Tables? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Tables? No, Malwarebytes removes Tables completely. If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the Tables entry. If you are using Opera, you may have to remove the Extension manually under Opera > Extensions, first disable the extension and then click the x behind Tables and click OK in the prompt to confirm. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the Tables hijacker. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: FF user.js: detected! => C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\user.js [2017-04-12] FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\Extensions\669206@extcorp.com.xpi [2017-04-12] CHR Extension: (Tables) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2017-04-18] OPR Extension: (Tables) - C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj [2017-04-18] C:\Users\{username}\AppData\Roaming\BrowserModule AdvancedModule (HKCU\...\Advanced Module_is1) (Version: - ) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0 Adds the file index.html"="3/18/2017 6:05 PM, 118 bytes, A Adds the file manifest.json"="4/12/2017 11:16 AM, 1281 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon Adds the file icon128.png"="3/3/2017 5:43 PM, 3238 bytes, A Adds the file icon16.png"="3/3/2017 5:43 PM, 505 bytes, A Adds the file icon24.png"="3/3/2017 5:43 PM, 727 bytes, A Adds the file icon32.png"="3/3/2017 5:43 PM, 618 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\js Adds the file background.js"="4/12/2017 11:23 AM, 4034 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\BrowserModule Adds the file unins000.dat"="4/18/2017 9:13 AM, 16173 bytes, A Adds the file unins000.exe"="4/18/2017 9:13 AM, 1202385 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile} Adds the file user.js"="4/12/2017 11:16 AM, 247 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\chrome Adds the file userContent.css"="3/3/2017 8:27 PM, 42 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions Adds the file 669206@extcorp.com.xpi"="4/12/2017 11:16 AM, 9961 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0 Adds the file index.html"="3/18/2017 6:05 PM, 118 bytes, A Adds the file manifest.json"="4/12/2017 11:16 AM, 882 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon Adds the file icon128.png"="3/3/2017 5:43 PM, 3238 bytes, A Adds the file icon16.png"="3/3/2017 5:43 PM, 505 bytes, A Adds the file icon24.png"="3/3/2017 5:43 PM, 727 bytes, A Adds the file icon32.png"="3/3/2017 5:43 PM, 618 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\js Adds the file background.js"="4/12/2017 11:16 AM, 4215 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\BrowserModule] "instevent"="REG_SZ", "completed" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Module_is1] "DisplayName"="REG_SZ", "AdvancedModule" "EstimatedSize"="REG_DWORD", 1379 "Inno Setup: App Path"="REG_SZ", "C:\Users\{username}\AppData\Roaming\BrowserModule" "Inno Setup: Deselected Components"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "(Default)" "Inno Setup: Language"="REG_SZ", "default" "Inno Setup: Selected Components"="REG_SZ", "chromeext,mozillaext,operaext" "Inno Setup: Setup Type"="REG_SZ", "full" "Inno Setup: Setup Version"="REG_SZ", "5.5.9 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170418" "InstallLocation"="REG_SZ", "C:\Users\{username}\AppData\Roaming\BrowserModule\" "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\BrowserModule\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\BrowserModule\unins000.exe"" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/18/17 Scan Time: 9:31 AM Logfile: mbamTablesExtensions.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1751 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 327079 Time Elapsed: 1 min, 13 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.BrowserModule, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Advanced Module_is1, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, HKCU\SOFTWARE\BROWSERMODULE, Delete-on-Reboot, [2207], [389761],1.0.1751 Registry Value: 2 PUP.Optional.BrowserModule, HKCU\SOFTWARE\BROWSERMODULE|INSTEVENT, Delete-on-Reboot, [2207], [389761],1.0.1751 PUP.Optional.BrowserModule, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ADVANCED MODULE_IS1|INNO SETUP: APP PATH, Delete-on-Reboot, [2207], [389764],1.0.1751 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 9 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\BROWSERMODULE, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\js, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\FNGMHNNPILHPLAEEDIFHCCCEOMCLGFBG, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\js, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\EGAFJHHPBIPCMPOIOMEGBCKLJBBBPHOJ, Delete-on-Reboot, [2207], [389743],1.0.1751 File: 19 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\BROWSERMODULE\UNINS000.DAT, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\BrowserModule\unins000.exe, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\DESKTOP\MYSETUP.EXE, Delete-on-Reboot, [2207], [389737],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\FNGMHNNPILHPLAEEDIFHCCCEOMCLGFBG\78.0_0\MANIFEST.JSON, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon128.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon16.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon24.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon32.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\js\background.js, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\index.html, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\CHROME\USERCONTENT.CSS, Delete-on-Reboot, [2207], [389741],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\EXTENSIONS\669206@extcorp.com.xpi, Delete-on-Reboot, [2207], [389762],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\EGAFJHHPBIPCMPOIOMEGBCKLJBBBPHOJ\1.1_0\MANIFEST.JSON, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon128.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon16.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon24.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon32.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\js\background.js, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\index.html, Delete-on-Reboot, [2207], [389743],1.0.1751 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  9. What is System Cleanup? The Malwarebytes research team has determined that System Cleanup is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with System Cleanup? This is how the main screen of the sytem optimizer looks: You will find these icons in your taskbar, your startmenu and on your desktop: and see these warnings during install: and this screen when you try to fix the so-called "problems": You may see this entry in your list of installed programs: How did System Cleanup get on my computer? These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their site. How do I remove System Cleanup? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of System Cleanup? No, Malwarebytes removes System Cleanup completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this system optimizer. As you can see below the full version of Malwarebytes would have protected you against the System Cleanup installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for experts You may see these entries in FRST logs: () C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.exe C:\Users\Public\Desktop\System Cleanup.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Cleanup C:\Program Files (x86)\Epicsofts System Cleanup version 1.0 (HKLM-x32\...\{21AB2F09-1C61-4A31-AECA-3ADE74BBEE59}_is1) (Version: 1.0 - Epicsofts) Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Epicsofts\System Cleanup Adds the file bactch.cmd"="10/21/2014 2:01 AM, 0 bytes, A Adds the file icon.ico"="1/6/2015 3:55 AM, 32038 bytes, A Adds the file OSVersionInfo.dll"="9/18/2014 9:23 PM, 19968 bytes, A Adds the file PC Wiper.exe"="9/8/2015 5:08 AM, 3833856 bytes, A Adds the file PC Wiper.exe.config"="10/17/2014 6:25 PM, 926 bytes, A Adds the file PC Wiper.pdb"="9/8/2015 5:08 AM, 298496 bytes, A Adds the file PC Wiper.vshost.exe"="9/8/2015 5:08 AM, 22984 bytes, A Adds the file PC Wiper.vshost.exe.config"="10/17/2014 6:25 PM, 926 bytes, A Adds the file PC Wiper.vshost.exe.manifest"="10/17/2014 9:32 PM, 2672 bytes, A Adds the file unins000.dat"="4/17/2017 12:50 PM, 5992 bytes, A Adds the file unins000.exe"="4/17/2017 12:48 PM, 747681 bytes, A Adds the folder C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication Adds the file Activation.xml"="1/6/2015 3:58 AM, 194 bytes, A Adds the file Sys_Auth.txt"="4/19/2014 5:57 AM, 13 bytes, A Adds the file sys_error_nbr.txt"="4/17/2017 12:53 PM, 4 bytes, A Adds the file sys_error_size.txt"="4/17/2017 12:53 PM, 6 bytes, A Adds the file sys_manage.txt"="1/6/2015 3:59 AM, 0 bytes, A Adds the file sys_read.txt"="4/17/2017 12:52 PM, 21 bytes, A Adds the folder C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves Adds the file Cleaned.wav"="4/14/2014 7:43 PM, 106064 bytes, A Adds the file Cleaning.wav"="4/12/2014 6:19 PM, 108368 bytes, A Adds the file done.wav"="4/9/2014 4:29 AM, 73808 bytes, A Adds the file Issues.wav"="4/23/2014 2:14 AM, 364112 bytes, A Adds the file scandone.png"="4/12/2014 9:08 PM, 39016 bytes, A Adds the file scanning.wav"="4/9/2014 4:29 AM, 115280 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Cleanup Adds the file System Cleanup on the Web.url"="4/17/2017 12:50 PM, 131 bytes, A Adds the file System Cleanup.lnk"="4/17/2017 12:50 PM, 1313 bytes, A Adds the file Uninstall System Cleanup.lnk"="4/17/2017 12:50 PM, 1313 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file System Cleanup.lnk"="4/17/2017 12:50 PM, 1295 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{21AB2F09-1C61-4A31-AECA-3ADE74BBEE59}_is1] "Comments"="REG_SZ", "System Cleanup" "Contact"="REG_SZ", "877-780-7768" "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Epicsofts\System Cleanup\icon.ico" "DisplayName"="REG_SZ", "System Cleanup version 1.0" "DisplayVersion"="REG_SZ", "1.0" "EstimatedSize"="REG_DWORD", 9364 "HelpLink"="REG_SZ", "http://www.epicsofts.com/" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Epicsofts\System Cleanup" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "System Cleanup" "Inno Setup: Language"="REG_SZ", "english" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon" "Inno Setup: Setup Version"="REG_SZ", "5.5.6 (a)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20170417" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Epicsofts\System Cleanup\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Epicsofts" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Epicsofts\System Cleanup\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Epicsofts\System Cleanup\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.epicsofts.com/" "URLUpdateInfo"="REG_SZ", "http://www.epicsofts.com/" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/17/17 Scan Time: 1:07 PM Logfile: mbamSystemCleaner.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.103 Update Package Version: 1.0.1746 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 327056 Time Elapsed: 1 min, 18 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.exe, Quarantined, [2640], [350906],1.0.1746 Module: 1 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.exe, Quarantined, [2640], [350906],1.0.1746 Registry Key: 1 PUP.Optional.Epicsofts, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{21AB2F09-1C61-4A31-AECA-3ADE74BBEE59}_is1, Delete-on-Reboot, [2640], [350906],1.0.1746 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 6 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\PROGRAM FILES (X86)\EPICSOFTS\SYSTEM CLEANUP, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SYSTEM CLEANUP, Delete-on-Reboot, [2640], [350907],1.0.1746 File: 28 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves\Cleaned.wav, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves\Cleaning.wav, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves\done.wav, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves\Issues.wav, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves\scandone.png, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\System Cleanup\Waves\scanning.wav, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication\Activation.xml, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication\Sys_Auth.txt, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication\sys_error_nbr.txt, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication\sys_error_size.txt, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication\sys_manage.txt, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\Sys_auth\Authentication\sys_read.txt, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\bactch.cmd, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\icon.ico, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\OSVersionInfo.dll, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.exe, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.exe.config, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.pdb, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.vshost.exe, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.vshost.exe.config, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\PC Wiper.vshost.exe.manifest, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\unins000.dat, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\Program Files (x86)\Epicsofts\System Cleanup\unins000.exe, Delete-on-Reboot, [2640], [350906],1.0.1746 PUP.Optional.Epicsofts, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Cleanup\System Cleanup on the Web.url, Delete-on-Reboot, [2640], [350907],1.0.1746 PUP.Optional.Epicsofts, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Cleanup\System Cleanup.lnk, Delete-on-Reboot, [2640], [350907],1.0.1746 PUP.Optional.Epicsofts, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Cleanup\Uninstall System Cleanup.lnk, Delete-on-Reboot, [2640], [350907],1.0.1746 PUP.Optional.Epicsofts, C:\USERS\PUBLIC\DESKTOP\SYSTEM CLEANUP.LNK, Delete-on-Reboot, [2640], [350911],1.0.1746 PUP.Optional.Epicsofts, C:\USERS\{username}\DESKTOP\SYSTEM_CLEANUP.EXE, Delete-on-Reboot, [2640], [350905],1.0.1746 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  10. What is MeSafe? The Malwarebytes research team has determined that MeSafe is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by MeSafe? You may see this entry in your list of Chrome extensions: and this icon in the Chrome taskbar: How did MeSafe get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove MeSafe? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of MeSafe? No, Malwarebytes removes MeSafe completely. You may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the MeSafe entry. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the MeSafe adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: CHR Extension: (MeSafe) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana [2017-04-14] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0 Adds the file background.html"="4/14/2017 8:23 AM, 154 bytes, A Adds the file manifest.json"="4/14/2017 8:23 AM, 1371 bytes, A Adds the file popup.html"="4/14/2017 8:23 AM, 669 bytes, A Adds the file warn.html"="4/14/2017 8:23 AM, 1356 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\de Adds the file messages.json"="4/14/2017 8:23 AM, 494 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\en Adds the file messages.json"="4/14/2017 8:23 AM, 472 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\ru Adds the file messages.json"="4/14/2017 8:23 AM, 581 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_metadata Adds the file computed_hashes.json"="4/14/2017 8:23 AM, 6789 bytes, A Adds the file verified_contents.json"="4/14/2017 8:23 AM, 4111 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\css Adds the file bootstrap.css"="4/14/2017 8:23 AM, 191738 bytes, A Adds the file popup.css"="4/14/2017 8:23 AM, 413 bytes, A Adds the file warn.css"="4/14/2017 8:23 AM, 462 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images Adds the file icon128.png"="4/14/2017 8:23 AM, 7687 bytes, A Adds the file icon16.png"="4/14/2017 8:23 AM, 803 bytes, A Adds the file icon19.png"="4/14/2017 8:23 AM, 1042 bytes, A Adds the file icon19_red.png"="4/14/2017 8:23 AM, 1426 bytes, A Adds the file icon38.png"="4/14/2017 8:23 AM, 2457 bytes, A Adds the file icon38_red.png"="4/14/2017 8:23 AM, 2992 bytes, A Adds the file icon48.png"="4/14/2017 8:23 AM, 3151 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js Adds the file background.js"="4/14/2017 8:23 AM, 4097 bytes, A Adds the file content.js"="4/14/2017 8:23 AM, 1308 bytes, A Adds the file jquery.js"="4/14/2017 8:23 AM, 277125 bytes, A Adds the file popup.js"="4/14/2017 8:23 AM, 2752 bytes, A Adds the file warn.js"="4/14/2017 8:23 AM, 2701 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\mesafe] "status"="REG_SZ", "1" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/14/17 Scan Time: 8:39 AM Logfile: mbamMeSafe.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1725 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 326803 Time Elapsed: 1 min, 18 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 1 PUP.Optional.MeSafe, HKCU\SOFTWARE\MESAFE, Delete-on-Reboot, [9021], [389387],1.0.1725 Registry Value: 1 PUP.Optional.MeSafe, HKCU\SOFTWARE\MESAFE|STATUS, Delete-on-Reboot, [9021], [389387],1.0.1725 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 10 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\de, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\en, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\ru, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_metadata, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\css, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\NKKNFLEDGPMLNAPBBFDAHIIGCANJGANA, Delete-on-Reboot, [9021], [389385],1.0.1725 File: 25 PUP.Optional.MeSafe, C:\USERS\{username}\DESKTOP\MESAFE.EXE, Delete-on-Reboot, [9021], [389383],1.0.1725 PUP.Optional.MeSafe, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\NKKNFLEDGPMLNAPBBFDAHIIGCANJGANA\0.1.3_0\MANIFEST.JSON, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\css\bootstrap.css, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\css\popup.css, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\css\warn.css, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon128.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon16.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon19.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon19_red.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon38.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon38_red.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\images\icon48.png, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js\background.js, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js\content.js, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js\jquery.js, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js\popup.js, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\js\warn.js, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\de\messages.json, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\en\messages.json, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_locales\ru\messages.json, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_metadata\computed_hashes.json, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\_metadata\verified_contents.json, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\background.html, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\popup.html, Delete-on-Reboot, [9021], [389385],1.0.1725 PUP.Optional.MeSafe, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkknfledgpmlnapbbfdahiigcanjgana\0.1.3_0\warn.html, Delete-on-Reboot, [9021], [389385],1.0.1725 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  11. What is GlobalWeather? The Malwarebytes research team has determined that GlobalWeather is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by GlobalWeather? You may see this entry in your list of installed programs and features: and this warning during install: How did GlobalWeather get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software. How do I remove GlobalWeather? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of GlobalWeather? No, Malwarebytes removes GlobalWeather completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the GlobalWeather adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. Technical details for experts Possible signs in FRST logs: () C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherServ.exe R2 WeatherService; C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherServ.exe [147656 2017-03-02] () C:\Users\Public\Documents\Tools C:\Users\{username}\AppData\Roaming\GlobalWeather C:\Program Files (x86)\GlobalWeather C:\Users\{username}\AppData\Local\Temp\weatherHelper.exe GlobalWeather 2.0.0.0 (HKLM\...\{F772C08D-9F61-45c6-0407-ADDEEE0D92C6}) (Version: 2.0.0.0 - ShenZhen xingzhidao co,.Ltd) () C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherUpdate.dll Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\GlobalWeather\2.0.0.0 Adds the file Report.exe"="3/2/2017 3:05 AM, 327368 bytes, A Adds the file weatherHelper.exe"="3/2/2017 3:05 AM, 753352 bytes, A Adds the file weatherServ.exe"="3/2/2017 3:05 AM, 147656 bytes, A Adds the file weatherUpdate.dll"="3/2/2017 3:05 AM, 575176 bytes, A Adds the folder C:\Program Files (x86)\GlobalWeather\2.0.0.0\UpdateData Adds the folder C:\Users\{username}\AppData\Roaming\GlobalWeather\dump Adds the folder C:\Users\Public\Documents\Tools\Common\I18N Adds the file conf.db"="4/13/2017 9:04 AM, 367 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\GlobalWeather\dump Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\GlobalWeather] "FrID"="REG_SZ", "MVgA5hV0HA==" "INSTALL_FIRST_TIME"="REG_SZ", "2017-04-13_09:04:37" "PartnerID"="REG_SZ", "base" "UserID"="REG_SZ", "6f3bb58c3fd9e2aaf610e56356f706c9" "Version"="REG_SZ", "2.0.0.0" [HKEY_LOCAL_MACHINE\SOFTWARE\GlobalWeather\2.0.0.0] "INSTALL_PATH"="REG_SZ", "C:\Program Files (x86)\GlobalWeather\2.0.0.0" [HKEY_LOCAL_MACHINE\SOFTWARE\GlobalWeather\INSTALL_MARK] "version"="REG_SZ", "2.0.0.0" [HKEY_LOCAL_MACHINE\SOFTWARE\GlobalWeather\QUIT] "QuitSession"="REG_SZ", "{E96345A3-90EE-4A6C-AFCC-90E2A9B792D8}-1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F772C08D-9F61-45c6-0407-ADDEEE0D92C6}] "DisplayFullVersion"="REG_SZ", "2.0.0.0" "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherServ.exe" "DisplayName"="REG_SZ", "GlobalWeather 2.0.0.0" "DisplayVersion"="REG_SZ", "2.0.0.0" "Publisher"="REG_SZ", "ShenZhen xingzhidao co,.Ltd" "UninstallString"="REG_SZ", "C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherHelper.exe -Uninstall English" [HKEY_LOCAL_MACHINE\SOFTWARE\weatherUpdateTools] "{F772C08D-9F61-45c6-0407-ADDEEE0D92C6}"="REG_SZ", "{F772C08D-9F61-45c6-0407-ADDEEE0D92C6}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WeatherService] "DisplayName"="REG_SZ", "Weather Service" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherServ.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/13/17 Scan Time: 9:20 AM Logfile: mbamGlobalWeather.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1718 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 326654 Time Elapsed: 1 min, 44 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.GlobalWeather, C:\PROGRAM FILES (X86)\GLOBALWEATHER\2.0.0.0\WEATHERSERV.EXE, Quarantined, [9026], [389381],1.0.1718 Module: 2 PUP.Optional.GlobalWeather, C:\PROGRAM FILES (X86)\GLOBALWEATHER\2.0.0.0\WEATHERSERV.EXE, Quarantined, [9026], [389381],1.0.1718 PUP.Optional.GlobalWeather, C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherUpdate.dll, Quarantined, [9026], [389402],1.0.1718 Registry Key: 4 PUP.Optional.GlobalWeather, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WeatherService, Delete-on-Reboot, [9026], [389381],1.0.1718 PUP.Optional.GlobalWeather, HKLM\SOFTWARE\WEATHERUPDATETOOLS, Delete-on-Reboot, [9026], [389398],1.0.1718 PUP.Optional.GlobalWeather, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F772C08D-9F61-45c6-0407-ADDEEE0D92C6}, Delete-on-Reboot, [9026], [389402],1.0.1718 PUP.Optional.GlobalWeather, HKLM\SOFTWARE\GLOBALWEATHER, Delete-on-Reboot, [9026], [389399],1.0.1718 Registry Value: 3 PUP.Optional.GlobalWeather, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WEATHERSERVICE|IMAGEPATH, Delete-on-Reboot, [9026], [389403],1.0.1718 PUP.Optional.GlobalWeather, HKLM\SOFTWARE\WEATHERUPDATETOOLS|{F772C08D-9F61-45C6-0407-ADDEEE0D92C6}, Delete-on-Reboot, [9026], [389398],1.0.1718 PUP.Optional.GlobalWeather, HKLM\SOFTWARE\GLOBALWEATHER|PARTNERID, Delete-on-Reboot, [9026], [389399],1.0.1718 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 3 PUP.Optional.GlobalWeather, C:\Program Files (x86)\GlobalWeather\2.0.0.0\UpdateData, Delete-on-Reboot, [9026], [389402],1.0.1718 PUP.Optional.GlobalWeather, C:\Program Files (x86)\GlobalWeather\2.0.0.0, Delete-on-Reboot, [9026], [389402],1.0.1718 PUP.Optional.GlobalWeather, C:\PROGRAM FILES (X86)\GLOBALWEATHER, Delete-on-Reboot, [9026], [389402],1.0.1718 File: 6 PUP.Optional.GlobalWeather, C:\PROGRAM FILES (X86)\GLOBALWEATHER\2.0.0.0\WEATHERSERV.EXE, Delete-on-Reboot, [9026], [389381],1.0.1718 PUP.Optional.GlobalWeather, C:\USERS\{username}\DESKTOP\GLOBALWEATHER.EXE, Delete-on-Reboot, [9026], [389382],1.0.1718 PUP.Optional.GlobalWeather, C:\USERS\{username}\APPDATA\LOCAL\TEMP\WEATHERHELPER.EXE, Delete-on-Reboot, [9026], [389380],1.0.1718 PUP.Optional.GlobalWeather, C:\PROGRAM FILES (X86)\GLOBALWEATHER\2.0.0.0\Report.exe, Delete-on-Reboot, [9026], [389402],1.0.1718 PUP.Optional.GlobalWeather, C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherHelper.exe, Delete-on-Reboot, [9026], [389402],1.0.1718 PUP.Optional.GlobalWeather, C:\Program Files (x86)\GlobalWeather\2.0.0.0\weatherUpdate.dll, Delete-on-Reboot, [9026], [389402],1.0.1718 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  12. What is Registry Scanner? The Malwarebytes research team has determined that Registry Scanner is a fake registry cleaner. These so-called "registry cleaners" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems. More information can be found on our Malwarebytes Labs blog. How do I know if I am infected with Registry Scanner? This is how the main screen of the registry cleaning application looks: You will find these icons in your taskbar, your startmenu, and on your desktop: And see this warning immediately after install: and these screens during "operations": You may see this task in your Task Scheduler: How did Registry Scanner get on my computer? These so-called registry cleaners use different methods of getting installed. This particular one was bundled by other software. How do I remove Registry Scanner? Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Registry Scanner? No, Malwarebytes removes Registry Scanner completely. The shortcut called Registry Scanner on the desktop can be deleted if it belonged to the rogue. This PUP creates a scheduled task. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this registry cleaner. As you can see below the full version of Malwarebytes would have protected you against the Registry Scanner installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block traffic to their domain. Technical details for experts You may see these entries in FRST logs: (Registry Scanner) C:\Program Files (x86)\Registry Scanner\Registry Scanner\System Ignitor.exe C:\Windows\System32\Tasks\Registry Scanner C:\Users\Public\Desktop\Registry Scanner.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Scanner C:\Program Files (x86)\Registry Scanner Task: {C9828F01-43F1-4FEC-8398-342883F265ED} - System32\Tasks\Registry Scanner => C:\Program Files (x86)\Registry Scanner\Registry Scanner\System Ignitor.exe [2017-04-09] (Registry Scanner) Alterations made by the installer: File system details --------------------------------------------- Adds the folder C:\Program Files (x86)\Registry Scanner\Registry Scanner Adds the file Error.xml"="4/12/2017 11:36 AM, 211 bytes, A Adds the file errordetails.xml"="4/12/2017 11:36 AM, 110682 bytes, A Adds the file ExtendedWindowsControls.dll"="8/21/2013 3:06 PM, 8192 bytes, A Adds the file helper.exe"="1/23/2017 9:36 PM, 7168 bytes, A Adds the file icon.ico"="4/19/2016 4:09 PM, 32038 bytes, A Adds the file issues.wav"="4/9/2017 1:28 PM, 242162 bytes, A Adds the file locii.txt"="3/16/2017 1:55 PM, 6 bytes, A Adds the file log.txt"="4/24/2014 7:25 AM, 3 bytes, A Adds the file log.xml"="4/12/2017 11:34 AM, 315 bytes, A Adds the file Microsoft.Win32.TaskScheduler.dll"="6/3/2014 1:08 AM, 171008 bytes, A Adds the file Newtonsoft.Json.dll"="6/14/2016 12:06 AM, 526336 bytes, A Adds the file Sys_auth.xml"="4/12/2017 11:34 AM, 316 bytes, A Adds the file System Ignitor.exe"="4/9/2017 1:36 PM, 2105856 bytes, A Adds the file System Ignitor.exe.config"="1/28/2017 3:22 PM, 1486 bytes, A Adds the file System Ignitor.pdb"="4/9/2017 1:36 PM, 480768 bytes, A Adds the file System Ignitor.vshost.exe"="4/9/2017 1:34 PM, 22984 bytes, A Adds the file System Ignitor.vshost.exe.config"="1/28/2017 3:22 PM, 1486 bytes, A Adds the file System Ignitor.vshost.exe.manifest"="11/18/2016 12:44 PM, 2673 bytes, A Adds the file trialerror.xml"="8/5/2014 5:21 AM, 55340 bytes, A Adds the file VTRegScan.dll"="4/30/2014 10:37 PM, 82944 bytes, A Adds the file WpfAnimatedGif.dll"="8/7/2013 11:30 AM, 28160 bytes, A Adds the folder C:\Program Files (x86)\Registry Scanner\Registry Scanner\de Adds the file System Ignitor.resources.dll"="4/9/2017 1:36 PM, 13824 bytes, A Adds the folder C:\Program Files (x86)\Registry Scanner\Registry Scanner\en Adds the file System Ignitor.resources.dll"="4/9/2017 1:36 PM, 12288 bytes, A Adds the folder C:\Program Files (x86)\Registry Scanner\Registry Scanner\es Adds the file System Ignitor.resources.dll"="4/9/2017 1:36 PM, 13824 bytes, A Adds the folder C:\Program Files (x86)\Registry Scanner\Registry Scanner\fr Adds the file System Ignitor.resources.dll"="4/9/2017 1:36 PM, 13824 bytes, A Adds the folder C:\Program Files (x86)\Registry Scanner\Registry Scanner\ja Adds the file System Ignitor.resources.dll"="4/9/2017 1:36 PM, 14848 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Scanner Adds the file Registry Scanner on the Web.url"="4/12/2017 11:33 AM, 134 bytes, A Adds the file Registry Scanner.lnk"="4/12/2017 11:33 AM, 1424 bytes, A Adds the file Uninstall Registry Scanner.lnk"="4/12/2017 11:33 AM, 310 bytes, A Adds the folder C:\Users\{username}\AppData\LocalLow\Mozilla\Temp-{3037838a-a14a-46f9-821d-9895a7c7705d} In the existing folder C:\Users\Public\Desktop Adds the file Registry Scanner.lnk"="4/12/2017 11:33 AM, 1406 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Registry Scanner"="4/12/2017 11:34 AM, 3132 bytes, A Registry details ------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\RegistryScanner\Scanner] "InstallPath"="REG_SZ", "C:\Program Files (x86)\Registry Scanner\Registry Scanner" "Track"="REG_SZ", "01" [HKEY_CURRENT_USER\Software\RegistryScanner\Scanner] "InstallPath"="REG_SZ", "C:\Program Files (x86)\Registry Scanner\Registry Scanner" "Track"="REG_SZ", "01" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/12/17 Scan Time: 11:52 AM Logfile: mbamSystemIgnitor.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1712 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 326426 Time Elapsed: 1 min, 30 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 Rogue.RegistryScanner, C:\PROGRAM FILES (X86)\REGISTRY SCANNER\REGISTRY SCANNER\SYSTEM IGNITOR.EXE, Quarantined, [8937], [384993],1.0.1712 Module: 1 Rogue.RegistryScanner, C:\PROGRAM FILES (X86)\REGISTRY SCANNER\REGISTRY SCANNER\SYSTEM IGNITOR.EXE, Quarantined, [8937], [384993],1.0.1712 Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 8 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\de, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\en, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\es, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\fr, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\ja, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\PROGRAM FILES (X86)\REGISTRY SCANNER, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\REGISTRY SCANNER, Delete-on-Reboot, [8937], [385007],1.0.1712 File: 30 Rogue.RegistryScanner, C:\PROGRAM FILES (X86)\REGISTRY SCANNER\REGISTRY SCANNER\SYSTEM IGNITOR.EXE, Delete-on-Reboot, [8937], [384993],1.0.1712 Rogue.RegistryScanner, C:\USERS\{username}\DESKTOP\REGISTRY-SCANNER-01236541_SILENT.EXE, Delete-on-Reboot, [8937], [384992],1.0.1712 Rogue.RegistryScanner, C:\PROGRAM FILES (X86)\REGISTRY SCANNER\REGISTRY SCANNER\SYSTEM IGNITOR.EXE.CONFIG, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\de\System Ignitor.resources.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\en\System Ignitor.resources.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\es\System Ignitor.resources.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\fr\System Ignitor.resources.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\ja\System Ignitor.resources.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\System Ignitor.pdb, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\Error.xml, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\errordetails.xml, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\ExtendedWindowsControls.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\helper.exe, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\icon.ico, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\issues.wav, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\locii.txt, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\log.txt, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\log.xml, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\Microsoft.Win32.TaskScheduler.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\Newtonsoft.Json.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\System Ignitor.vshost.exe, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\System Ignitor.vshost.exe.config, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\System Ignitor.vshost.exe.manifest, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\Sys_auth.xml, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\trialerror.xml, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\VTRegScan.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\Program Files (x86)\Registry Scanner\Registry Scanner\WpfAnimatedGif.dll, Delete-on-Reboot, [8937], [385010],1.0.1712 Rogue.RegistryScanner, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\REGISTRY SCANNER\REGISTRY SCANNER ON THE WEB.URL, Delete-on-Reboot, [8937], [385007],1.0.1712 Rogue.RegistryScanner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Scanner\Registry Scanner.lnk, Delete-on-Reboot, [8937], [385007],1.0.1712 Rogue.RegistryScanner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Scanner\Uninstall Registry Scanner.lnk, Delete-on-Reboot, [8937], [385007],1.0.1712 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  13. What is greenmartmediaads? The Malwarebytes research team has determined that greenmartmediaads is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by greenmartmediaads? You may see these changed settings in Internet Explorer under Internet Options > Connections > LAN settings : How did greenmartmediaads get on my computer? Adware applications use different methods for distributing themselves. This particular one was bundled with other software calling itself Flexart Setup. How do I remove greenmartmediaads? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of greenmartmediaads? No, Malwarebytes removes greenmartmediaads completely. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. As you can see below the full version of Malwarebytes would have protected you against the greenmartmediaads adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late. The web protection module also blocks some of the connections the installer tries to make: Technical details for experts Possible signs in FRST logs: (The Privoxy team - www.privoxy.org) C:\Windows\{computername}_030317\oxy.exe (greenmartmediaads) C:\Windows\{computername}_030317\Windebug.exe ProxyEnable: [{user SID}] => Proxy is enabled. ProxyServer: [{user SID}] => 127.0.0.1:8118 R2 Telephone; C:\Windows\{computername}_030317\oxy.exe [373248 2016-01-22] (The Privoxy team - www.privoxy.org) [File not signed] R2 Windefender; C:\Windows\{computername}_030317\Windebug.exe [3413504 2017-03-03] (greenmartmediaads) [File not signed] C:\Windows\{computername}_030317 () C:\Windows\{computername}_030317\mgwz.dll Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Windows\{computername}_030317 Adds the file config.txt"="3/28/2016 2:22 PM, 407 bytes, A Adds the file default.action"="2/7/2016 5:10 AM, 21 bytes, A Adds the file default.filter"="2/10/2017 5:09 AM, 108 bytes, A Adds the file mgwz.dll"="1/22/2016 3:45 AM, 86528 bytes, A Adds the file oxy.exe"="1/22/2016 3:45 AM, 373248 bytes, A Adds the file oxy.log"="4/11/2017 12:35 PM, 0 bytes, A Adds the file Windebug.exe"="3/3/2017 6:08 AM, 3413504 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{72B2A04D-03B2-4DE3-9026-2F6C30227602}_is1] "DisplayVersion"="REG_SZ", "1.02.1" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Telephone] "Description"="REG_SZ", "Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service." "DisplayName"="REG_SZ", "Telephone" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Windows\{computername}_030317\oxy.exe --service" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Windefender] "Description"="REG_SZ", "Helps protect users from malware and other potentially unwanted software" "DisplayName"="REG_SZ", "Win Defender Service" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Windows\{computername}_030317\Windebug.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyEnable" = REG_DWORD, 1 "ProxyServer"="REG_SZ", "127.0.0.1:8118" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/11/17 Scan Time: 12:54 PM Logfile: mbamPrivoxy.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1704 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 326135 Time Elapsed: 1 min, 17 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 2 Adware.Privoxy, C:\WINDOWS\{computername}_030317\OXY.EXE, Quarantined, [1969], [385808],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\Windebug.exe, Quarantined, [319], [305765],1.0.1704 Module: 3 Adware.Privoxy, C:\WINDOWS\{computername}_030317\OXY.EXE, Quarantined, [1969], [385808],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\mgwz.dll, Quarantined, [319], [305765],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\Windebug.exe, Quarantined, [319], [305765],1.0.1704 Registry Key: 3 Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TELEPHONE, Delete-on-Reboot, [1969], [385808],1.0.1704 Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Delete-on-Reboot, [1969], [-1],0.0.0 PUP.Optional.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Windefender, Delete-on-Reboot, [319], [305765],1.0.1704 Registry Value: 8 Adware.Privoxy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TELEPHONE|IMAGEPATH, Delete-on-Reboot, [1969], [385808],1.0.1704 Adware.Privoxy, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1969], [-1],0.0.0 Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1969], [-1],0.0.0 Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1969], [-1],0.0.0 Adware.Privoxy, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [1969], [-1],0.0.0 Adware.Privoxy, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Delete-on-Reboot, [1969], [-1],0.0.0 Adware.Privoxy.CNDIRDEL, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDEFENDER|DISPLAYNAME, Delete-on-Reboot, [8329], [388524],1.0.1704 PUM.Optional.ProxyHijacker, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Delete-on-Reboot, [12645], [250493],1.0.1704 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 1 PUP.Optional.Privoxy, C:\WINDOWS\{computername}_030317, Delete-on-Reboot, [319], [305765],1.0.1704 File: 8 Trojan.Dropper, C:\USERS\{username}\DESKTOP\SETUP.EXE, Delete-on-Reboot, [17], [388284],1.0.1704 Adware.Privoxy, C:\WINDOWS\{computername}_030317\OXY.EXE, Delete-on-Reboot, [1969], [385808],1.0.1704 PUP.Optional.Privoxy, C:\WINDOWS\{computername}_030317\CONFIG.TXT, Delete-on-Reboot, [319], [305765],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\default.action, Delete-on-Reboot, [319], [305765],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\default.filter, Delete-on-Reboot, [319], [305765],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\mgwz.dll, Delete-on-Reboot, [319], [305765],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\oxy.log, Delete-on-Reboot, [319], [305765],1.0.1704 PUP.Optional.Privoxy, C:\Windows\{computername}_030317\Windebug.exe, Delete-on-Reboot, [319], [305765],1.0.1704 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  14. What is CreateDocsOnline? The Malwarebytes research team has determined that CreateDocsOnline is a browser NewTab. These so-called "NewTabs" can manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. CreateDocsOnline is a member of the Mindspark/Ask family now known as IAC Applications. How do I know if my computer is affected by CreateDocsOnline? You may see these browser extensions/add-ons: You may see this entry in your list of installed software: these warnings during install: and this new startpage in the affected browsers: How did CreateDocsOnline get on my computer? Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their site. How do I remove CreateDocsOnline? Our program Malwarebytes can detect and remove this potentially unwanted program. You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of CreateDocsOnline? If you are using Chrome, you may have to remove the Extension manually under Tools > Settings > Extensions. Remove the checkmark and click on the bin behind the CreateDocsOnline entry. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this hijacker. As you can see below the full version of Malwarebytes would have protected you against the CreateDocsOnline hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic too some of their domains: Technical details for experts Possible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/createdocsonline/ttab02/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1} FF Homepage: hxxp://hp.myway.com/createdocsonline/ttab02/index.html?coId={coid2}&subId&ln=en&n={n1}&ptb={ptb2}&st=tab&p2={p22}&si FF Extension: CreateDocsOnline - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\Extensions\_j4Members_@free.createdocsonline.com [2017-04-10] CHR Extension: (CreateDocsOnline) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk [2017-04-10] C:\Users\{username}\AppData\Local\CreateDocsOnlineTooltab CreateDocsOnline Internet Explorer Homepage and New Tab (HKCU\...\CreateDocsOnlineTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION Most significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\CreateDocsOnlineTooltab Adds the file TooltabExtension.dll"="1/9/2017 11:27 PM, 266864 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0 Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\createdocsonline_j4 Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com Adds the file bootstrap.js"="4/10/2017 11:21 AM, 24730 bytes, A Adds the file chrome.manifest"="4/10/2017 11:21 AM, 135 bytes, A Adds the file chrome.manifest.restartless"="4/10/2017 11:21 AM, 135 bytes, A Adds the file install.rdf"="4/10/2017 11:21 AM, 1472 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\chrome Adds the file ffxtbr.jar"="4/10/2017 11:21 AM, 343784 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\META-INF Adds the file manifest.mf"="4/10/2017 11:21 AM, 680 bytes, A Adds the file mozilla.rsa"="4/10/2017 11:21 AM, 4195 bytes, A Adds the file mozilla.sf"="4/10/2017 11:21 AM, 121 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\CreateDocsOnline] "Start Page"="REG_SZ"", "http://hp.myway.com/createdocsonline/ttab02/index.html?n={n1}&p2=^CP5^yyyyyy^TTAB02^nl&ptb={ptb1}&coid={coid1}" "UnInstallSurveyUrl"="REG_SZ"", "http://@{downloadDomain}.dl.myway.com/uninstall.jhtml?surveyUrl=http%3A%2F%2Fwww.research.net%2Fr%2FHYSCVNM%3Fc%3D{ptb1}%26ptb%3{ptb2}&quot;!!~~~~~~~~~~ie-sucks~~~~~~~~~~~~!! [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://hp.myway.com/createdocsonline/ttab02/index.html?n={n1}&p2={p21}&ptb={ptb1}&coid={coid1}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\CreateDocsOnlineTooltab Uninstall Internet Explorer] "DisplayName"="REG_SZ"", "CreateDocsOnline Internet Explorer Homepage and New Tab" "HelpLink"="REG_SZ"", "http://support.mindspark.com/" "Publisher"="REG_SZ"", "Mindspark Interactive Network, Inc." "UninstallString"="REG_SZ"", "Rundll32.exe "C:\Users\{username}\AppData\Local\CreateDocsOnlineTooltab\TooltabExtension.dll" U uninstall:CreateDocsOnline" "URLInfoAbout"="REG_SZ"", "http://support.mindspark.com/" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/10/17 Scan Time: 11:31 AM Logfile: mbamCreateDocOnline.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1695 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 325870 Time Elapsed: 2 min, 27 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\CREATEDOCSONLINETOOLTAB\TOOLTABEXTENSION.DLL, Quarantined, [250], [301125],1.0.1695 Registry Key: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CreateDocsOnlineTooltab Uninstall Internet Explorer, Delete-on-Reboot, [250], [301125],1.0.1695 Registry Value: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\CreateDocsOnlineTooltab Uninstall Internet Explorer|PUBLISHER, Delete-on-Reboot, [250], [352442],1.0.1695 Registry Data: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replace-on-Reboot, [250], [293497],1.0.1695 Data Stream: 0 (No malicious items detected) Folder: 89 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\abstractbutton\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\thirdparty\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\uninstall\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\weather\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\weather\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\weather\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\generic\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\alert\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\link\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\weather, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\abstractbutton, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\rss\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\rss\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare\icons, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\images, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\rss, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\radioWrapper, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\thirdparty, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\foreground, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\uninstall, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\generic, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\weather, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\background, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\alert, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\link, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\rss, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\window, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\adapter, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\libs, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\_metadata, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MOGHNFLHLCPJKJKPNPGEBFFCJBMIFLJK, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\CreateDocsOnlineTooltab, Delete-on-Reboot, [755], [356944],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\META-INF, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\chrome, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\EXTENSIONS\_J4MEMBERS_@FREE.CREATEDOCSONLINE.COM, Delete-on-Reboot, [755], [371671],1.0.1695 File: 288 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\CREATEDOCSONLINETOOLTAB\TOOLTABEXTENSION.DLL, Delete-on-Reboot, [250], [301125],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [319354],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\PREFS.JS, Replaced, [755], [356946],1.0.1695 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_createdocsonline.dl.myway.com_0.localstorage, Delete-on-Reboot, [250], [240305],1.0.1695 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_createdocsonline.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [250], [240305],1.0.1695 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MOGHNFLHLCPJKJKPNPGEBFFCJBMIFLJK\12.600.11.14185_0\MANIFEST.JSON, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\adapter\adapterUtil.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\adapter\widget-adapter.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\abstractbutton\background\abstractButton.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\alert\background\alertButton.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\background\embedHtmlWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\html\embedHtmlTemplate.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedhtml\js\embedHtmlUI.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\background\embedScriptWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\html\embedScriptTemplate.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\html\innerEmbedScriptTemplate.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\embedscript\js\embedScriptUI.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare\background\FlareWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare\icons\Icon_Flare_blue.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare\icons\Icon_Flare_pink.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\flare\icons\Thumbs.db, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\generic\background\GenericWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\link\background\linkButton.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\background\menuButton.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\css\menuframe.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\html\menuframe.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\images\right_arrow.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\images\right_arrow_white.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\js\jquery-1.7.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\js\menuframe.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\js\query-string.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\js\underscore-1.3.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\menu\README.txt, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\rss\background\RssWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\thirdparty\background\thirdPartyWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\uninstall\background\uninstallButton.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\components\weather\background\weatherButton.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\bs.30.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\common.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\dynamic.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\enableDetect.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\eventListening.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\global.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\jquery-1.7.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\list-interaction.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\messageEventListener.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\navRedirector.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\paramReplacer.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\PartnerId.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\set.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\underscore-1.3.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\underscore-1.5.2.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\js\unifiedLogging.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common\common.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common\eventListening.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common\jquery-1.7.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common\list-interaction.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common\set.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\common\underscore-1.3.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\css\radio-widget.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\js\radio-custom.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\js\radio-parser.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\js\radio-widget-ui.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\js\radio-widget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\radio\radio-widget.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\rss\js\rss-widget-custom.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\rss\js\rss-widget-parse.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\rss\js\rss-widget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\rss\rssWidget.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\invalid.json, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\jquery.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\qunit.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\qunit.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\resource.json, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\resource.xml, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\testWidget.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\test\testWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\css\widget.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\js\topapps-config.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\js\widget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\topapps\widget.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\weather\css\weatherButton.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\weather\js\weather.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widgets\weather\weatherButton.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\common\widget-api\widget-context-1.0.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\background\ApiBasedWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\background\widget-api-impl.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\window\hiddenWidgetWindow.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\window\hiddenWidgetWindow.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\window\hiddenWidgetWindowInit.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\window\widgetWindow.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\api\window\widgetWindow.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\background\updateSearch.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\background\updateSearchPromptBg.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\07_buttons2.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\08_buttons2.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\defaultSearchModal.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\defaultSearchModalInjector.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\defaultSearchModalInjector.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\tvf_btn_ok.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\tvf_btn_ok2.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\tvf_restart_alert_icon.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\tvf_restart_icon.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\defaultSearch\foreground\updateSearchPromptFg.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\background\MovieReviewsWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\css\movieReviews.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\html\movieReviews.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\moviereviews\js\movieReviews.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\background\RadioWidget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\css\toolbar-item.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\foreground\button.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\radioWrapper\radioWrapper.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\radio\radioWrapper\radioWrapper.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\background\searchBox.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\html\searchSuggestions.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\html\searchSuggestions.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\html\searchSuggestions.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\search\html\searchSuggestionsInit.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\css\supertab.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\html\supertab.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js\newtabfork.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js\reporting.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js\srchsugg.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js\supertab.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js\unifiedLogging.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\components\supertab\js\__utm.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\_metadata\computed_hashes.json, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\_metadata\verified_contents.json, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\arrowSprite.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\icon128.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\icon16.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\icon19disabled.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\icon19on.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\icon48.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\icons\tb_icon_search_disappearing_ask.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\232471867.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\232471879.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\232471880.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\232471931.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\232471948.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\down_arrow.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\IDR_PRODUCT_LOGO_16.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\IDR_WEBSTORE_ICON.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\magnifying_glass.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\RadioPlayerSprite.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\search_button.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\tvf_icon_guide.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\tvf_logo.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\images\wrench.png, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\newTabInitialize.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\chromeStorage.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\chromeUtils.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\companionSWUtils.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\exeManager.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\exeManagerNMD.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\exePackageManager.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\focusManager.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\globalBlacklistManager.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\messaging.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\mutation_summary-min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\mutation_summary.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\nativeMessagingDispatcher.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\newTabInfo.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\options.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\readLocalStorage.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\reservespacefortoolbar.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\reservespaceifenabled.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\scriptInjector.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\searchContext.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\settingsOverrides.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\toolbarCookieParser.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\toolbarPreinit.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\underscore-1.3.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\URILoaderContentScript.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\webTooltabAPI.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\Widget.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\widgetContentScriptInjectee.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\widgetFactory.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\js\widgetWindowManager.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\libs\jquery-1.7.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\libs\jquery-1.9.1.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\libs\underscore-1.5.2.min.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\cache.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\ce.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\debug.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\native\ss.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\activePing.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\buttonLogger.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\competitorDnsList.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\console.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\FFPreferencesPersister.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\httpTransport.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\HttpURL.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\internationalSearch.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\LocalStoragePersister.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\MindsparkGlobal.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\MindsparkGlobal.unitTest.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\MindsparkGlobalNotes.txt, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\rsvp-latest.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\searchSuggestLocale.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\testHttpTransport.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\unifiedLogger.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\unifiedLogging.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\universalConsole.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\shared\utils.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spent2.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\bg.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\buildVars, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\buildVars.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\companionSW.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\config.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\contentScript.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\contentScript.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\debug.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\debug.jade, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spentJ.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spentK.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spentK.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\startup.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\stub.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\stubby.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\superFrame.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\toolbar.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\toolbar.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\toolbarUI.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\toolbarUI.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\toolbarUI.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\url.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\urlFragmentActions.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\webtooltab.cs.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\extension_toolbar_api.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\initWidgetWindow.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\newTabContentScript.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\options.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spent.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spent.html, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spent.js, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\moghnflhlcpjkjkpnpgebffcjbmifljk\12.600.11.14185_0\spent2.css, Delete-on-Reboot, [250], [301932],1.0.1695 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_createdocsonline.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [250], [240306],1.0.1695 PUP.Optional.MindSpark, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_createdocsonline.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [250], [240306],1.0.1695 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\EXTENSIONS\_J4MEMBERS_@FREE.CREATEDOCSONLINE.COM\BOOTSTRAP.JS, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\chrome\ffxtbr.jar, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\META-INF\manifest.mf, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\META-INF\mozilla.rsa, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\META-INF\mozilla.sf, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\chrome.manifest, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\chrome.manifest.restartless, Delete-on-Reboot, [755], [371671],1.0.1695 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}\extensions\_j4Members_@free.createdocsonline.com\install.rdf, Delete-on-Reboot, [755], [371671],1.0.1695 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  15. Intellitraces Tech Support Screenlocker The file called WMPNewtworksSvcx.exe mentioned in the post above tries to download and run a screenlocker for a Tech Support Scam. The screenlocker uses taskkill to shut down the Windows Taskmanager and turns the ESC key into a TAB key. The screenlocker can be unlocked by the code 8716098676542789 Using this will produce a prompt telling you that "Closing of the registration form is not allowed" Click OK on that prompt and you will have the control over the system back Now run the necessary steps outlined in the first post to install and run Malwarebytes. As you can see below the full version of Malwarebytes would have protected you against the Pcobserver installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and it blocks traffic the download location: