Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Имам вируси:аMuleCC,Kuaizip....

Featured Replies

Здравейте на екипът на kaldata.

Здравейте,имам следният проблем от известно време забелязвам че ми се запълва C но не слагам нищо там забелязах че се появиха тези имена който изброих във заглавието на темата след опит да ги премахна kuaizip отказва да се истрие aMuleCC го премахвам но пак се появява искам да попитам има ли някакъв шанс да ги премахна и защо ми се запълва C постоянно.

ето и системата ми

процесор:pentium dual core E6500

видео:NVIDIA GeForce GT 640

дънна платка:Gigabyte G41M-Combo

Рам:3 GB kingston

операционна система Windows 7 ultimate не располагам със дискът на windows.

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-01-2017
Ran by Niko (administrator) on NIKO-PC (20-01-2017 14:45:07)
Running from C:\Users\Niko\Desktop
Loaded Profiles: Niko (Available Profiles: Niko)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Αγγλικά (Ηνωμένων Πολιτειών)
Internet Explorer Version 10 (Default browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\ProgramData\Logic Handler\set.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe
(Copyright (C) 2016) C:\Users\Niko\AppData\Roaming\ibeib\UvConverter.exe
() C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe
() C:\Program Files (x86)\InterHop\InterHop.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\ProgramData\NetworkPacketManitor\Nettrans.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(TODO: <Company name>) C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\WinSaber\WinSaber.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() D:\Programs\OpenHardwareMonitor\OpenHardwareMonitor.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\...\MountPoints2: {39943681-0c59-11e3-88e4-94de8032cb43} - F:\autorun.exe
HKU\S-1-5-18\...\Run: [] => 0
IFEO\MRT.exe: [Debugger] C:\ProgramData\ficfi\Gubed.exe -Yrrehs
ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} => C:\Program Files (x86)\KuaiZip\X64\KZipShell.dll [2016-10-06] ()
GroupPolicy\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-3399182300-3254828621-142692518-1000] => hxxp://noblockingweb.net/wpad.dat?8b0eb9aff20e3d8fd3d1cb4b4f6f580a23130821
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{A9E20E9E-792A-4F68-89E1-1415384AFC8B}: [DhcpNameServer] 192.168.1.1 192.168.1.1
ManualProxies: 0hxxp://noblockingweb.net/wpad.dat?8b0eb9aff20e3d8fd3d1cb4b4f6f580a23130821

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/el-gr/?ocid=iehp
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
URLSearchHook: HKLM-x32 -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3399182300-3254828621-142692518-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=1483110200&z=d48e425f76393480ef60d70g4z5b6c2g8g7e1o0e5c&from=archer1028&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3399182300-3254828621-142692518-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=1483110200&z=d48e425f76393480ef60d70g4z5b6c2g8g7e1o0e5c&from=archer1028&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3399182300-3254828621-142692518-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-02] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-02] (Oracle Corporation)
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll [2013-05-21] ()
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL No File
StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.amisites.com/?type=sc&ts=1484911140&z=530d4ae64c14c0b45dd85a7g4z5baz2t3g7gfg9zaq&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1

FireFox:
========
FF DefaultProfile: edks5xtv.Προκαθορισμένος χρήστης
FF DefaultProfile: iwf25orn.default
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Profiles\iwf25orn.default [not found]
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default [2017-01-06]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\a25r7i00.default -> Ask Search
FF Homepage: Mozilla\Firefox\Profiles\a25r7i00.default -> hxxp://www.amisites.com/?type=hp&ts=1482955869&z=5614d51f004ae6def90ed2ag2zcb0oet1wew0b5mbg&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
FF SearchPlugin: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\searchplugins\amisites.xml [2016-11-09]
FF SearchPlugin: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\searchplugins\mylucky123.xml [2016-09-23]
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\et6305sn.default-1482858172314 [2017-01-05]
FF Homepage: Mozilla\Firefox\Profiles\et6305sn.default-1482858172314 -> hxxp://www.amisites.com/?type=hp&ts=1483453719&z=95dd8210a375af38020c13ag3z5b5c6zaw9cfm3oeg&from=archer1028&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης [2017-01-20]
FF Homepage: Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης -> www.google.gr
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Firefox\Firefox\Profiles\a25r7i00.default [2016-09-23]
FF DefaultSearchEngine: Firefox\Firefox\Profiles\a25r7i00.default -> Ask Search
FF Homepage: Firefox\Firefox\Profiles\a25r7i00.default -> hxxps://www.google.gr/
FF SearchPlugin: C:\Users\Niko\AppData\Roaming\Firefox\Firefox\Profiles\a25r7i00.default\searchplugins\mylucky123.xml [2016-09-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-18] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-18] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll [2012-03-29] ( Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-09-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3399182300-3254828621-142692518-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.amisites.com/?type=sc&ts=1484911140&z=530d4ae64c14c0b45dd85a7g4z5baz2t3g7gfg9zaq&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\71546286.js [2017-01-01] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\71546286.cfg [2017-01-01] <==== ATTENTION

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Archer; C:\Program Files (x86)\WinArcher\Archer.dll [417280 2017-01-19] () [File not signed]
R2 backlh; C:\ProgramData\Logic Handler\set.exe [3786752 2016-10-06] () [File not signed]
S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [445976 2016-10-21] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [425496 2016-10-21] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [466456 2016-10-21] (BlueStack Systems, Inc.)
S2 Coerwcultcntand.exe; C:\Program Files (x86)\Crecult\Coerwcultcntand.exe [415320 2016-08-19] ()
R2 Convxxxx; C:\Users\Niko\AppData\Roaming\ibeib\UvConverter.exe [396800 2016-12-26] (Copyright (C) 2016) [File not signed]
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [106160 2017-01-19] ()
R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [124416 2017-01-19] () [File not signed]
R2 Gubed_WMI; C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe [110080 2016-12-26] () [File not signed]
R2 InterHop; C:\Program Files (x86)\InterHop\InterHop.exe [486912 2016-10-31] () [File not signed]
R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [583680 2017-01-19] () [File not signed] <==== ATTENTION
R2 Kuaizip Update Checker; C:\Program Files (x86)\KuaiZip\X86\kuaizipUpdateChecker.dll [216704 2016-10-06] ()
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MSLN; C:\ProgramData\Microsoft\IdentityCRL\ppcrlconf.dll [501248 2017-01-18] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 Nettrans; C:\ProgramData\NetworkPacketManitor\Nettrans.exe [57856 2016-09-28] () [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 SoEasySvc; C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe [177304 2016-08-22] (TODO: <Company name>) <==== ATTENTION
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2009-07-14] (Microsoft Corporation) [DependOnService: iThemes5]<==== ATTENTION
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 winsaber; C:\Program Files (x86)\WinSaber\WinSaber.exe [877272 2016-10-08] ()
R2 WinSAPSvc; C:\ProgramData\WinSAPSvc\WinSAP.dll [485376 2017-01-20] () [File not signed]
S2 WinSnare; C:\Users\Niko\AppData\Roaming\WinSnare\WinSnare.dll [776192 2017-01-18] (InterSect Alliance Pty Ltd) [File not signed]
S2 ed2kidle; "C:\Program Files (x86)\amuleC\ed2k.exe" -downloadwhenidle [X] <==== ATTENTION

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [305920 2011-10-24] (AVEO)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-10-21] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-10-07] (Bluestack System Inc. )
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-24] (Disc Soft Ltd)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
R2 KuaiZipDrive2; C:\Windows\system32\drivers\KuaiZipDrive2.sys [93072 2016-10-06] (WinMount International Inc) <==== ATTENTION
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-01-20] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
R3 WinRing0_1_2_0; \??\D:\Programs\OpenHardwareMonitor\OpenHardwareMonitor.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-20 14:45 - 2017-01-20 14:45 - 00020800 _____ C:\Users\Niko\Desktop\FRST.txt
2017-01-20 14:44 - 2017-01-20 14:45 - 00000000 ____D C:\FRST
2017-01-20 14:44 - 2017-01-20 14:44 - 02419712 _____ (Farbar) C:\Users\Niko\Desktop\FRST64.exe
2017-01-20 14:20 - 2017-01-20 14:20 - 00003136 _____ C:\Windows\System32\Tasks\{F6FB8D9F-8D03-4028-8AFD-441580394D90}
2017-01-20 14:17 - 2017-01-20 14:21 - 00000000 ____D C:\Program Files\Trojan Killer
2017-01-20 14:17 - 2017-01-20 14:17 - 00000952 _____ C:\Users\Niko\Desktop\Trojan Killer.lnk
2017-01-20 14:16 - 2017-01-20 14:16 - 01811408 _____ (GridinSoft LLC) C:\Users\Niko\Downloads\TrojanKiller-Setup.exe
2017-01-19 17:21 - 2017-01-19 17:21 - 00003558 _____ C:\Windows\System32\Tasks\Milimili
2017-01-19 17:21 - 2017-01-19 17:21 - 00000000 ____D C:\Program Files (x86)\MIO
2017-01-19 14:23 - 2017-01-19 19:24 - 00000040 _____ C:\Program Files (x86)\settings.dat
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 ____D C:\Users\Niko\AppData\Local\Applefat
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 ____D C:\Program Files (x86)\reports
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 _____ C:\Program Files (x86)\metadata
2017-01-19 14:22 - 2017-01-19 14:22 - 00000000 ____D C:\Program Files (x86)\Firefox
2017-01-19 14:21 - 2017-01-19 14:21 - 00000019 _____ C:\Users\Public\Documents\cc.ini
2017-01-18 16:47 - 2017-01-19 14:21 - 00002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-18 16:47 - 2017-01-19 14:21 - 00002372 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-01-18 16:46 - 2017-01-18 16:46 - 00000000 ____D C:\Program Files (x86)\Applefat
2017-01-18 15:49 - 2017-01-18 15:49 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.0.6)
2017-01-16 14:02 - 2009-10-15 09:44 - 00809560 ____R (Creative Labs Inc.) C:\Windows\SysWOW64\tmp9676.tmp
2017-01-13 19:14 - 2017-01-13 19:15 - 50557072 _____ C:\Users\Niko\Downloads\mame0181b_64bit.exe
2017-01-12 15:08 - 2017-01-18 14:46 - 00003638 _____ C:\Windows\System32\Tasks\WinTOOL
2017-01-12 15:08 - 2017-01-18 14:46 - 00000000 ____D C:\ProgramData\wintools
2017-01-09 13:53 - 2017-01-09 13:53 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-01-09 12:45 - 2017-01-18 15:50 - 00000000 ____D C:\Users\Niko\AppData\Roaming\WinSnare
2017-01-09 12:45 - 2017-01-09 12:45 - 00000000 ____D C:\Program Files (x86)\rf4derqf
2017-01-07 21:29 - 2017-01-07 21:29 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Frogwares
2017-01-07 21:28 - 2017-01-07 21:28 - 00000838 _____ C:\Users\Public\Desktop\The Testament of Sherlock Holmes.lnk
2017-01-07 21:28 - 2017-01-07 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus Home Interactive
2017-01-06 15:55 - 2017-01-20 13:18 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-06 15:51 - 2017-01-06 15:51 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2017-01-06 15:51 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2017-01-06 15:51 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-01-06 15:51 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-01-05 17:03 - 2017-01-05 17:20 - 00000000 ____D C:\ProgramData\NFS Underground
2017-01-05 17:02 - 2017-01-05 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7
2017-01-03 15:59 - 2017-01-19 14:22 - 00002285 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-01-02 22:10 - 2017-01-02 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2017-01-02 21:41 - 2017-01-02 21:41 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003778 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003766 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003590 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003530 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-01-02 21:41 - 2016-12-12 04:37 - 01854400 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01452480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2017-01-02 21:40 - 2017-01-02 21:40 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-02 21:40 - 2016-12-12 04:37 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-01-02 21:40 - 2016-12-11 20:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-01-02 21:40 - 2016-09-09 20:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-01-02 21:40 - 2016-09-09 20:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2017-01-02 21:40 - 2016-09-09 20:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-01-02 21:40 - 2016-09-09 20:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2017-01-02 21:37 - 2016-12-12 04:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 17436808 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03479744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00491536 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00212936 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00101824 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00091584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-01-02 21:37 - 2016-12-12 04:37 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2017-01-02 21:31 - 2017-01-02 21:31 - 00000000 ____D C:\Windows\Sun
2017-01-01 22:47 - 2017-01-01 22:47 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Easeware
2016-12-29 13:28 - 2017-01-01 22:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-29 13:28 - 2016-12-29 13:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-27 14:24 - 2016-12-27 14:24 - 00000000 ____D C:\Program Files (x86)\mtdh7czn
2016-12-27 14:22 - 2016-12-27 14:22 - 00000000 ____D C:\Program Files (x86)\Gubed
2016-12-26 14:54 - 2016-12-26 14:54 - 00000000 ____D C:\Users\Niko\AppData\Roaming\ibeib
2016-12-26 14:54 - 2016-12-26 14:54 - 00000000 ____D C:\ProgramData\cficf
2016-12-23 15:03 - 2016-12-26 14:54 - 00000000 ____D C:\Program Files (x86)\Gubed_WMI

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-20 14:44 - 2016-10-06 20:58 - 00000454 _____ C:\Windows\Tasks\UCBrowserUpdater.job
2017-01-20 14:30 - 2016-09-29 01:38 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-01-20 14:21 - 2016-11-24 10:40 - 00000000 ____D C:\Users\Niko\AppData\LocalLow\Mozilla
2017-01-20 14:11 - 2013-08-24 03:47 - 00000000 ____D C:\Users\Niko\AppData\Roaming\uTorrent
2017-01-20 13:34 - 2014-11-04 23:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-01-20 13:25 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-20 13:25 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-20 13:24 - 2015-01-25 06:54 - 04022766 _____ C:\Windows\system32\perfh008.dat
2017-01-20 13:24 - 2015-01-25 06:54 - 01264870 _____ C:\Windows\system32\perfc008.dat
2017-01-20 13:24 - 2009-07-14 07:13 - 00006208 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-20 13:18 - 2016-10-25 15:20 - 00000000 ____D C:\ProgramData\WinSAPSvc
2017-01-20 13:18 - 2016-09-29 01:38 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-01-20 13:18 - 2013-08-23 18:50 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-20 13:18 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-19 14:23 - 2014-01-21 14:42 - 00000000 ____D C:\Users\Niko\AppData\Local\Google
2017-01-19 14:22 - 2016-09-29 01:39 - 00002289 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-01-19 14:20 - 2016-08-22 02:44 - 00000000 ____D C:\Program Files (x86)\Crecult
2017-01-18 14:45 - 2016-10-26 18:48 - 00000000 ____D C:\Program Files (x86)\WinArcher
2017-01-16 18:21 - 2016-02-19 08:41 - 00000000 ____D C:\Users\Niko\AppData\Local\CrashDumps
2017-01-16 14:03 - 2013-09-03 05:16 - 00000000 ____D C:\ProgramData\Codemasters
2017-01-16 14:02 - 2013-12-28 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
2017-01-16 14:02 - 2013-12-28 23:20 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00122968 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2017-01-16 14:02 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-01-16 13:52 - 2013-08-24 03:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-01-10 22:54 - 2016-02-02 23:43 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-10 22:52 - 2015-03-23 06:57 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-09 13:53 - 2016-10-11 11:45 - 00000000 ____D C:\Users\Niko\AppData\Roaming\aMule
2017-01-07 21:30 - 2013-10-17 17:02 - 00000000 ____D C:\Users\Niko\AppData\Roaming\NVIDIA
2017-01-06 15:51 - 2016-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-01-06 15:51 - 2014-04-10 04:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-01-02 22:15 - 2014-04-25 21:36 - 00000000 ____D C:\Users\Niko\Documents\NFS Carbon
2017-01-02 21:44 - 2014-01-20 06:31 - 00000000 ____D C:\Users\Niko\AppData\Local\NVIDIA Corporation
2017-01-02 21:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-01-02 21:42 - 2013-08-23 18:50 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-02 21:41 - 2013-08-23 18:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-02 21:41 - 2013-08-23 18:49 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-02 21:29 - 2013-08-24 03:06 - 00059144 _____ C:\Users\Niko\AppData\Local\GDIPFONTCACHEV1.DAT
2017-01-02 21:28 - 2009-07-14 06:45 - 04893920 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-02 21:26 - 2016-04-15 00:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2017-01-02 21:26 - 2014-02-18 15:20 - 00000000 ____D C:\ProgramData\HP
2017-01-02 21:16 - 2013-08-23 18:55 - 00000000 ____D C:\Users\Niko\AppData\Local\NVIDIA
2017-01-02 20:39 - 2016-02-18 07:59 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-02 00:50 - 2014-07-24 20:30 - 00000000 ____D C:\Users\Niko\Documents\NFS Most Wanted
2016-12-31 20:36 - 2013-09-02 05:37 - 00000000 ____D C:\Users\Niko\AppData\Roaming\BSplayer Pro
2016-12-27 19:03 - 2016-08-22 02:47 - 00000000 ____D C:\Users\Niko\AppData\Local\Profiles
2016-12-27 19:03 - 2016-08-22 02:44 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Profiles
2016-12-26 14:55 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\ttff
2016-12-26 14:55 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\QQBrowser

==================== Files in the root of some directories =======

2017-01-19 14:23 - 2017-01-19 14:23 - 0000000 _____ () C:\Program Files (x86)\metadata
2017-01-19 14:23 - 2017-01-19 19:24 - 0000040 _____ () C:\Program Files (x86)\settings.dat
2016-10-06 20:55 - 2016-10-06 20:55 - 7176704 _____ () C:\Users\Niko\AppData\Roaming\agent.dat
2016-10-06 20:55 - 2016-10-06 20:55 - 0070704 _____ () C:\Users\Niko\AppData\Roaming\Config.xml
2016-10-06 20:54 - 2016-10-06 20:54 - 0015792 _____ () C:\Users\Niko\AppData\Roaming\InstallationConfiguration.xml
2016-10-06 20:54 - 2016-10-06 20:54 - 0140288 _____ () C:\Users\Niko\AppData\Roaming\Installer.dat
2016-10-06 20:55 - 2016-10-06 20:55 - 0018432 _____ () C:\Users\Niko\AppData\Roaming\Main.dat
2016-10-06 20:55 - 2016-10-06 20:55 - 0005568 _____ () C:\Users\Niko\AppData\Roaming\md.xml
2016-10-06 20:55 - 2016-10-06 20:55 - 0126464 _____ () C:\Users\Niko\AppData\Roaming\noah.dat
2016-10-06 20:54 - 2016-10-06 20:54 - 0190394 _____ () C:\Users\Niko\AppData\Roaming\Relex.bin
2016-10-06 20:55 - 2016-10-06 20:55 - 1897576 _____ () C:\Users\Niko\AppData\Roaming\Tres-Fax.bin
2016-10-06 20:55 - 2016-10-06 20:54 - 0693760 _____ () C:\Users\Niko\AppData\Roaming\Tresfan.exe
2016-10-06 20:55 - 2016-10-06 20:55 - 1927967 _____ () C:\Users\Niko\AppData\Roaming\Tresfan.tst
2016-10-06 20:55 - 2016-10-06 20:55 - 0032038 _____ () C:\Users\Niko\AppData\Roaming\uninstall_temp.ico
2014-01-27 14:18 - 2014-01-27 14:18 - 0003584 _____ () C:\Users\Niko\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-09 23:48 - 2016-03-09 23:48 - 0000000 _____ () C:\Users\Niko\AppData\Local\{17E571E6-9009-4609-B1E3-75C6FB68244D}
2014-07-12 18:23 - 2014-07-12 18:23 - 0000000 _____ () C:\Users\Niko\AppData\Local\{46DE8AB8-CF21-4A09-B2D9-AA70260696B5}
2014-02-18 15:20 - 2017-01-02 21:27 - 0014081 _____ () C:\ProgramData\hpzinstall.log
2015-11-19 08:17 - 2015-11-19 08:17 - 0000040 _____ () C:\ProgramData\ra3.ini
2016-08-22 02:45 - 2016-08-22 02:45 - 0000186 _____ () C:\ProgramData\Mozilla Firefox.lnk.bat

Files to move or delete:
====================
C:\ProgramData\Mozilla Firefox.lnk.bat


Some files in TEMP:
====================
C:\Users\Niko\AppData\Local\Temp\121D.tmp.exe
C:\Users\Niko\AppData\Local\Temp\1998.tmp.exe
C:\Users\Niko\AppData\Local\Temp\2186.tmp.exe
C:\Users\Niko\AppData\Local\Temp\3220.tmp.exe
C:\Users\Niko\AppData\Local\Temp\32B5.tmp.exe
C:\Users\Niko\AppData\Local\Temp\696D.tmp.exe
C:\Users\Niko\AppData\Local\Temp\6_Offer_4.exe
C:\Users\Niko\AppData\Local\Temp\7za.exe
C:\Users\Niko\AppData\Local\Temp\81B.tmp.exe
C:\Users\Niko\AppData\Local\Temp\8A21.tmp.exe
C:\Users\Niko\AppData\Local\Temp\8QkzPQzqFM.exe
C:\Users\Niko\AppData\Local\Temp\AutoRun.exe
C:\Users\Niko\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Niko\AppData\Local\Temp\binkw32.dll
C:\Users\Niko\AppData\Local\Temp\BluestacksUninstaller.exe
C:\Users\Niko\AppData\Local\Temp\Browser_V5.6.14087.902_f_4674_(Build1608021049).exe
C:\Users\Niko\AppData\Local\Temp\CmdLineExt03.dll
C:\Users\Niko\AppData\Local\Temp\D09D.tmp.exe
C:\Users\Niko\AppData\Local\Temp\D2C1.tmp.exe
C:\Users\Niko\AppData\Local\Temp\d2l_Install.exe
C:\Users\Niko\AppData\Local\Temp\d2l_PlayD2.exe
C:\Users\Niko\AppData\Local\Temp\E060.tmp.exe
C:\Users\Niko\AppData\Local\Temp\EAInstall.dll
C:\Users\Niko\AppData\Local\Temp\eauninstall.exe
C:\Users\Niko\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Niko\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Niko\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe
C:\Users\Niko\AppData\Local\Temp\fsdE7CF.exe
C:\Users\Niko\AppData\Local\Temp\HD-LibraryHandler.dll
C:\Users\Niko\AppData\Local\Temp\HD-Logger-Native.dll
C:\Users\Niko\AppData\Local\Temp\htmlayout.dll
C:\Users\Niko\AppData\Local\Temp\ICReinstall_8A21.tmp.exe
C:\Users\Niko\AppData\Local\Temp\ins6068.tmp.exe
C:\Users\Niko\AppData\Local\Temp\inst12.exe
C:\Users\Niko\AppData\Local\Temp\iv_uninstall.exe
C:\Users\Niko\AppData\Local\Temp\kernel32.dll
C:\Users\Niko\AppData\Local\Temp\KuaiZip.exe
C:\Users\Niko\AppData\Local\Temp\libeay32.dll
C:\Users\Niko\AppData\Local\Temp\msvcr120.dll
C:\Users\Niko\AppData\Local\Temp\Need for Speed Most Wanted_uninst.exe
C:\Users\Niko\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\Niko\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Niko\AppData\Local\Temp\nvStInst.exe
C:\Users\Niko\AppData\Local\Temp\nvstlink.exe
C:\Users\Niko\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Niko\AppData\Local\Temp\patchw32.dll
C:\Users\Niko\AppData\Local\Temp\sdf152E.exe
C:\Users\Niko\AppData\Local\Temp\setup.exe
C:\Users\Niko\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Niko\AppData\Local\Temp\SoHuVA_4.2.0.16-c20762-ng-nti-s-tp-x.exe
C:\Users\Niko\AppData\Local\Temp\speed.exe
C:\Users\Niko\AppData\Local\Temp\sqlite3.dll
C:\Users\Niko\AppData\Local\Temp\tmd_34012506.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34013739.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34014067.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34014502.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34016590.exe
C:\Users\Niko\AppData\Local\Temp\tmp17ED.exe
C:\Users\Niko\AppData\Local\Temp\Uninstall.exe
C:\Users\Niko\AppData\Local\Temp\uninstall13306027.exe
C:\Users\Niko\AppData\Local\Temp\Utils.dll
C:\Users\Niko\AppData\Local\Temp\_is44EB.exe
C:\Users\Niko\AppData\Local\Temp\_is84A9.exe
C:\Users\Niko\AppData\Local\Temp\_isC1F7.exe
C:\Users\Niko\AppData\Local\Temp\_isEAAC.exe
C:\Users\Niko\AppData\Local\Temp\~ct2EF0.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct4D55.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct4F87.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct5C53.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct697C.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct932.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct959B.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctA85C.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctAB3D.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctAC56.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctB654.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctBA5A.tmp.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-13 00:58

==================== End of FRST.txt ============================

следвах инструкциите за добавяне на тема надявам се че не съм допусна грешка със добавянето на темата или не съм испуснал нещо да добавя ако е така моля да ме извините.

БЛАГОДАРЯ

Addition.txt

Здравейте..! :) Системата ви е заразена...! Да започнем: така:

 

Изтеглете програмата GeekUninstaller и я запазете на десктопа.
Разархивирайте я и стартирайте файла geek.exe IxXO5oO.jpg  От списъка намерете и деинсталирайте всички програми които съм ви написал в карето:

Цитат

amuleC 
amuleC 

WinSnare 

Кликнете с десен бутон върху програмата и изберете Uninstall
 
XhV2QLa.png
 
 
След края на всяка деинсталацията ще се отвори прозорец подканващ ви да премахнете всички остатъци от програмата (ако има такива, ако няма този прозорец няма да се появи).Натиснете бутона Finish за да изтриете останките от програмата.

 

GfiJrQ9.png Malwarebytes Anti-Malware (MBAM)

Моля, изтеглете Malwarebytes Anti-Malware 2.2.0.1024 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-bc.хххх-х.х.х.хххх.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката. Т.е. премахнете първата отметка:

DkgJ7Zr.png

  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категориятаDetection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.

65ZBqkR.jpg

  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинацияCtrl + V и го публикувайте в следващия си коментар.

 

BY4dvz9.png Сканиране с AdwCleaner

 
Моля, изтеглете и стартирайте програмата Malwarebytes AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте A49sxPr.pngScan (провери).
  • След завършване, кликнете на 6cyn5v5.pngLogfile (дневник).Ще се отвори прозорец в който се намира дневника (AdwCleaner [S0] .txt).Кликнете два пъти върх реда и ще се отвори съдържанието на дневника.Публикувайте го в следващия си пост
  • Върнете се към основния прозорец на AdwCleaner .маркирайте MqHawIb.pngClean (Почисти)
  • Следвайте указанията и разрешете на компютъра да се рестартира.
  • След рестарта ще се отвори дневник AdwCleaner[C0].txt . Моля копирайте съдържанието на лог файла в следващия си пост.

 

 

E3feWj5.png  Сканиране с Junkware Removal Tool
 
Моля, изтеглете Junkware Removal Tool (by Thisisu ) и запазете на вашия десктоп.

  • Спрете временно работата на защитните програми.
  • Стартирайте инструмента JRT.exe
  • Ще се отвори ДОС прозорец. Натиснете което и да е копче от клавиатурата.
  • Затворете излишните приложения и всички браузъри и изчакайте проверката да завърши.
  • Ще се появи лог файл (който можете да намерите и ръчно на десктопа с името JRT.txt).
  • Моля копирайте съдържанието на лог файла в следващия си пост.

 

122.jpg?1414578932  Моля, изтеглете  Check Browsers' LNK by Dragokas & regist

  • Запомнете архива на вашия декстоп,разархивирате.
  • Временно спрете вашия  антивирусен софтуер.
  • Стартирайте файла Check Browsers LNK.exe от името на администратор.
  • Изчакайте програмата да завърши работата си.Това може да отнеме до 5 минути. Моля бъдете търпеливи. След сканирането, отворете генерираната папка LOG и публикувайте отчета Check_Browsers_LNK.log, в следвашия си пост.

 

 Дневници
 
В следващия си отговор, моля да включите (като копирате целите съдържания ) следните дневници:

  • Дневник от Malwarebytes Anti -Malware
  • AdwCleaner.txt
  • JRT.txt
  • Check_Browsers_LNK.log

 

 

  • Автор

Здравейте отново завърших всичко от постът по горе единствено не успя да завърши ADV cleaner след като го стартирах откри 137 заплахи след натискане на бутонът почистване компютърът забива исключих го пренудително пак пуснах програмата отново откри 137 заплахи и отново след натискане на бутона почистване заби оставх го час и половина и нямаше промяна.

Ето останалите файлове:

Malwarebytes:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 20/1/2017
Scan Time: 4:26 μμ
Logfile:
Administrator: Yes

Version: 2.2.0.1024
Malware Database: v2017.01.20.05
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Niko

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 305885
Time Elapsed: 25 min, 22 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 12
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe, 592, Delete-on-Reboot, [53d26519c2e6de58ac3deaae23de9f61]
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe, 1124, Delete-on-Reboot, [879ed7a7891f96a0e2072375669bf10f]
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\set.exe, 2132, Delete-on-Reboot, [4bda55295355ba7c83e155c5748dca36]
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe, 2572, Delete-on-Reboot, [64c1f08edfc914224b9e7622dd246898]
Adware.Elex, C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe, 2864, Delete-on-Reboot, [66bf6a14b1f7d660770d5f80a25e7090]
PUP.Optional.Linkury, C:\ProgramData\NetworkPacketManitor\Nettrans.exe, 2372, Delete-on-Reboot, [e34248363078d16566b4dd8a7f81fa06]
PUP.Optional.Elex, C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe, 492, Delete-on-Reboot, [2203acd26642082e252bef4b1ae69f61]
PUP.Optional.Elex, C:\Program Files (x86)\WinSaber\WinSaber.exe, 3180, Delete-on-Reboot, [bd6808769018b5816c39d384768a12ee]
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe, 5012, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7]
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\Firefox.exe, 4940, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7]
PUP.Optional.Interhop, C:\Program Files (x86)\InterHop\InterHop.exe, 3044, Delete-on-Reboot, [f0353549d1d7e94da7d5c19a2bd55fa1]
Adware.Elex.Generic, C:\Users\Niko\AppData\Roaming\gjdgj\UvConverter.exe, 2532, Delete-on-Reboot, [1c09a4da4365c5710d4b01c015ebb050]

Modules: 94
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll, Delete-on-Reboot, [8a9bceb033755fd75693cdcb6b96a65a],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll, Delete-on-Reboot, [13125a24dfc9af870fda5e3a5ba6857b],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll, Delete-on-Reboot, [13125a24dfc9af870fda5e3a5ba6857b],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll, Delete-on-Reboot, [13125a24dfc9af870fda5e3a5ba6857b],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll, Delete-on-Reboot, [df461d61525692a4a3460c8c11f018e8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll, Delete-on-Reboot, [df461d61525692a4a3460c8c11f018e8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll, Delete-on-Reboot, [df461d61525692a4a3460c8c11f018e8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll, Delete-on-Reboot, [4bdafe8071371323c2279404de23d828],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll, Delete-on-Reboot, [978e5727d3d53cfadd0cd4c47c85b848],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll, Delete-on-Reboot, [978e5727d3d53cfadd0cd4c47c85b848],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll, Delete-on-Reboot, [978e5727d3d53cfadd0cd4c47c85b848],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll, Delete-on-Reboot, [869fc8b62682261057922177c8393ac6],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll, Delete-on-Reboot, [869fc8b62682261057922177c8393ac6],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll, Delete-on-Reboot, [869fc8b62682261057922177c8393ac6],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll, Delete-on-Reboot, [7aab5925fbad2e08a54422760df4c13f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll, Delete-on-Reboot, [7aab5925fbad2e08a54422760df4c13f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll, Delete-on-Reboot, [9590b2cc3b6da69075749dfbe819847c],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll, Delete-on-Reboot, [1a0bd1ad891fe0564a9f217752afe020],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafebs.dll, Delete-on-Reboot, [b86d3e409c0c1422a2478216818040c0],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll, Delete-on-Reboot, [2afbfa84f9afad899950296f9e6302fe],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll, Delete-on-Reboot, [1411700edcccba7c1bce2b6d926f28d8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll, Delete-on-Reboot, [3ce9542a8721ed4977724e4adc2531cf],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll, Delete-on-Reboot, [27fedf9fd9cf40f631b88612df2208f8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll, Delete-on-Reboot, [6bba0a742c7c94a230b91583cb36bb45],
Adware.Elex, C:\Program Files (x86)\Common Files\Services\iThemes.dll, Delete-on-Reboot, [b471621c674178be3250d1cedf21f10f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafebase.dll, Delete-on-Reboot, [58cd2b533d6bcc6a3baebddbc04108f8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll, Delete-on-Reboot, [a67f631b9315cc6ad2178a0ec63b09f7],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll, Delete-on-Reboot, [77aed8a60c9cac8a2bbe9305f30ebb45],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTpNodisturb.dll, Delete-on-Reboot, [df469fdfa00852e4dd0c237535ccc43c],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll, Delete-on-Reboot, [d64fb5c9b3f52d0907e2aeea71902ad6],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll, Delete-on-Reboot, [fb2a2b53f1b7102663864e4a23ded927],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll, Delete-on-Reboot, [e243f48afcac56e05198dbbdcf324bb5],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll, Delete-on-Reboot, [80a5d4aaf3b5b2846683eeaaaa5726da],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll, Delete-on-Reboot, [ac79b3cb9810b18573763662ca375ea2],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPAutoClean.dll, Delete-on-Reboot, [ae77304ed9cfd066e8010d8b18e9e21e],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-file-l1-2-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-file-l2-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-localization-l1-2-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-processthreads-l1-1-1.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-synch-l1-2-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-timezone-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-convert-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-environment-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-filesystem-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-heap-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-locale-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-multibyte-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-runtime-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-stdio-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-string-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-time-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-utility-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-math-l1-1-0.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\lgpllibs.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\freebl3.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\mozavcodec.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\mozavutil.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\mozglue.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\msvcp140.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nss3.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nssckbi.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nssdbm3.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\softokn3.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\ucrtbase.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\vcruntime140.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\xul.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\components\browsercomps.dll, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\kuaizipUpdateChecker.dll, Delete-on-Reboot, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Elex, C:\Program Files (x86)\WinArcher\Archer.dll, Delete-on-Reboot, [27fef18d3078fb3b210e92e06f917090],
PUP.Optional.Elex, C:\ProgramData\WinSAPSvc\WinSAP.dll, Delete-on-Reboot, [6db86519d8d061d53e57de9b03fda15f],
Adware.Elex, C:\Program Files (x86)\Gubed\GubedZL.dll, Delete-on-Reboot, [4ed7ed9146625cdaca258457bd43c13f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libeay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libeay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libeay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libpng.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcp110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcp110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcp110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcr110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcr110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcr110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ouilibx.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ssleay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ssleay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ssleay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],

Registry Keys: 355
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeService, Delete-on-Reboot, [53d26519c2e6de58ac3deaae23de9f61],
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iThemes5, Quarantined, [b471621c674178be3250d1cedf21f10f],
PUP.Optional.LogicHandler, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\backlh, Quarantined, [4bda55295355ba7c83e155c5748dca36],
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Gubed_WMI, Quarantined, [66bf6a14b1f7d660770d5f80a25e7090],
PUP.Optional.Linkury, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Nettrans, Quarantined, [e34248363078d16566b4dd8a7f81fa06],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SoEasySvc, Quarantined, [2203acd26642082e252bef4b1ae69f61],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\winsaber, Quarantined, [bd6808769018b5816c39d384768a12ee],
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnlKit, Delete-on-Reboot, [39ecdf9f8f19fe3897528612778a6d93],
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnlR3, Delete-on-Reboot, [59cc92ec347480b69e4b5543e21faa56],
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnl, Delete-on-Reboot, [2bfa4d3101a7280eba2f613751b00cf4],
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnlMon, Quarantined, [49dc136b01a7231313d6a6f2738e9b65],
PUP.Optional.Elex.SHHKRST, HKLM\SOFTWARE\CLASSES\CLSID\{6710C780-E20E-4C49-A87D-321850ED3D7C}, Quarantined, [65c0e6984a5e1125956334e3a15f6c94],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F3}, Quarantined, [1c09215da8008fa7c5ea9d0534cc05fb],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.KzShlobj, Quarantined, [9e875925bfe95adc0fa0bee4d42c3dc3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.KzShlobj.1, Quarantined, [be67fb83abfded490ca3d6ccf10f956b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.KzShlobj, Quarantined, [29fc81fd48600531b5faadf5a95759a7],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.KzShlobj.1, Quarantined, [79aca2dcd1d771c51f9049595fa13ac6],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.KzShlobj, Quarantined, [29fc35490f99e551129dc2e0ee128c74],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.KzShlobj.1, Quarantined, [f62fcdb1555338fe9718831fb050d927],
PUP.Optional.Ghokswa, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\FirefoxU, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\CLSID\{3DCCD550-7586-40D2-A51D-D2F98EC06B3D}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\TYPELIB\{86C4C3BA-4EA4-4CF8-98B9-6B07B477B836}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\INTERFACE\{2DA6D0F1-13A1-4EC7-BD41-49A545AD326F}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2DA6D0F1-13A1-4EC7-BD41-49A545AD326F}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{2DA6D0F1-13A1-4EC7-BD41-49A545AD326F}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{86C4C3BA-4EA4-4CF8-98B9-6B07B477B836}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{86C4C3BA-4EA4-4CF8-98B9-6B07B477B836}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.DragDropMenu.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.DragDropMenu, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.DragDropMenu, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.DragDropMenu, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.DragDropMenu.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.DragDropMenu.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\CLSID\{6ADF19E3-77A3-4395-ADB4-9FD7D351EB3F}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.ContextMenuExt.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.ContextMenuExt, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.ContextMenuExt, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.ContextMenuExt, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.ContextMenuExt.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.ContextMenuExt.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\CLSID\{C9487131-EF4C-40D9-BA70-E85356CAF67F}, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.KYDropHandler.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\QZipShell2.KYDropHandler, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.KYDropHandler, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.KYDropHandler, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\QZipShell2.KYDropHandler.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\WOW6432NODE\QZipShell2.KYDropHandler.1, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\KuaiZipDrive2, Quarantined, [31f46816baee22142cb9e4764bb55ba5],
PUP.Optional.Interhop, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\InterHop, Quarantined, [f0353549d1d7e94da7d5c19a2bd55fa1],
Adware.Elex.Generic, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Convxxxx, Quarantined, [1c09a4da4365c5710d4b01c015ebb050],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.001, Quarantined, [ac7917671f8903330ad4d5d2ec1441bf],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.002, Quarantined, [f62f295548608fa72ab482259f61fd03],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.003, Quarantined, [50d55d210a9e92a413cbb9eef30d07f9],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.004, Quarantined, [65c01f5f6a3e0c2a736b4265a95713ed],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.005, Quarantined, [8b9a99e55d4b60d634aa04a35ba5e020],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.006, Quarantined, [d055fe80dace1323e1fdd7d06d9338c8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.007, Quarantined, [a67f502e4068f145726ca8fff60ad729],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.008, Quarantined, [ed387e00ccdc91a520bed0d78b756997],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.009, Quarantined, [ef3693ebc9dffb3b7e601691e51b9070],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.01, Quarantined, [10154836228675c107d700a797697888],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.010, Quarantined, [bd68b4caa50357df8e50ced91be502fe],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.011, Quarantined, [40e5dba33d6b0234924cb7f0c040df21],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.012, Quarantined, [c85db5c903a5c670e0fe11967f81e31d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.013, Quarantined, [84a1334bd8d089ad479756512dd30ef2],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.014, Quarantined, [74b15f1f5355bd79a43a05a2a55b6898],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.015, Quarantined, [56cfc5b956524fe7647a5f48956b7d83],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.016, Quarantined, [bf66bbc3e7c18fa71cc27631c9372bd5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.017, Quarantined, [69bcfd81e9bfe15596481d8ad22ebe42],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.018, Quarantined, [0520f688a701cb6b429c7a2dce32837d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.019, Quarantined, [f92cd7a708a090a614ca01a6629e2ed2],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.02, Quarantined, [fc29314de1c7360069758a1d03fd5ba5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.020, Quarantined, [ba6b6816a800e94db32b3b6ccf31e41c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.021, Quarantined, [d84d3a44dfc9d264e4fa921554ace719],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.022, Quarantined, [59ccafcf0c9c2e08fee0921514eceb15],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.023, Quarantined, [44e1e89635730f274b936146a15fc739],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.024, Quarantined, [170eacd2a3051a1ceef06443b84828d8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.025, Quarantined, [72b3fc824365b1856b73fcabb64ade22],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.026, Quarantined, [bc69235b75337eb8a7371a8de719857b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.027, Quarantined, [a97cd8a6129645f16f6ff1b68f71fe02],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.028, Quarantined, [ae77b4ca2880ce6898465e49f10f728e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.029, Quarantined, [b570acd24e5abf77c01e9e0947b9d828],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.03, Quarantined, [ff26fe805256dd59b42ad2d54bb5fb05],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.030, Quarantined, [1a0b7905aefa16200dd1aef929d714ec],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.031, Quarantined, [1f061c6202a62a0cd707f1b6b34daf51],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.032, Quarantined, [ed38f9853f695ed82ab4693e8779b54b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.033, Quarantined, [e93c0a744167989ed806c9de11ef55ab],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.034, Quarantined, [a5806c123a6ed462de00d9ce966a649c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.035, Quarantined, [63c2d5a99c0c6acce7f73d6a9868f709],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.036, Quarantined, [81a4037b852369cd39a52d7a04fc23dd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.037, Quarantined, [a58081fd9612eb4b6b73881f8b75857b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.038, Quarantined, [a184a4da208805319747d4d309f7659b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.039, Quarantined, [62c3bac4604879bdeef0c0e734ccac54],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.04, Quarantined, [ac79641a6d3bc76f2cb2b6f1cd33b14f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.040, Quarantined, [071ed4aafaae85b1ad31fdaae818d32d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.041, Quarantined, [968fe29c792f0333e0fe8c1bdf219f61],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.042, Quarantined, [c16480fee6c2b87e33ab07a06b9515eb],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.043, Quarantined, [58cd6915b0f8c274805e891ef10fdb25],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.044, Quarantined, [1114f589f2b655e1e5f9c3e4ad53ba46],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.045, Quarantined, [f82d67174365fe38617dced9c23efb05],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.046, Quarantined, [eb3a384614942610e7f7b4f3b64a916f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.047, Quarantined, [9d8877070b9d280e20be81261fe148b8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.048, Quarantined, [9a8bbdc1238573c339a57532a858b14f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.049, Quarantined, [62c3bdc11a8ebf77d707396e24dc8b75],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.05, Quarantined, [a97cc5b9495f2d093aa45a4de11f1de3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.050, Quarantined, [41e485f908a08bab9d41d1d65ea2c13f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.051, Quarantined, [51d41d611395cb6b538b7b2cd030857b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.052, Quarantined, [b76ea3db3177f93d6a74b0f7c33d32ce],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.053, Quarantined, [cc59e49a198fc37357879710c739e818],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.054, Quarantined, [c65f3945acfc78be28b6238427d99868],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.055, Quarantined, [83a2acd24c5c102635a9fcab9c6417e9],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.056, Quarantined, [2ef7bfbf6147290d904ed7d0a25e619f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.057, Quarantined, [091cdaa48523da5ce6f83374867a1be5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.058, Quarantined, [57cefc823d6bb38322bc2186748caa56],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.059, Quarantined, [9d883f3f6d3bdb5b7e6085229f6151af],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.06, Quarantined, [3de848364266bc7ac01ee9bebb45ee12],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.060, Quarantined, [e144c6b83078b18501dd3c6b58a85da3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.061, Quarantined, [64c17c02b9ef40f6d905e0c714ec867a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.062, Quarantined, [39ec037b1b8d65d108d6d6d1ba469769],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.063, Quarantined, [44e15a24a1074beb00deebbcaf515fa1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.064, Quarantined, [c362d4aaedbb46f0548a1a8d847c9c64],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.065, Quarantined, [48dd027c495fea4c34aaa10636ca20e0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.066, Quarantined, [cf560e704d5b73c346982087d72936ca],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.067, Quarantined, [d64f433b872154e224ba5453718f16ea],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.068, Quarantined, [42e393eba1071b1baa344166b7498779],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.069, Quarantined, [52d3631bb2f677bfe5f98126bb45a55b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.07, Quarantined, [c263f9855e4a59ddfce21790f20e936d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.070, Quarantined, [b075433b5a4ee94dc915efb8946c23dd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.071, Quarantined, [71b4cab47038ef4716c85c4b7e82b64a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.072, Quarantined, [8e9768166c3cf244b628802743bdd12f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.073, Quarantined, [78adb5c9c6e22a0cce10d0d7e51b7b85],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.074, Quarantined, [af7679055553171f0fcf50577987c739],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.075, Quarantined, [3de8c6b8b4f449ed13cbb1f6c53baf51],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.076, Quarantined, [5dc8bec0aafe76c014ca00a7a35dca36],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.077, Quarantined, [9392a9d5684010262fafcbdc14eca858],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.078, Quarantined, [c2631965d5d3d066c717891ed12ff60a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.079, Quarantined, [e93c66184d5bbd79d80671360ef27f81],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.08, Quarantined, [c461b4cae4c46fc712cc594ed7291fe1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.080, Quarantined, [42e3d3ababfd989e726cfdaa4fb123dd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.081, Quarantined, [c362433b7f29082e0bd34562be421be5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.082, Quarantined, [5cc982fc3b6dd5614b9355523ec2fd03],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.083, Quarantined, [3de8eb9393151c1a78665a4def11a25e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.084, Quarantined, [061f9de1d2d655e1ac32e7c0c53bf907],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.085, Quarantined, [0e17443a02a6f83e4797367129d75da3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.086, Quarantined, [2ef7384698106fc7dc02fea99a6654ac],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.087, Quarantined, [c2633d418c1c0036bb2390177789b848],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.088, Quarantined, [a085285611978fa7af2f485f699712ee],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.089, Quarantined, [53d2bac4693f4aec1bc3d2d5d729bc44],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.09, Quarantined, [9b8a4737ecbcfb3bb6282b7c06fa1de3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.090, Quarantined, [c85d86f8e3c586b0d707891ecc345ba5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.091, Quarantined, [e243c9b5adfbe551b22cdccb659b7e82],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.092, Quarantined, [ab7a0a74f2b61b1bcf0f6c3bd62ac937],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.093, Quarantined, [0e17b6c8bceccd69fee0654204fc2cd4],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.094, Quarantined, [ef36dca2a0084cea9f3f03a44cb4649c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.095, Quarantined, [d64f314dc3e54fe7ba245057bd43c040],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.096, Quarantined, [1f060678d7d105314a943b6ced1313ed],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.097, Quarantined, [c065f78714942313e5f9b1f6946caa56],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.098, Quarantined, [d253611dc9df280eb32baef9649c9967],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.099, Quarantined, [2ff6f48a9513280eaf2fecbb689840c0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.7z, Quarantined, [d550344aa008be7814ca812613edc937],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.apk, Quarantined, [e441730b23857abcc717cfd848b86a96],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.arj, Quarantined, [ed381b6391178caa6b73aef93dc38d73],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.bz2, Quarantined, [1015c1bd476144f22bb38720a7598080],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.cab, Quarantined, [899c532b1e8afd397767b8ef18e8ca36],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.gz, Quarantined, [180d88f6d4d4b581d30b9d0ad12fcf31],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.gzip, Quarantined, [f2337608c7e1a88e8757e4c302fed42c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.jar, Quarantined, [a0858df130781620a33bf2b5966aeb15],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.kz, Quarantined, [80a5324c7e2a43f3b42a61467c8443bd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.lzh, Quarantined, [3de8641a06a2d95d5a84347329d733cd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.mou, Quarantined, [2afbdda1495fa39330ae426545bb6898],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.rar, Quarantined, [190c7707931553e357873077b24e13ed],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.rpm, Quarantined, [ab7ac0be2a7e93a3e0feeeb9fc04f709],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.tar, Quarantined, [9a8b1f5f4167f0464e90099e728eec14],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.tbz, Quarantined, [f1348ef03573b680cc12b1f65fa122de],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.tgz, Quarantined, [081dee9006a2ae8804daa0072cd4b050],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.wim, Quarantined, [ca5b572702a6d660e6f83572f50b7a86],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.z, Quarantined, [12136e1054543df9429c089fd729b749],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.zip, Quarantined, [c85dbfbf2a7e5adc10ce6542976939c7],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.zipx, Quarantined, [6db807775c4cf244ab334f58649c26da],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip_FileAsso.Origin, Quarantined, [42e3aed0a602082e7767aafdff01867a],
PUP.Optional.CornerSunshine, HKLM\SOFTWARE\CLIENTS\Corner Sunshine, Quarantined, [27feed917c2ca88e08bc28e415ebd12f],
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Delete-on-Reboot, [5cc998e62a7e3303952821368d736e92],
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MRT.EXE, Quarantined, [0b1a512d248492a45104bc4e2fd4c53b],
PUP.Optional.Elex, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{2270CC73-9869-4E38-A93C-FF532CCD8273}, Delete-on-Reboot, [f82d334b2d7bb185f793ed2651af916f],
PUP.Optional.WinTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3EB2D6F4-7562-42EF-A818-0756CE3C835C}, Delete-on-Reboot, [d84d1c62fbade84e9052199faa5627d9],
PUP.Optional.GoForFiles, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{491584B3-6719-4F7A-A6D4-7CC6AAF13731}, Delete-on-Reboot, [85a08df1e1c70f27aefcd8d139cab848],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{85E6936B-AECD-4D46-9086-3D75ECBE9257}, Delete-on-Reboot, [b86d26584d5ba195ce0f59ffde2206fa],
PUP.Optional.LuckyBrowse, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{978E9704-4E06-4A66-8FC9-3A4AD41C7541}, Delete-on-Reboot, [6db828562b7d02348ccce3d47f831be5],
PUP.Optional.Elex, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Coerwcult Center, Delete-on-Reboot, [db4a1767ddcbcf675d0720edcb3540c0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\KuaiZip_Update, Delete-on-Reboot, [cb5a017d575176c0a1f497b7cf315ea2],
PUP.Optional.LuckyBrowse, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\LuckyBrowse, Delete-on-Reboot, [c263a5d98f196fc7aad9cfbc51b208f8],
PUP.Optional.WinTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WinTOOL, Delete-on-Reboot, [7ea786f8396fde5812e1d1e7da2647b9],
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, Quarantined, [1c09d4aaf8b096a039628131b64c07f9],
PUP.Optional.Amisites.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\amisitesSoftware, Quarantined, [0c194c3246623cfa7ba18e2359a7b24e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\KuaiZip2, Quarantined, [61c4bcc22c7cc07697350f86ef112ed2],
PUP.Optional.LuckyBrowse.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\LuckyBrowse, Quarantined, [b0759ae42583b680cc34fcc4649e32ce],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\mtQuoteex, Quarantined, [ae7749359b0dbc7a6b16928229db659b],
PUP.Optional.SpringFiles, HKLM\SOFTWARE\WOW6432NODE\SrpnFiles, Quarantined, [cc595925931525113483931fd42ef20e],
PUP.Optional.SysTweak, HKLM\SOFTWARE\WOW6432NODE\Systweak, Quarantined, [c560c6b8edbb54e2bff95302ab55f808],
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\trotuxSoftware, Quarantined, [0d18c0be2f796ec88dd3ef33a65cc23e],
Adware.Elex, HKLM\SOFTWARE\WOW6432NODE\UvConv, Quarantined, [78addba3c5e370c6f950b31af0109967],
Adware.Elex, HKLM\SOFTWARE\WOW6432NODE\WinArcher, Quarantined, [f233ee906b3dcb6b2c938f189a66dc24],
Adware.Elex, HKLM\SOFTWARE\WOW6432NODE\WinSaberSvc, Quarantined, [1d085727d7d160d67cf98a379a6602fe],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.001, Quarantined, [35f0b3cb6c3c1d1932ac4067d8289e62],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.002, Quarantined, [68bd3c428b1d979f5589f4b347b930d0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.003, Quarantined, [9293cab41d8b48eeba24089ffa064fb1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.004, Quarantined, [12132b533b6d0a2c2faf575007f9be42],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.005, Quarantined, [1411dea082268aac627c357250b0e020],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.006, Quarantined, [63c2a8d6aff94beb36a84364a65a9070],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.007, Quarantined, [6fb64638beea5bdbfce24e5978882ed2],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.008, Quarantined, [889d403ea9ff6fc7a638f1b6f60ade22],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.009, Quarantined, [ce57e09e7e2aa393c816198e59a718e8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.01, Quarantined, [081d740a3e6a979fc31b703739c7758b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.010, Quarantined, [e045d9a50e9afc3a0fcf9d0aa06014ec],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.011, Quarantined, [dc49512d4c5c86b098466d3a47b9c43c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.012, Quarantined, [998c314d5d4b11255787fcab718f0ff1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.013, Quarantined, [76afaed06444fa3cdfff4c5bce32768a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.014, Quarantined, [d352a2dc36721f1785599314a9570bf5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.015, Quarantined, [53d2a1dd1d8b3ff7b32bbcebf10fa55b],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.016, Quarantined, [d253b5c94d5b45f1815d03a454ac21df],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.017, Quarantined, [3ee7a2dcb5f33402a836dacdf01020e0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.018, Quarantined, [7aab3d41cfd9b680c717674019e7bc44],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.019, Quarantined, [67be2e50ffa9d85efee04067867aff01],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.02, Quarantined, [34f181fd297f280e7b63bbec857b7b85],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.020, Quarantined, [071ef28c8d1bce684d9163445aa606fa],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.021, Quarantined, [41e40678d6d255e121bdc3e48c74817f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.022, Quarantined, [2ff60a747c2c6ec8dc025057e61ad729],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.023, Quarantined, [b273b7c72484fd393da172351be5d32d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.024, Quarantined, [939296e8a30522148a54b0f7b24e8080],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.025, Quarantined, [b471cdb1bcec0a2c4f8fb2f54db3f20e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.026, Quarantined, [9392e19d1890c96d647a80270bf533cd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.027, Quarantined, [85a06d118d1b47ef3f9f3e697888d22e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.028, Quarantined, [b96c9ce2b7f12511db03862140c026da],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.029, Quarantined, [0a1b532b00a873c3d509fdaa0bf5e020],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.03, Quarantined, [72b3067805a3a88eab33248355ab5fa1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.030, Quarantined, [6eb706782f797bbbdd01b1f6f40c7c84],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.031, Quarantined, [d64f8cf283251521ca14614679873fc1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.032, Quarantined, [ed38512df7b12b0b2ab4149357a97c84],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.033, Quarantined, [ed38f48a62468ea8e3fb62457a864cb4],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.034, Quarantined, [e73e5d211d8b5fd721bd7532f40ccd33],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.035, Quarantined, [d74e15699513a393b9258225ca36ec14],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.036, Quarantined, [7aab611d1494e0561dc14e59f30d31cf],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.037, Quarantined, [4ed73b43e9bf1b1be7f70b9c87798080],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.038, Quarantined, [160f730becbc45f137a7dacd43bdfe02],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.039, Quarantined, [bb6a7707dbcd9b9ba73700a743bd2cd4],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.04, Quarantined, [33f2a1dde5c353e35589941349b7cb35],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.040, Quarantined, [9b8aabd35355e25412cc8c1b9f6150b0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.041, Quarantined, [a08581fdabfd34029a44d9cec43c40c0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.042, Quarantined, [40e57d01b8f09a9c03db05a28e727d83],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.043, Quarantined, [85a0d8a6c9df1a1c20beeabd649c46ba],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.044, Quarantined, [160fe797951381b5bb2385224eb2fd03],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.045, Quarantined, [3fe69de188209c9a4e90b5f2e81838c8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.046, Quarantined, [26ff304e6d3bf64039a5c5e24cb48e72],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.047, Quarantined, [1a0bb2ccbcec49ede9f59413659bdb25],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.048, Quarantined, [d64f4e309c0caf87de00baeddc24df21],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.049, Quarantined, [50d5d5a9baeeab8b76685057d32da45c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.05, Quarantined, [7baa6a14a3053bfb6b7333749070768a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.050, Quarantined, [a87d403e258378be429c674032ce1ae6],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.051, Quarantined, [dd48b8c6792f999d22bce2c54ab643bd],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.052, Quarantined, [061f05797d2b20168b534364e917fa06],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.053, Quarantined, [54d12f4f9216d165d10da0075aa69070],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.054, Quarantined, [071e413d1c8cc76f9648cddaeb152fd1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.055, Quarantined, [58cddea03d6bb97d2fafc8df1de3e21e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.056, Quarantined, [d055e29ccedad1655f7fabfc32ce54ac],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.057, Quarantined, [a580e29ca1079a9c4995089f0cf437c9],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.058, Quarantined, [57ce5925ffa94bebd8065b4c53ad01ff],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.059, Quarantined, [c85dea94fcac2d0920bef1b68b751de3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.06, Quarantined, [b96c83fb2088c76f9e406047a759639d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.060, Quarantined, [7ca997e7c7e17eb85985ecbbab55926e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.061, Quarantined, [e243611d297fb185736b8d1a57a9e719],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.062, Quarantined, [e342b1cd773173c3c41a4265e21ea759],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.063, Quarantined, [899c90eee2c6a19558864f58dd23da26],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.064, Quarantined, [64c1c4baa9ffcb6b13cbe5c260a018e8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.065, Quarantined, [ec393648f3b5a69015c90d9a18e83cc4],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.066, Quarantined, [ca5b3549dfc9ac8ac41ad2d5bc44c23e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.067, Quarantined, [081dd6a8baee9c9a924cc3e42fd19070],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.068, Quarantined, [0421daa41494e6509d41b6f156aa8977],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.069, Quarantined, [d64fafcf9711c3736b732a7d34ccdd23],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.07, Quarantined, [9a8b8bf3bdebe74fd00ef0b7fd03ea16],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.070, Quarantined, [b4719de13b6d58de98467c2b926eab55],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.071, Quarantined, [8c99bfbfe4c4d85ed7077235c53b44bc],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.072, Quarantined, [76af7608891fe74f8d51c8df7e82748c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.073, Quarantined, [c164d2acd5d30135ba245d4a37c98f71],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.074, Quarantined, [27fea2dcb6f237ffd00e3c6be9171be5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.075, Quarantined, [d154ceb0594f45f1637b01a605fb8c74],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.076, Quarantined, [9a8b1668abfd2a0c904e01a6748cbf41],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.077, Quarantined, [67bec3bb93151c1ac5190a9d4cb4e31d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.078, Quarantined, [ba6be19d4c5cc4725a844b5cf907c63a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.079, Quarantined, [a5809be3179154e2627c60475ea28779],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.08, Quarantined, [170eb1cd3177989e716d268129d7ec14],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.080, Quarantined, [1213c4ba5c4cef473ba3ced90bf511ef],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.081, Quarantined, [a2836915cadea69020bee4c359a7e818],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.082, Quarantined, [d94c700ef9af86b09d410f98e61a08f8],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.083, Quarantined, [66bf26584464f73f6678a9fe08f82bd5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.084, Quarantined, [d35283fb5c4c57dfefef0d9a629e817f],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.085, Quarantined, [c461abd38e1a2214fce2594e6f913fc1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.086, Quarantined, [f1349de1fbad3afc37a75057c53b5fa1],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.087, Quarantined, [5acbcfaf5058280eae30bceb728e5ca4],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.088, Quarantined, [af76bdc1852357dfc21c971004fc04fc],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.089, Quarantined, [7aab740a9612b383419d8126be42669a],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.09, Quarantined, [7ca90c724662e74ffbe3386fb8487888],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.090, Quarantined, [3ce9dba3288024126a7417908b7557a9],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.091, Quarantined, [fa2b334bfcaca096c915d4d3946c41bf],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.092, Quarantined, [b17490eea50315216d711097c53b09f7],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.093, Quarantined, [ae77ee909b0dba7c14ca6d3acf3145bb],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.094, Quarantined, [1411aed0e9bfe84e3aa42483e9177090],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.095, Quarantined, [d64fe59907a17abcfae45e49be4211ef],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.096, Quarantined, [e540542a31771422f3ebb6f158a811ef],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.097, Quarantined, [7ea77fff7830ed49a539c8df34cc12ee],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.098, Quarantined, [65c0720c96129a9cae30aafd0ff14db3],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.099, Quarantined, [40e516684b5d65d188565057867a5ea2],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.7z, Quarantined, [34f10a74317740f69f3f5e499967b24e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.apk, Quarantined, [889d215d7a2ed85ec21cf7b048b849b7],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.arj, Quarantined, [1015a1ddbeea0531835b6641857b1be5],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.bz2, Quarantined, [d74e18669a0e40f61ac41691ed1330d0],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.cab, Quarantined, [70b5b8c6703864d2ce10eabdb749b947],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.gz, Quarantined, [6abb0e7008a02f076d71664155abb848],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.gzip, Quarantined, [4fd6add11a8e13236b738f1860a0c739],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.jar, Quarantined, [68bdd2acdbcd092d4c92ebbca65a738d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.kz, Quarantined, [a87d2b5326826dc931ad0f9836caf010],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.lzh, Quarantined, [2005710d8226d66055893d6a09f7c838],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.mou, Quarantined, [ab7a2a541e8a082e25b9a40389777d83],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.rar, Quarantined, [b96c9ee0e5c3b482b22c03a44db32ad6],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.rpm, Quarantined, [49dcf28cf1b77eb807d7d6d128d8f709],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.tar, Quarantined, [55d039458b1d1a1c0ad4fea96a9657a9],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.tbz, Quarantined, [7fa6daa4ffa9181e6c724a5d7d83ba46],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.tgz, Quarantined, [57ce95e99216ea4cbb23e9be629ef30d],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.wim, Quarantined, [be6794ea88201224d80657509070847c],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.z, Quarantined, [e63fdea0e8c086b004da36712fd135cb],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.zip, Quarantined, [85a0106e3276c37306d80f983ec24eb2],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip.zipx, Quarantined, [d94c9ce2594f2c0a617d14930df3a25e],
PUP.Optional.Kuaizip, HKLM\SOFTWARE\WOW6432NODE\CLASSES\KuaiZip_FileAsso.Origin, Quarantined, [a481037bd4d42c0a706eb7f087792ad6],
PUP.Optional.CornerSunshine, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\Corner Sunshine, Quarantined, [0d18f48a3f69d165ccf82fdd32ce18e8],
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online Application Installer, Quarantined, [a67f28560f9985b1c29cb9b5e020b749],
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH, Delete-on-Reboot, [e5403747525623137078dbc6f50e916f],
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Delete-on-Reboot, [b2731b638f197fb7407d74e30ef2a957],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Quoteex_RASAPI32, Quarantined, [8f9666187d2b85b1ecdc2b7a12f19070],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Quoteex_RASMANCS, Quarantined, [aa7bb6c82385b97dbb0d495c5fa48d73],
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MRT.EXE, Quarantined, [8a9b403ee1c7dd5987ce8882ad5621df],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe, Quarantined, [2afbccb2b7f1d066e8e120850cf7af51],
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, Quarantined, [75b0601e4068ba7c8e0dad05c9393ac6],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Archer, Quarantined, [929385f9feaaff373d9f295ffe0244bc],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Coerwcultcntand.exe, Quarantined, [7ea7bdc13c6c2d09020816f7e51baf51],
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\GubedZL, Quarantined, [988d1b63ddcb2c0a45a8c417748c9e62],
PUP.Optional.Kuaizip, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Kuaizip Update Checker, Quarantined, [c75e641ac5e3102645d85100a65ade22],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinSAPSvc, Quarantined, [7baaa3db1f8984b28aecc3c42dd334cc],
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinSnare, Quarantined, [50d5b6c8565280b61a0018ba51af6799],
PUP.Optional.Linkury.ACMB1, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Application Hosting, Quarantined, [3de838466c3c6fc7428c0c979370e917],
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ISAFEKRNLBOOT, Delete-on-Reboot, [f035314d1d8bb97d3daa4f65cf33a45c],
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ISAFENETFILTER, Delete-on-Reboot, [85a0146ab4f4f244a345bef652b0a060],
PUP.Optional.Kuaizip, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\KuaiZip2, Quarantined, [3aeb027cb9ef2c0ac00b5342a858956b],
PUP.Optional.SpringFiles, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\SrpnFiles, Quarantined, [091c7e009d0b3ef874539e6f4abacc34],
PUP.Optional.SysTweak, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\systweak, Quarantined, [c461ceb06741d264dd6d7eda728eb34d],
PUP.Optional.Linkury, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{IELNKSRCH}, Delete-on-Reboot, [83a26f0fc7e10234cf189b06847f3fc1],
PUP.Optional.Amisites.ShrtCln, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Delete-on-Reboot, [82a3641af1b743f3725cb2ea90702ad6],
FraudTool.YAC, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\iSafe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],

Registry Values: 42
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, mylucky123, Quarantined, [5cc998e62a7e3303952821368d736e92]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Quarantined, [b273b5c99f09d264ba034d0afc0413ed]
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MRT.EXE|Debugger, C:\ProgramData\ficfi\Gubed.exe -Yrrehs, Quarantined, [0b1a512d248492a45104bc4e2fd4c53b]
PUP.Optional.Elex, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{2270CC73-9869-4E38-A93C-FF532CCD8273}|Path, \Coerwcult Center, Delete-on-Reboot, [f82d334b2d7bb185f793ed2651af916f]
PUP.Optional.WinTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3EB2D6F4-7562-42EF-A818-0756CE3C835C}|Path, \WinTOOL, Delete-on-Reboot, [d84d1c62fbade84e9052199faa5627d9]
PUP.Optional.GoForFiles, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{491584B3-6719-4F7A-A6D4-7CC6AAF13731}|Path, \GoforFilesUpdate, Delete-on-Reboot, [85a08df1e1c70f27aefcd8d139cab848]
PUP.Optional.Kuaizip, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{85E6936B-AECD-4D46-9086-3D75ECBE9257}|Path, \KuaiZip_Update, Delete-on-Reboot, [b86d26584d5ba195ce0f59ffde2206fa]
PUP.Optional.LuckyBrowse, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{978E9704-4E06-4A66-8FC9-3A4AD41C7541}|Path, \LuckyBrowse, Delete-on-Reboot, [6db828562b7d02348ccce3d47f831be5]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, http://www.trotux.com/?z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=hp&mode=ffsengext, Quarantined, [1c09d4aaf8b096a039628131b64c07f9]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, http://www.trotux.com/?z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=hp&mode=ffsengext, Quarantined, [b4714c327e2a3cfadfbca0129c665ca4]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, http://www.trotux.com/search/?q={searchTerms}&z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=sp, Quarantined, [0b1a4d31b4f4f046b3e8b9f934cee917]
PUP.Optional.Trotux, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, http://www.trotux.com/search/?&z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=sp&q=, Quarantined, [1b0a0975476155e14f4cfab842c009f7]
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|DisplayName, Search the web, Quarantined, [e5403747525623137078dbc6f50e916f]
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Quarantined, [da4bc4ba4761e65081763a69e91a45bb]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, mylucky123, Quarantined, [b2731b638f197fb7407d74e30ef2a957]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Quarantined, [29fc4d31e0c85dd9f8c5094e748c47b9]
Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\MRT.EXE|Debugger, C:\ProgramData\ficfi\Gubed.exe -Yrrehs, Quarantined, [8a9b403ee1c7dd5987ce8882ad5621df]
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp, http://www.trotux.com/?z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=hp&mode=ffsengext, Quarantined, [75b0601e4068ba7c8e0dad05c9393ac6]
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab, http://www.trotux.com/?z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=hp&mode=ffsengext, Quarantined, [170ed6a843656dc9a8f3dad85aa812ee]
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, http://www.trotux.com/search/?q={searchTerms}&z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=sp, Quarantined, [e93c532bd6d2db5b3368a50daf53a45c]
PUP.Optional.Trotux, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl, http://www.trotux.com/search/?&z=768c2d5f852fd3b6d1db14eg2zdm5g4b6o0q8mcodg&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=sp&q=, Quarantined, [f82d314d812744f2e0bb4270778b28d8]
PUP.Optional.Ghokswa.Generic, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\FirefoxU|ImagePath, "C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe", Quarantined, [60c54b33eeba0a2c4baa2116b0507e82]
PUP.Optional.LogicHandler, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BACKLH|ImagePath, C:\ProgramData\Logic Handler\set.exe, Quarantined, [1411631b9711c76f5b2d555efa0850b0]
PUP.Optional.Interhop, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\INTERHOP|ImagePath, "C:\Program Files (x86)\InterHop\InterHop.exe" {2C8E8C85-942B-451C-8243-97A089265577}, Quarantined, [4cd92c524e5a3006d88da3b334cc837d]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnl|ImagePath, \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys, Delete-on-Reboot, [9392710dc3e550e6687e9e1607fb22de]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnlKit|ImagePath, \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys, Delete-on-Reboot, [8c99631bc5e3a09604e2d3e15da5a759]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnlMon|ImagePath, \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys, Quarantined, [2104e19d6444fc3a9a4c2c8833cff60a]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\iSafeKrnlR3|ImagePath, \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys, Delete-on-Reboot, [7baa413dd4d4979fd214d6de2bd7c43c]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ISAFEKRNLBOOT|ImagePath, system32\DRIVERS\iSafeKrnlBoot.sys, Delete-on-Reboot, [f035314d1d8bb97d3daa4f65cf33a45c]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ISAFENETFILTER|ImagePath, system32\DRIVERS\iSafeNetFilter.sys, Delete-on-Reboot, [85a0146ab4f4f244a345bef652b0a060]
FraudTool.YAC, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ISAFESERVICE|ImagePath, C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe, Delete-on-Reboot, [3de892ec248455e16b7e981c43bfd927]
PUP.Optional.Linkury, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NETTRANS|ImagePath, C:\ProgramData\NetworkPacketManitor\Nettrans.exe, Quarantined, [04215628faae2a0c64740a5b758b956b]
Hijack.AutoConfigURL.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, 0http://noblockingweb.net/wpad.dat?8b0eb9aff20e3d8fd3d1cb4b4f6f580a23130821, Quarantined, [d64f2955fbadb482e5cc7143e818e21e]
PUP.Optional.LuckyBrowse, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{C2C16730-9650-42FA-854C-73B78435BD08}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\LuckyBrowse\app\LuckyBrowse.exe|Name=LuckyBrowse|, Quarantined, [6db8f28cbdeb171f55de6d2fa85b38c8]
PUP.Optional.LuckyBrowse, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{78585DE9-7094-4623-843E-D52605133419}, v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\LuckyBrowse\app\LuckyBrowse.exe|Name=LuckyBrowse|, Quarantined, [37ee81fd9810082e45eee1bb946f7b85]
Trojan.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\THEMES|DependOnService, iThemes5^^, Quarantined, [d55099e54d5be74fff3d19c667997f81]
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINSABER|ImagePath, C:\Program Files (x86)\WinSaber\WinSaber.exe, Quarantined, [dc49a4da109860d637d33107d12f619f]
PUP.Optional.Linkury, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|DisplayName, Search the web, Quarantined, [83a26f0fc7e10234cf189b06847f3fc1]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Quarantined, [9491ec92ccdc5adc599c693af1128f71]
PUP.Optional.Amisites.ShrtCln, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, http://www.amisites.com/search/?type=ds&ts=1483110200&z=d48e425f76393480ef60d70g4z5b6c2g8g7e1o0e5c&from=archer1028&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Quarantined, [82a3641af1b743f3725cb2ea90702ad6]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Quarantined, [45e00c7260488fa724d29a09d82b06fa]
Hijack.AutoConfigURL.PrxySvrRST, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|AutoConfigUrl, http://noblockingweb.net/wpad.dat?8b0eb9aff20e3d8fd3d1cb4b4f6f580a23130821, Quarantined, [29fca2dc426695a1ec62c7ee0cf42dd3]

Registry Data: 16
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}),Replaced,[1b0abbc306a2c0769dbaa5b105fba858]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1, Good: (www.google.com), Bad: (http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1),Delete-on-Reboot,[38eda5d9f0b87bbbabac3f17bd43fc04]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1, Good: (www.google.com), Bad: (http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1),Delete-on-Reboot,[6bba631bb0f8aa8c62f5282e6c947f81]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}),Replaced,[8e977905852361d55601470f54ac5da3]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Delete-on-Reboot,[ea3b75094e5a86b014a94aaa49bab848]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}),Replaced,[cd58dea02a7ee25497c0223447b97987]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1, Good: (www.google.com), Bad: (http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1),Delete-on-Reboot,[50d5a4da6543082eaaadb79f5ba5eb15]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1, Good: (www.google.com), Bad: (http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1),Delete-on-Reboot,[75b0a6d836725ed8e57263f38a7644bc]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mylucky123.com/search/?type=ds&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&q={searchTerms}),Replaced,[95903846b8f0cd691344c98d5ba5619f]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Delete-on-Reboot,[7aab7d012385f145e5d8ae46a45f847c]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Good: (www.google.com), Bad: (http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}),Replaced,[5fc67905f7b169cd07b38076dd2623dd]
PUP.Optional.MyLucky123.ShrtCln, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1, Good: (www.google.com), Bad: (http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1),Delete-on-Reboot,[90957fff07a10f27e55d6aebbc445ca4]
PUP.Optional.MyLucky123.ShrtCln, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1, Good: (www.google.com), Bad: (http://www.mylucky123.com/?type=hp&ts=1478249762&z=c3ec702ff547edeb93f6e06gfz8m9bdo9zbtdbaeco&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1),Delete-on-Reboot,[50d5740a6d3b270ff84a59fc00007c84]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Good: (www.google.com), Bad: (http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}),Replaced,[db4aceb0e8c05ed8d5e5ad49659e728e]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SearchAssistant, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Good: (www.google.com), Bad: (http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}),Replaced,[5bcabdc1fcac75c10eacd71f16ed44bc]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}, Good: (www.google.com), Bad: (http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH4gFuGAZQsTZQEOFGpWojamzmyMahm1BAZjj58K62Mf5Po-vNqL1F_ce-8Cy3uU1MV43wFdV_3eqt0SiwCeeMLAdwp_5f0T_XWpydzPmt-LOsD_p3Z_3qyrihRNHzu1E1hV0FlW1MesBp8NW7XR_Ot0mn2TyjBm33B4kB86Ug,,&q={searchTerms}),Replaced,[7ea7502e297f0135b3088c6acf34d030]

Folders: 401
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\bin, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\components, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\extensions, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\features, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\VisualElements, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\defaults, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\defaults\pref, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\dictionaries, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\fonts, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\gmp-clearkey, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\gmp-clearkey\0.1, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\uninstall, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86, Delete-on-Reboot, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\lang, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\sfx, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip, Delete-on-Reboot, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\data, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language\en, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64, Delete-on-Reboot, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\lang, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Interhop, C:\Program Files (x86)\InterHop, Delete-on-Reboot, [f0353549d1d7e94da7d5c19a2bd55fa1],
PUP.Optional.Elex, C:\Program Files (x86)\WinArcher, Delete-on-Reboot, [27fef18d3078fb3b210e92e06f917090],
PUP.Optional.Elex, C:\ProgramData\WinSAPSvc, Delete-on-Reboot, [6db86519d8d061d53e57de9b03fda15f],
PUP.Optional.Elex, C:\ProgramData\WinSAPSvc\winsap_update, Quarantined, [6db86519d8d061d53e57de9b03fda15f],
Adware.Elex.Generic, C:\Users\Niko\AppData\Roaming\gjdgj, Delete-on-Reboot, [1c09a4da4365c5710d4b01c015ebb050],
Adware.Elex, C:\Program Files (x86)\Gubed, Delete-on-Reboot, [4ed7ed9146625cdaca258457bd43c13f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler, Delete-on-Reboot, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\X64, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\X86, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.Linkury, C:\Windows\Temp\Smartbar, Quarantined, [061fa3dba206e4521ccae4bd25de649c],
PUP.Optional.Elex, C:\Program Files (x86)\SoSoEasy, Delete-on-Reboot, [05207b034068bc7a3482a5610bf5b749],
PUP.Optional.Elex, C:\Program Files (x86)\SoSoEasy\{4111C1D9-49FB-4B17-ABE4-41D927404796}, Quarantined, [05207b034068bc7a3482a5610bf5b749],
PUP.Optional.Elex, C:\Program Files (x86)\SoSoEasy\{E2DB3EEC-E148-4231-A7F4-56AB34672A7B}, Quarantined, [05207b034068bc7a3482a5610bf5b749],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_303c93, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\.bin, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws-sign2, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\doc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\doc\wg-meetings, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\build, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\caseless, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\forever-agent, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\dist, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\bin, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\ansi-styles, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\escape-string-regexp, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules\ansi-regex, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules\ansi-regex, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\supports-color, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\fixtures, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules\pinkie, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\dist, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\example, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\images, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\images, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\images, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\examples, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\examples, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-00, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-01, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-02, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-04, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\tests, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\bin, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man\man1, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\tst, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\tst\ber, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\etc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\is-typedarray, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\benchmark, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\bin, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\oauth-sign, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\dist, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\test, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tunnel-agent, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\backup, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Data, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\device, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Download, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Download\Apk, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Download\Music, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Download\Picture, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Download\Video, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\driver, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Version, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Version\CacheVersion, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Version\NewVersion, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Version\OldVersion, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.Linkury, C:\ProgramData\NetworkPacketManitor, Delete-on-Reboot, [4adb7905baee8caa0bafbaae51af0ff1],
PUP.Optional.Elex, C:\Program Files (x86)\WinSaber, Delete-on-Reboot, [bb6a6d11842478be3064f583837d7987],
PUP.Optional.Elex, C:\ProgramData\ChelfNotify, Quarantined, [8c995d218f1916201aaa017930d009f7],
PUP.Optional.OnlineIO, C:\ProgramData\Microleaves\Traffic Exchange, Quarantined, [c362c7b7c8e0ba7c6e8aed8dc33dae52],
PUP.Optional.Kuaizip, C:\Users\Niko\AppData\Roaming\KuaiZip, Quarantined, [81a4542ae2c635017f60485f8f71e020],
Adware.MoboGenie, C:\Program Files (x86)\Mobogenie, Quarantined, [5ec7a7d7d9cf80b6dd51e4ddba464eb2],
Adware.Elex, C:\Program Files (x86)\Gubed_WMI, Delete-on-Reboot, [52d3ccb28d1b0e28d40225b6d52b14ec],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\iDesk, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\cache, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\defs, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\quarantine, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\trustzone, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\font, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\clog, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\pfdatapfdata, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\pfdatapfdata\SSL, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\foldericon, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\layout\newclean, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\layout\pop, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Appstore, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\style, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\tws, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\tws\defs, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\tws\filwls, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\tws\quarantine, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\update, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\update\0, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\update\1, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\update\temp, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
PUP.Optional.LuckyBrowse.ShrtCln, C:\ProgramData\LuckyBrowse, Quarantined, [ee37f787594f290d6ba5822937cb1ae6],
PUP.Optional.SpringFiles, C:\Users\Niko\AppData\Roaming\SpringFiles, Quarantined, [3de80c722187330376c7cae2ce346b95],
PUP.Optional.ConduitTB.Gen, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\CT3289075, Quarantined, [5acb5826307883b326b54e6034ced52b],
PUP.Optional.Elex.Generic, C:\Program Files (x86)\89uBD7E, Quarantined, [4bda146a3e6acd69c85335f95ca43bc5],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Quoteexs, Quarantined, [1e0736484e5a5cda8d97715d11ef9b65],

Files: 2300
FraudTool.YAC, C:\WINDOWS\SYSTEM32\drivers\iSafeKrnlBoot.sys, Delete-on-Reboot, [fab2eba07369bf3c6db33469b5b36fcb],
FraudTool.YAC, C:\WINDOWS\SYSTEM32\drivers\iSafeNetFilter.sys, Delete-on-Reboot, [9fb02fba90f6af59537a30c3db9777c8],
PUP.Optional.Kuaizip, C:\Windows\System32\drivers\KuaiZipDrive2.sys, Delete-on-Reboot, [01904ef71c50dd1c2863fb153a1b4417],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe, Delete-on-Reboot, [53d26519c2e6de58ac3deaae23de9f61],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll, Delete-on-Reboot, [8a9bceb033755fd75693cdcb6b96a65a],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll, Delete-on-Reboot, [13125a24dfc9af870fda5e3a5ba6857b],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll, Delete-on-Reboot, [df461d61525692a4a3460c8c11f018e8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll, Delete-on-Reboot, [4bdafe8071371323c2279404de23d828],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll, Delete-on-Reboot, [978e5727d3d53cfadd0cd4c47c85b848],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll, Delete-on-Reboot, [869fc8b62682261057922177c8393ac6],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll, Delete-on-Reboot, [7aab5925fbad2e08a54422760df4c13f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll, Delete-on-Reboot, [9590b2cc3b6da69075749dfbe819847c],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe, Delete-on-Reboot, [879ed7a7891f96a0e2072375669bf10f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll, Delete-on-Reboot, [1a0bd1ad891fe0564a9f217752afe020],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafebs.dll, Delete-on-Reboot, [b86d3e409c0c1422a2478216818040c0],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll, Delete-on-Reboot, [2afbfa84f9afad899950296f9e6302fe],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll, Delete-on-Reboot, [1411700edcccba7c1bce2b6d926f28d8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll, Delete-on-Reboot, [3ce9542a8721ed4977724e4adc2531cf],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll, Delete-on-Reboot, [27fedf9fd9cf40f631b88612df2208f8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll, Delete-on-Reboot, [6bba0a742c7c94a230b91583cb36bb45],
Adware.Elex, C:\Program Files (x86)\Common Files\Services\iThemes.dll, Delete-on-Reboot, [b471621c674178be3250d1cedf21f10f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\set.exe, Delete-on-Reboot, [4bda55295355ba7c83e155c5748dca36],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe, Delete-on-Reboot, [64c1f08edfc914224b9e7622dd246898],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafebase.dll, Delete-on-Reboot, [58cd2b533d6bcc6a3baebddbc04108f8],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll, Delete-on-Reboot, [a67f631b9315cc6ad2178a0ec63b09f7],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll, Delete-on-Reboot, [77aed8a60c9cac8a2bbe9305f30ebb45],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTpNodisturb.dll, Delete-on-Reboot, [df469fdfa00852e4dd0c237535ccc43c],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll, Delete-on-Reboot, [d64fb5c9b3f52d0907e2aeea71902ad6],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll, Delete-on-Reboot, [fb2a2b53f1b7102663864e4a23ded927],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll, Delete-on-Reboot, [e243f48afcac56e05198dbbdcf324bb5],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll, Delete-on-Reboot, [80a5d4aaf3b5b2846683eeaaaa5726da],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll, Delete-on-Reboot, [ac79b3cb9810b18573763662ca375ea2],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iTPAutoClean.dll, Delete-on-Reboot, [ae77304ed9cfd066e8010d8b18e9e21e],
Adware.Elex, C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe, Delete-on-Reboot, [66bf6a14b1f7d660770d5f80a25e7090],
PUP.Optional.Linkury, C:\ProgramData\NetworkPacketManitor\Nettrans.exe, Delete-on-Reboot, [e34248363078d16566b4dd8a7f81fa06],
PUP.Optional.Elex, C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe, Delete-on-Reboot, [2203acd26642082e252bef4b1ae69f61],
PUP.Optional.Elex, C:\Program Files (x86)\WinSaber\WinSaber.exe, Delete-on-Reboot, [bd6808769018b5816c39d384768a12ee],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys, Delete-on-Reboot, [39ecdf9f8f19fe3897528612778a6d93],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\Coerwcultcntand.exe, Quarantined, [d64f6519e5c3f442dda9fc8a956b8b75],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys, Delete-on-Reboot, [59cc92ec347480b69e4b5543e21faa56],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys, Delete-on-Reboot, [2bfa4d3101a7280eba2f613751b00cf4],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys, Delete-on-Reboot, [49dc136b01a7231313d6a6f2738e9b65],
PUP.Optional.Elex, C:\Program Files (x86)\89uBD7E\olpBDAD.dll, Quarantined, [170ed4aa6e3aa591684350dbb848946c],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\chrome_elf.dll, Quarantined, [ad78f8861593b87e1a0c39422dd304fc],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\Coerwcultcntdnk.exe, Quarantined, [5dc8522c139557df64226620d22ebc44],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\saber.exe, Quarantined, [ec39dba37f292c0a1194abac09f7cc34],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\121D.tmp.exe, Quarantined, [15100678bbedf145e4d7d541d828f010],
PUP.Optional.ConvertAd, C:\Users\Niko\AppData\Local\Temp\nsqE7DF.tmp, Quarantined, [6abbc2bcabfd0b2b76040fe132d143bd],
PUP.Optional.ConvertAd, C:\Users\Niko\AppData\Local\Temp\nsg5583.tmp, Quarantined, [9f86b6c8bcec2a0c87f3e40cff048977],
PUP.Optional.Amonetize, C:\Users\Niko\AppData\Local\Temp\sdf152E.exe, Quarantined, [9590f18d6c3ca29453f72cdc9072f30d],
PUP.Optional.Bundler, C:\Users\Niko\AppData\Local\Temp\fsdE7CF.exe, Quarantined, [35f00c72a9ff8aac24a8c62cc43cf808],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\D09D.tmp.exe, Quarantined, [b5707e00b7f155e1c2f947cfb848629e],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\D2C1.tmp.exe, Quarantined, [7aab5727aff937ff9e1dcb4b9868a25e],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\81B.tmp.exe, Quarantined, [5dc83c421a8ee1556a5118feca364fb1],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\8A21.tmp.exe, Quarantined, [899ce29c3f693cfa8536d640679916ea],
PUP.Optional.VBates, C:\Users\Niko\AppData\Local\Temp\8QkzPQzqFM.exe, Quarantined, [4dd8e39b268286b04611a0657d85d828],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\ICReinstall_8A21.tmp.exe, Quarantined, [aa7b700eacfc86b0803b48cede22b848],
PUP.Optional.ConvertAd, C:\Users\Niko\AppData\Local\Temp\nswE36D.tmp, Quarantined, [cd587e001890fd3968124ca442c18779],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\1998.tmp.exe, Quarantined, [52d3d5a9b6f2f640bcffff1726dab947],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\2186.tmp.exe, Quarantined, [c06582fcfcac0b2b1f9c0f071fe14cb4],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\3220.tmp.exe, Quarantined, [879e186610982b0b734880966b959868],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\32B5.tmp.exe, Quarantined, [e045423c6e3a8caa6556d343ea169f61],
PUP.Optional.BundleInstaller, C:\Users\Niko\AppData\Local\Temp\696D.tmp.exe, Quarantined, [aa7b433bb9eff4423883be582bd5d729],
PUP.Optional.Kuaizip, C:\Users\Niko\AppData\Local\Temp\KZ7ZData.7z, Quarantined, [4ed7bfbf6d3bde58285fafe2e917e11f],
PUP.Optional.ConvertAd, C:\Users\Niko\AppData\Local\Temp\nsbE782.tmp, Quarantined, [b66f2856d5d31323750518d88e7527d9],
PUP.Optional.Elex.ClnShrt, C:\Users\Niko\AppData\Local\Temp\00022800\hp.exe, Quarantined, [ba6b96e821872c0a17f9bca7738dbb45],
PUP.Optional.Elex, C:\Users\Niko\AppData\Local\Temp\00022803\kpzip.exe, Quarantined, [da4badd15157092d1e98808cc43c29d7],
PUP.Optional.Elex, C:\Users\Niko\AppData\Local\Temp\00022803\service.exe, Quarantined, [4cd97a043f69e84ec7ebca9534cc6799],
PUP.Optional.LogicHandler, C:\Users\Niko\AppData\Local\Temp\RarSFX0\LogicHandler.exe, Quarantined, [9c8981fd04a4cb6b3a2a9c7e669baa56],
PUP.Optional.Amonetize, C:\Users\Niko\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\OfferInstaller.exe, Quarantined, [0421fc82a800c670d67444c4e02231cf],
PUP.Optional.Offerware, C:\Users\Niko\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\Extracted\adv_109.exe, Quarantined, [32f3ec923b6dc670d415d8ff4eb36b95],
PUP.Optional.ConvertAd, C:\Windows\Temp\135D.tmp, Quarantined, [b76edca2f8b0a294268bfed9e1209c64],
PUP.Optional.ConvertAd, C:\Windows\Temp\25FE.tmp, Quarantined, [f92c2757495f64d26e43c80f679adc24],
PUP.Optional.ConvertAd, C:\Windows\Temp\3A2.tmp, Quarantined, [4ed73a44adfb64d25f52825524dd758b],
PUP.Optional.ConvertAd, C:\Windows\Temp\3B1F.tmp, Quarantined, [ce57b1cdeeba280e327fbc1b12efc937],
PUP.Optional.ConvertAd, C:\Windows\Temp\4932.tmp, Quarantined, [d74ebec0edbb999de2cfedea36cbd927],
PUP.Optional.ConvertAd, C:\Windows\Temp\49F1.tmp, Quarantined, [68bd720cedbb2412813026b178897789],
PUP.Optional.ConvertAd, C:\Windows\Temp\4B16.tmp, Quarantined, [6cb9245ad3d5cf67ad04a235d42d8878],
PUP.Optional.ConvertAd, C:\Windows\Temp\4BC4.tmp, Quarantined, [74b182fcc4e4e5513c75835454adbc44],
PUP.Optional.ConvertAd, C:\Windows\Temp\4CBB.tmp, Quarantined, [db4a99e57a2ea98d763b9a3d8d740af6],
PUP.Optional.ConvertAd, C:\Windows\Temp\4EA6.tmp, Quarantined, [ce57067850582115c3eeb3249b6602fe],
PUP.Optional.ConvertAd, C:\Windows\Temp\514D.tmp, Quarantined, [38ed91edf6b2c0767c35cd0a966b25db],
PUP.Optional.ConvertAd, C:\Windows\Temp\516.tmp, Quarantined, [a2832856f2b673c37938c413e71abf41],
PUP.Optional.ConvertAd, C:\Windows\Temp\5247.tmp, Quarantined, [8e9758268e1a181eb0016374a85908f8],
PUP.Optional.ConvertAd, C:\Windows\Temp\5736.tmp, Quarantined, [53d26f0fa008c373edc413c49c656898],
PUP.Optional.ConvertAd, C:\Windows\Temp\5BCB.tmp, Quarantined, [e045c3bb7f2938fe0fa2fddafe037987],
PUP.Optional.ConvertAd, C:\Windows\Temp\5C88.tmp, Quarantined, [1213f5893e6a9d99763b785f28d9fe02],
PUP.Optional.ConvertAd, C:\Windows\Temp\654C.tmp, Quarantined, [1b0a39457f296dc9ddd4c90ead54817f],
PUP.Optional.ConvertAd, C:\Windows\Temp\6730.tmp, Quarantined, [2cf9007eb4f49e98664b9047f40d0ef2],
PUP.Optional.ConvertAd, C:\Windows\Temp\6771.tmp, Quarantined, [9194ccb23177a393d7dadbfcc53c34cc],
PUP.Optional.ConvertAd, C:\Windows\Temp\6885.tmp, Quarantined, [6fb608769d0b82b4941de5f2689915eb],
PUP.Optional.ConvertAd, C:\Windows\Temp\698E.tmp, Quarantined, [bb6a5c22555367cf258cedeabf426997],
PUP.Optional.ConvertAd, C:\Windows\Temp\6AA0.tmp, Quarantined, [3bea17672781270f04adf7e031d0a957],
PUP.Optional.ConvertAd, C:\Windows\Temp\E265.tmp, Quarantined, [57ce136be1c759dd941d14c391702fd1],
PUP.Optional.ConvertAd, C:\Windows\Temp\E390.tmp, Quarantined, [e93c463888203afc2091845308f946ba],
PUP.Optional.ConvertAd, C:\Windows\Temp\E487.tmp, Quarantined, [eb3a0a747e2a3afcbdf43b9c43be47b9],
PUP.Optional.ConvertAd, C:\Windows\Temp\F3A8.tmp, Quarantined, [d64fc3bb4662fa3c5f52c61147bae61a],
PUP.Optional.ConvertAd, C:\Windows\Temp\F57A.tmp, Quarantined, [ea3b0579fdabfc3a8829c017a65ba858],
PUP.Optional.ConvertAd, C:\Windows\Temp\F7B9.tmp, Quarantined, [90952b534a5e9d99506186517e83f10f],
PUP.Optional.ConvertAd, C:\Windows\Temp\F9AF.tmp, Quarantined, [1c09037bc3e5a1959a17b324a75ad828],
PUP.Optional.ConvertAd, C:\Windows\Temp\6C92.tmp, Quarantined, [0520bbc308a01e18ad04def9a75add23],
PUP.Optional.ConvertAd, C:\Windows\Temp\B2B5.tmp, Quarantined, [cf565b23743490a67e3329ae728fc23e],
PUP.Optional.ConvertAd, C:\Windows\Temp\B5EA.tmp, Quarantined, [a3822d51a305b97dc0f131a68c7560a0],
PUP.Optional.ConvertAd, C:\Windows\Temp\B8DC.tmp, Quarantined, [f035cdb10f992e0804adc90ef50c60a0],
PUP.Optional.ConvertAd, C:\Windows\Temp\BCE2.tmp, Quarantined, [35f0760888200d2939781bbc837ed030],
PUP.Optional.ConvertAd, C:\Windows\Temp\BE87.tmp, Quarantined, [2df8a5d9f5b3ce68b3fe983f1ce508f8],
PUP.Optional.ConvertAd, C:\Windows\Temp\C08C.tmp, Quarantined, [95909de1dfc905310fa2af2844bd16ea],
PUP.Optional.ConvertAd, C:\Windows\Temp\C34A.tmp, Quarantined, [80a5c7b7981088aec4ed7d5a0ef3b14f],
PUP.Optional.ConvertAd, C:\Windows\Temp\C67F.tmp, Quarantined, [1411f7877f293006951c25b226dbc63a],
PUP.Optional.ConvertAd, C:\Windows\Temp\C7AE.tmp, Quarantined, [0421c6b8e2c6a096862beee9b051fb05],
PUP.Optional.ConvertAd, C:\Windows\Temp\D24F.tmp, Quarantined, [2302dda1e1c77abc08a96572ce332fd1],
PUP.Optional.ConvertAd, C:\Windows\Temp\D382.tmp, Quarantined, [ad78fe804d5b3bfbe0d192454ab73ac6],
PUP.Optional.ConvertAd, C:\Windows\Temp\D3F4.tmp, Quarantined, [9293c0be51575adc6d445a7da16044bc],
Adware.Agent.WFI, C:\Windows\Temp\DC50.tmp, Quarantined, [a97c542a703877bf5448bd45db27cf31],
PUP.Optional.ConvertAd, C:\Windows\Temp\6D5A.tmp, Quarantined, [ac797905d5d339fd8130cf0817ea758b],
PUP.Optional.ConvertAd, C:\Windows\Temp\6DC9.tmp, Quarantined, [d5505e202a7e63d3aa07c3147e83ee12],
PUP.Optional.ConvertAd, C:\Windows\Temp\765C.tmp, Quarantined, [a481c1bd02a6171fb8f937a0e91852ae],
PUP.Optional.ConvertAd, C:\Windows\Temp\766E.tmp, Quarantined, [4dd8c1bd297f60d6436e23b4bf4225db],
PUP.Optional.ConvertAd, C:\Windows\Temp\7775.tmp, Quarantined, [2cf9c7b7a5031224bbf6b42345bc17e9],
PUP.Optional.ConvertAd, C:\Windows\Temp\7957.tmp, Quarantined, [49dc621c872143f3d0e1983fc938847c],
PUP.Optional.ConvertAd, C:\Windows\Temp\7B22.tmp, Quarantined, [bd68007e5157cf67e2cf3f98b34e51af],
PUP.Optional.ConvertAd, C:\Windows\Temp\7CC5.tmp, Quarantined, [4adbf688c0e87db95b56aa2d35ccb848],
PUP.Optional.ConvertAd, C:\Windows\Temp\7DE3.tmp, Quarantined, [8c9905792d7b0135a20f4f88917032ce],
PUP.Optional.ConvertAd, C:\Windows\Temp\7E0A.tmp, Quarantined, [32f3f5896642b97d7d34934418e9a858],
PUP.Optional.ConvertAd, C:\Windows\Temp\7E1E.tmp, Quarantined, [d2539fdfacfc77bf04ad6374bb468a76],
PUP.Optional.ConvertAd, C:\Windows\Temp\7EDB.tmp, Quarantined, [3ee74539fdabbf777f328354ac5556aa],
PUP.Optional.ConvertAd, C:\Windows\Temp\84FF.tmp, Quarantined, [0124dea08226eb4b2b867b5ce819be42],
PUP.Optional.ConvertAd, C:\Windows\Temp\891F.tmp, Quarantined, [e34268164c5c2b0b7a37a3343ac720e0],
PUP.Optional.ConvertAd, C:\Windows\Temp\8940.tmp, Quarantined, [70b52b53852384b22e837c5be0219967],
PUP.Optional.ConvertAd, C:\Windows\Temp\8B38.tmp, Quarantined, [ba6b92ec8523ab8bc1f013c4e0211ce4],
PUP.Optional.ConvertAd, C:\Windows\Temp\8BFE.tmp, Quarantined, [02233d41aff9cb6b8f22efe8956c6d93],
PUP.Optional.ConvertAd, C:\Windows\Temp\8C86.tmp, Quarantined, [0025dda1495fd165dc50f76acb3733cd],
PUP.Optional.ConvertAd, C:\Windows\Temp\8FEC.tmp, Quarantined, [4ed71f5f9e0a48eea908637432cfdf21],
PUP.Optional.ConvertAd, C:\Windows\Temp\90FE.tmp, Quarantined, [061f9be3e6c256e08d244394966b946c],
PUP.Optional.ConvertAd, C:\Windows\Temp\9194.tmp, Quarantined, [4adbef8f4266112509a8c0173cc5a65a],
PUP.Optional.ConvertAd, C:\Windows\Temp\944A.tmp, Quarantined, [91942559792f9d99377a1cbbb24fd12f],
PUP.Optional.ConvertAd, C:\Windows\Temp\9AEF.tmp, Quarantined, [a184f48a9e0a04327839c611bf420ff1],
PUP.Optional.ConvertAd, C:\Windows\Temp\A1D1.tmp, Quarantined, [39ec5a24f7b1c373674a21b6b44d04fc],
PUP.Optional.ConvertAd, C:\Windows\Temp\A1F1.tmp, Quarantined, [2500720cb3f551e5169b3a9df40da45c],
PUP.Optional.ConvertAd, C:\Windows\Temp\A593.tmp, Quarantined, [75b0e698feaa65d1852c587fa65bfc04],
PUP.Optional.ConvertAd, C:\Windows\Temp\AAE1.tmp, Quarantined, [30f53747654363d3b7756bf64eb402fe],
PUP.Optional.ConvertAd, C:\Windows\Temp\AC01.tmp, Quarantined, [9e879ee0e7c16ec828896176bd44649c],
Adware.Elex, C:\Windows\Temp\nsiF682.tmp\yacqq.exe, Quarantined, [57ceea94b1f76fc77a265d5943bd13ed],
Adware.Elex, C:\Windows\Temp\wea453C.tmp\yacqq.exe, Quarantined, [36ef007e4860d561da29d9e9847c27d9],
PUP.Optional.Elex, C:\Windows\Temp\ist2A2C.tmp\saberBox.exe, Quarantined, [33f28bf33d6bcb6b72331443659b8d73],
Adware.Elex, C:\Windows\Temp\ist340B.tmp\Archer.dll, Quarantined, [032294ea1098f640d01d52483ac6dd23],
Adware.Elex, C:\Windows\Temp\ist340B.tmp\uvcins.msi, Quarantined, [9a8b136bf3b5ab8b2ef2efbee0204eb2],
PUP.Optional.Elex, C:\Windows\Temp\ist515B.tmp\saberBox.exe, Quarantined, [5ec70a74317795a1990c2f2867999c64],
PUP.Optional.Elex, C:\Windows\Temp\ist515B.tmp\tools\saber.exe, Quarantined, [1b0adf9f9c0c0036287d8dcaa65a15eb],
PUP.Optional.Elex, C:\Windows\Temp\ist515B.tmp\tools\yasdwd.exe, Quarantined, [190c17678424c96d0e9770e7a25e5da3],
PUP.Optional.Elex, C:\Windows\Temp\ist7139.tmp\saberBox.exe, Quarantined, [1f06c1bd693f55e133722f28d12fdb25],
PUP.Optional.Elex, C:\Windows\Temp\ist7139.tmp\tools\saber.exe, Quarantined, [59cc46381692f34355505700dd234bb5],
PUP.Optional.Elex, C:\Windows\Temp\ist7139.tmp\tools\yasdwd.exe, Quarantined, [1d08522c3e6a6acc376e6deaea16c33d],
Adware.Elex, C:\Windows\Temp\istFAD1.tmp\de_svr.exe, Quarantined, [46df91edadfbc76fc83b06c48779cd33],
Adware.Elex, C:\Windows\Temp\istFAD1.tmp\saberBox.exe, Quarantined, [0a1be698f5b3aa8ca880ed7522de8080],
Adware.Elex, C:\Windows\Temp\wea102D.tmp\yacqq.exe, Quarantined, [e1444e30f3b5db5b43c00db59c64d62a],
Adware.Elex, C:\Windows\Temp\wea39E7.tmp\yacqq.exe, Quarantined, [b075a0de8f193303fb08635f6997748c],
Adware.Elex, C:\Windows\Temp\nsi4394.tmp\yacqq.exe, Quarantined, [65c0b3cb2880cb6bddc35f57e719847c],
Adware.Elex, C:\Windows\Temp\nsi448E.tmp\update.dll-201611021738.dll.exe, Quarantined, [5cc981fd2385ad89f70ccff3bf419070],
Adware.Elex, C:\Windows\Temp\nsi448E.tmp\yacqq.exe, Quarantined, [f233a9d538705fd745be6f536898ea16],
Adware.Elex, C:\Windows\Temp\nsi4845.tmp\update.dll-201611211705.dll.exe, Quarantined, [9491a1ddbeeaf1455e8c327b5ea28e72],
Adware.Elex, C:\Windows\Temp\nsi4845.tmp\yacqq.exe, Quarantined, [d451324ca701a0968f11694dd52b9d63],
Adware.Elex, C:\Windows\Temp\nsi49CE.tmp\update.dll-201612121644.dll.exe, Quarantined, [a5808bf3b1f742f4812b89232ad6d42c],
Adware.Elex, C:\Windows\Temp\nsi4F18.tmp\de_svr.exe, Quarantined, [df4636484d5b072f48cd69435fa10df3],
Adware.Elex, C:\Windows\Temp\nsi4F18.tmp\update.dll-201612231551.dll.exe, Quarantined, [d253542a6b3d37ff9d787834ec1438c8],
Adware.Elex, C:\Windows\Temp\nsi4F18.tmp\yacqq.exe, Quarantined, [84a10a74a9ffce68a360249e42be629e],
PUP.Optional.Elex, C:\Windows\Temp\nsi5B96.tmp\yasdwd.exe, Quarantined, [55d096e8e2c693a3485d97c0de22cf31],
Adware.Elex, C:\Windows\Temp\nsi6354.tmp\update.dll-201612281751.dll.exe, Quarantined, [cc59ee900d9b5ed85fa4853d6a963ec2],
Adware.Elex, C:\Windows\Temp\nsi6354.tmp\yacqq.exe, Quarantined, [35f04d31ceda16207390bd051ae63ec2],
Adware.Elex, C:\Windows\Temp\nsiAB35.tmp\yacnvd.exe, Quarantined, [42e35b2336724cea9e025066f10fb54b],
Adware.Elex, C:\Windows\Temp\nsiDB06.tmp\update.dll-201611291808.dll.exe, Quarantined, [3ee76e102b7d3006a041d3b9fb05d62a],
Adware.Elex, C:\Windows\Temp\nsiEF52.tmp\QQBrowserFrame.dll, Quarantined, [28fd7a04faae2e081d89cdf79f61be42],
Adware.Elex, C:\Windows\Temp\nsiEF52.tmp\update.dll-201610171344.dll.exe, Quarantined, [1312a3dbfaaec373b1f5dde7f0106d93],
Adware.Elex, C:\Windows\Temp\wea56C9.tmp\yacqq.exe, Quarantined, [a58087f7fcaccd69897a784a06fa40c0],
Adware.Elex, C:\Windows\Temp\wea5A52.tmp\yacqq.exe, Quarantined, [9c891d613870fa3c16ed437f05fb1fe1],
Adware.Elex, C:\Windows\Temp\weaFEFE.tmp\yacqq.exe, Quarantined, [b66fbfbfa1078ea85fa4c20031cff010],
Adware.WinArcher, C:\Windows\Temp\oua209C.tmp\Archer.dll, Quarantined, [e045c8b6c8e087afb4433176a35de818],
Adware.Elex, C:\Windows\Temp\oua209C.tmp\QQBrowserFrame.dll, Quarantined, [cf56c8b67b2d2c0aabfbd9eb7f816f91],
Adware.Elex, C:\Windows\Temp\oua5AB1.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [7baaa2dcd3d5280e9b0b596bc83837c9],
Adware.Elex, C:\Windows\Temp\oua5FEC.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [6db8cab4dbcd5bdb8224e2e27d83a25e],
Adware.Elex, C:\Windows\Temp\oua5FEC.tmp\secondu71\uvcSetup.msi, Quarantined, [58cdcdb1ebbd78be33195345bc4411ef],
Adware.Elex, C:\Windows\Temp\oua60AB.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [64c127576543eb4bb8eea81c7f81aa56],
Adware.Elex, C:\Windows\Temp\oua68C2.tmp\Archer.dll, Quarantined, [180d314dacfced492181efee16ea0bf5],
Adware.Elex, C:\Windows\Temp\oua68C2.tmp\QQBrowserFrame.dll, Quarantined, [e540720c06a2191d386e398b59a7d62a],
Adware.Elex, C:\Windows\Temp\oua693F.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [2ff6ee907c2ca78f396d685cd52bdb25],
Adware.Elex, C:\Windows\Temp\oua6A49.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [ba6b8af4d7d17cba3d69bc0837c97987],
Adware.Elex, C:\Windows\Temp\oua6D44.tmp\QQBrowserFrame.dll, Quarantined, [db4a66187434979fd4d221a3c739ae52],
Adware.Elex, C:\Windows\Temp\oua758E.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [8f96d8a6f3b571c5f5b1fcc8c9370df3],
Adware.Elex, C:\Windows\Temp\oua7B58.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [a580c9b5c4e468ce1096517330d01ce4],
Adware.Elex, C:\Windows\Temp\ouaCC50.tmp\secondu71\QQBrowserFrame.dll, Quarantined, [63c28ef0b2f6270fabfbd7edc33dfb05],
Adware.Elex, C:\ProgramData\behbe\yacqq.exe, Quarantined, [57ce1569b1f74de9bbe5892d976927d9],
Adware.Elex, C:\ProgramData\bfibe\yacqq.exe, Quarantined, [ac795e204d5b2115cbd5e2d4da269f61],
Adware.Elex, C:\ProgramData\cfibf\yacqq.exe, Quarantined, [e0452b539b0d52e4fc07665cec144ab6],
Adware.Elex, C:\ProgramData\cficf\Gubed.exe, Quarantined, [0e17d9a5f1b783b37a0abf207789f10f],
Adware.Elex, C:\ProgramData\cficf\yacqq.exe, Quarantined, [9a8b4e30b3f577bf23e05e64ab55d42c],
Adware.Elex, C:\ProgramData\ChelfNotify\chrome_elf.dll, Quarantined, [cd5816688e1a91a57620e2a13ec2926e],
Adware.Elex, C:\ProgramData\jcfic\yacnvd.exe, Quarantined, [071e89f51e8a64d2b6eab204ab55d42c],
Adware.Elex, C:\ProgramData\ficfi\yacqq.exe, Quarantined, [b372d4aa723645f17390a61cf70940c0],
PUP.Optional.Linkury, C:\Users\Niko\AppData\Roaming\Relex.bin, Quarantined, [b86da1dd1a8e6acc62b8b4b324dcd42c],
PUP.Optional.LogicHandler, C:\Users\Niko\AppData\Roaming\Tres-Fax.bin, Quarantined, [60c5601e5355082e6cf8eb2fdd245ca4],
Adware.Agent, C:\Users\Niko\AppData\Roaming\Tresfan.exe, Quarantined, [63c277072880f244c2e98fe813ed03fd],
PUP.Optional.Elex, C:\Windows\System32\Tasks\Coerwcult Center, Quarantined, [6db84e30a701320430dabd4699674cb4],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe, Delete-on-Reboot, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\AccessibleMarshal.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-file-l1-2-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-file-l2-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-handle-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-heap-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-interlocked-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-libraryloader-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-localization-l1-2-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-memory-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-namedpipe-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-processenvironment-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-processthreads-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-processthreads-l1-1-1.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-rtlsupport-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-string-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-synch-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-synch-l1-2-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-sysinfo-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-timezone-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-util-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-conio-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-convert-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-environment-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-filesystem-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-heap-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-locale-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-console-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-datetime-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-debug-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-errorhandling-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-multibyte-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-private-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-process-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-runtime-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-stdio-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-string-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-time-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-utility-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\application.ini, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-file-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-core-profile-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\api-ms-win-crt-math-l1-1-0.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\breakpadinjector.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\lgpllibs.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\omni.ja, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\crashreporter.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\crashreporter.ini, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\d3dcompiler_47.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\dependentlibs.list, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\fbox.bin, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\Firefox.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\firefox.VisualElementsManifest.xml, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\freebl3.chk, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\freebl3.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\IA2Marshal.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\libEGL.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\libGLESv2.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\maintenanceservice.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\maintenanceservice_installer.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\mozavcodec.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\mozavutil.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\mozglue.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\msvcp140.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nss3.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nssckbi.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nssdbm3.chk, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\nssdbm3.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\platform.ini, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\plugin-container.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\plugin-hang-ui.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\precomplete, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\qipcap.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\removed-files, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\softokn3.chk, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\softokn3.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\ucrtbase.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\update-settings.ini, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\updater.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\updater.ini, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\vcruntime140.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\wow_helper.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\xul.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\blocklist.xml, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\chrome.manifest, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\crashreporter-override.ini, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\omni.ja, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\components\browsercomps.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\components\components.manifest, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\features\[email protected], Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\features\[email protected], Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\features\[email protected], Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\features\[email protected], Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\VisualElements\VisualElements_150.png, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\browser\VisualElements\VisualElements_70.png, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\defaults\pref\channel-prefs.js, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\dictionaries\en-US.aff, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\dictionaries\en-US.dic, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\fonts\EmojiOneMozilla.ttf, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\gmp-clearkey\0.1\clearkey.dll, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\gmp-clearkey\0.1\clearkey.info, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Ghokswa, C:\Program Files (x86)\Firefox\uninstall\helper.exe, Quarantined, [1411037b5157c2740774f04110f009f7],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\KuaiZip.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\7z.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\DuiLib.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\finderlib.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\kuaizipUpdateChecker.dll, Delete-on-Reboot, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\KZFormat.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\KZModule.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\KZReport.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\KZTui.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\Mount.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\MountCore.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\Uninst.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\Update.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\UpdateChecker.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\lang\en_lang.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X86\sfx\kzsetup_en.sfx, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\7zNew.dat, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\KuaiZip Website.url, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\KzNew.dat, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\readme.txt, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\SLDefault.xml, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\ZipNew.dat, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\data\slimdata.dat, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language\en\kuaizip.xml, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language\en\KZipShell.xml, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language\en\kzmount2.xml, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language\en\kztui.xml, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\language\en\uninst.xml, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\7z.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\KuaiZipDrive.sys, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\KZFormat.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\KZipShell.dll, Delete-on-Reboot, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\KZModule.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\KZMount2.exe, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\Mount.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\MountCore.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Program Files (x86)\KuaiZip\X64\lang\en_lang.dll, Quarantined, [a283f58905a37db91433b59cb54b8f71],
PUP.Optional.Kuaizip, C:\Windows\System32\Tasks\KuaiZip_Update, Quarantined, [30f51f5ffdab12246f55f65f956b758b],
PUP.Optional.MyLucky123.ShrtCln, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\searchplugins\mylucky123.xml, Quarantined, [6cb9433b4c5c102638f4a6b18c74b34d],
PUP.Optional.Interhop, C:\Program Files (x86)\InterHop\InterHop.exe, Delete-on-Reboot, [f0353549d1d7e94da7d5c19a2bd55fa1],
PUP.Optional.Interhop, C:\Program Files (x86)\InterHop\main, Quarantined, [f0353549d1d7e94da7d5c19a2bd55fa1],
PUP.Optional.Elex, C:\Program Files (x86)\WinArcher\Archer.dll, Delete-on-Reboot, [27fef18d3078fb3b210e92e06f917090],
PUP.Optional.Elex, C:\Program Files (x86)\WinArcher\Packet.dll, Quarantined, [27fef18d3078fb3b210e92e06f917090],
PUP.Optional.Elex, C:\Users\Niko\AppData\Roaming\Firefox\Firefox\Profiles\xjoysaf1.default\extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi, Quarantined, [998c98e64e5a251100c86510619fc53b],
PUP.Optional.Elex, C:\Users\Niko\AppData\Roaming\Firefox\Firefox\Profiles\xjoysaf1.default\extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi, Quarantined, [998c3945edbba0966068f48121dfaa56],
PUP.Optional.Elex, C:\ProgramData\WinSAPSvc\WinSAP.dll, Delete-on-Reboot, [6db86519d8d061d53e57de9b03fda15f],
PUP.Optional.Amisites.ShrtCln, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\searchplugins\amisites.xml, Quarantined, [48dd2e507f29e45238db435ae21eca36],
PUP.Optional.WinTool, C:\Windows\System32\Tasks\WinTOOL, Quarantined, [80a52b5301a7eb4b8745b404639d8d73],
Adware.Elex.Generic, C:\Users\Niko\AppData\Roaming\gjdgj\UvConverter.exe, Delete-on-Reboot, [1c09a4da4365c5710d4b01c015ebb050],
Adware.Elex.Generic, C:\Users\Niko\AppData\Roaming\gjdgj\main, Quarantined, [1c09a4da4365c5710d4b01c015ebb050],
Adware.Elex.Generic, C:\Users\Niko\AppData\Roaming\gjdgj\UniKeyNT.exe, Quarantined, [1c09a4da4365c5710d4b01c015ebb050],
PUP.Optional.Linkury.Generic, C:\Users\Niko\AppData\Roaming\agent.dat, Quarantined, [8f9615696345ea4cdaa4c30bd72941bf],
Adware.Elex, C:\Program Files (x86)\Gubed\GubedZL.dll, Delete-on-Reboot, [4ed7ed9146625cdaca258457bd43c13f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\set.exe.config, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\Config.json, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\System.Data.SQLite.dll, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\System.Data.SQLite.Linq.dll, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\System.Data.SQLite.xml, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\X64\SQLite.Interop.dll, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LogicHandler, C:\ProgramData\Logic Handler\X86\SQLite.Interop.dll, Quarantined, [cd5890eeabfde84e5730b9fa2ad8619f],
PUP.Optional.LuckyBrowse, C:\Windows\System32\Tasks\LuckyBrowse, Quarantined, [6db846388e1a22143c454843d0339070],
PUP.Optional.Linkury, C:\Users\Niko\AppData\Roaming\md.xml, Quarantined, [e83d334b16922d0921c3faa33fc402fe],
PUP.Optional.Linkury, C:\Users\Niko\AppData\Roaming\noah.dat, Quarantined, [58cd83fb1a8ef343e203d4c944bf6898],
PUP.Optional.Linkury, C:\Users\Niko\AppData\Roaming\uninstall_temp.ico, Quarantined, [8a9b6e10beeadc5ac125712c5ca7827e],
PUP.Optional.Linkury, C:\Windows\Temp\Smartbar\Ronnix.ico, Quarantined, [061fa3dba206e4521ccae4bd25de649c],
PUP.Optional.Linkury, C:\Windows\Temp\Smartbar\Stockdax.ico, Quarantined, [061fa3dba206e4521ccae4bd25de649c],
PUP.Optional.Linkury.ACMB1, C:\Windows\SysWOW64\findit.xml, Quarantined, [d64f2c52f4b42b0b4b30930fd72c6d93],
PUP.Optional.GsearchFinder, C:\Users\Niko\AppData\Roaming\Profiles\jqishkonerszguent\extensions\@90B817C8-8A5C-413B-9DDD-B2C61ED6E79A.xpi, Quarantined, [67becbb3f8b06ec8dc4b792f51b28977],
PUP.Optional.Linkury.Gen, C:\Users\Niko\AppData\Roaming\Tresfan.tst, Quarantined, [ea3b0e7022863006d57317f87b89ba46],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\9.3.6494.400.manifest, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\BrowserUpdate.exe, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\InHop.msi, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\amuleins.msi, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\Archer.dat, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\Archer.dll, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\ClearLog.dll, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\de_svr.exe, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\Gubed.exe, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\hhhhh.exe, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\Lancer.dll, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\lanceruse.dat, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\regkey.exe, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\ttttt.exe, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\WinSAP.dll, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.Elex, C:\Program Files (x86)\Crecult\_ALLOWDEL_3aa784d\{5A711AEB-93A1-4F09-9E56-7E6C7FA86266}, Quarantined, [cf560c725454c37369ade3291ee29868],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\uninstall.exe, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\version, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\init.html, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\.eslintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\CHANGELOG.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\CONTRIBUTING.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\request.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\auth.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\cookies.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\getProxyFromURI.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\har.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\helpers.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\multipart.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\oauth.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\querystring.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\redirect.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\lib\tunnel.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\.bin\har-validator, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\.bin\har-validator.cmd, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\.bin\uuid, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\.bin\uuid.cmd, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws-sign2\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws-sign2\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws-sign2\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws-sign2\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\.tern-port, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\aws4.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\example.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\CONTRIBUTORS, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\lib\lru-cache.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\test\basic.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\test\foreach.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\test\memory-leak.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\aws4\node_modules\lru-cache\test\serialize.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\.jshintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\bl.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\LICENSE.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\.zuul.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\duplex.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\passthrough.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\readable.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\transform.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\writable.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\doc\stream.markdown, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\doc\wg-meetings\2015-01-30.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib\_stream_duplex.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib\_stream_passthrough.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib\_stream_readable.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib\_stream_transform.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\lib\_stream_writable.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\float.patch, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\core-util-is\lib\util.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits\inherits.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits\inherits_browser.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\inherits\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\component.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\isarray\build\build.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args\license.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\process-nextick-args\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\string_decoder\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate\browser.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate\History.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate\node.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\node_modules\readable-stream\node_modules\util-deprecate\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\bl\test\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\caseless\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\caseless\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\caseless\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\caseless\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\caseless\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\License, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\Readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\lib\combined_stream.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\License, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\Makefile, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\Readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\combined-stream\node_modules\delayed-stream\lib\delayed_stream.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\.eslintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\.jscs.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\CHANGELOG.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\component.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\extend\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\forever-agent\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\forever-agent\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\forever-agent\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\forever-agent\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\License, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\Readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\lib\browser.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\lib\form_data.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\CHANGELOG.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\dist\async.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\dist\async.min.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\form-data\node_modules\async\lib\async.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\bin\har-validator, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\async.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\error.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\runner.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\cache.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\cacheEntry.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\content.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\cookie.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\creator.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\entry.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\har.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\log.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\page.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\pageTimings.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\postData.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\record.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\request.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\response.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\lib\schemas\timings.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\ansi-styles\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\ansi-styles\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\ansi-styles\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\ansi-styles\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\escape-string-regexp\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\escape-string-regexp\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\escape-string-regexp\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\escape-string-regexp\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules\ansi-regex\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules\ansi-regex\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules\ansi-regex\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\has-ansi\node_modules\ansi-regex\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules\ansi-regex\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules\ansi-regex\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules\ansi-regex\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\strip-ansi\node_modules\ansi-regex\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\supports-color\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\supports-color\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\supports-color\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\chalk\node_modules\supports-color\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\History.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\Readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\commander\node_modules\graceful-readlink\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\example.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\formats.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\require.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\example.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-function\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property\is-property.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\generate-object-property\node_modules\is-property\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer\jsonpointer.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\jsonpointer\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\.jshintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\immutable.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\LICENCE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\Makefile, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\mutable.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\node_modules\xtend\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\misc.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\fixtures\cosmic.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\additionalItems.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\additionalProperties.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\allOf.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\anyOf.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\bignum.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\default.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\definitions.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\dependencies.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\enum.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\format.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\items.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\maximum.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\maxItems.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\maxLength.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\maxProperties.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\minimum.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\minItems.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\minLength.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\minProperties.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\multipleOf.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\not.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\nullAndFormat.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\nullAndObject.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\oneOf.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\pattern.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\patternProperties.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\properties.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\ref.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\refRemote.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\required.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\type.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\is-my-json-valid\test\json-schema-draft4\uniqueItems.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules\pinkie\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules\pinkie\license, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules\pinkie\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\har-validator\node_modules\pinkie-promise\node_modules\pinkie\readme.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\bower.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\component.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\dist\client.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\example\usage.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\images\hawk.png, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\images\logo.png, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib\browser.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib\client.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib\crypto.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib\server.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\lib\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\CONTRIBUTING.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\images\boom.png, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\boom\test\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\cryptiles\test\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\CONTRIBUTING.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\images\hoek.png, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\lib\escape.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\escaper.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\modules\ignore.txt, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\modules\test1.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\modules\test2.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\hoek\test\modules\test3.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\Makefile, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\examples\offset.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\examples\time.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\node_modules\sntp\test\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\browser.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\client.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\crypto.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\readme.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\server.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\uri.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\hawk\test\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\.dir-locals.el, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\CHANGES.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\http_signing.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\lib\parser.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\lib\signer.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\lib\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\lib\verify.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin\sshpk-conv, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin\sshpk-conv.cmd, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin\sshpk-sign, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin\sshpk-sign.cmd, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin\sshpk-verify, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\.bin\sshpk-verify.cmd, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus\assert.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus\AUTHORS, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus\CHANGES.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\assert-plus\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\CHANGES.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\lib\jsprim.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\.gitmodules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\jsl.node.conf, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\Makefile, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\Makefile.deps, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\Makefile.targ, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\examples\simple.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\extsprintf\lib\extsprintf.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-zyp-json-schema-03.xml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-zyp-json-schema-04.xml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-00\hyper-schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-00\json-ref, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-00\links, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-00\schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-01\hyper-schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-01\json-ref, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-01\links, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-01\schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-02\hyper-schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-02\json-ref, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-02\links, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-02\schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\hyper-schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\json-ref, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\links, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples\address, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples\calendar, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples\card, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples\geo, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-03\examples\interfaces, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-04\hyper-schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-04\links, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\draft-04\schema, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\lib\links.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\lib\validate.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\json-schema\test\tests.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\.gitmodules, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\jsl.node.conf, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\Makefile, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\Makefile.targ, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples\levels-verror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples\levels-werror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples\varargs.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples\verror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\examples\werror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\lib\verror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\tests\tst.inherit.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\tests\tst.verror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\jsprim\node_modules\verror\tests\tst.werror.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\bin\sshpk-conv, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\bin\sshpk-sign, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\bin\sshpk-verify, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\algs.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\dhe.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\ed-compat.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\errors.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\fingerprint.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\key.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\private-key.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\signature.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\ssh-buffer.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\auto.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\pem.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\pkcs1.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\pkcs8.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\rfc4253.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\ssh-private.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\lib\formats\ssh.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man\man1\sshpk-conv.1, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man\man1\sshpk-sign.1, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\man\man1\sshpk-verify.1, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber\errors.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber\reader.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber\types.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\lib\ber\writer.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\tst\ber\reader.test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\asn1\tst\ber\writer.test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\etc\dashdash.bash_completion.in, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\dashdash\lib\dashdash.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\lib\ec.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\lib\LICENSE-jsbn, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\ecc-jsbn\lib\sec.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\almond.0, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\almond.1, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\AUTHORS.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\jsdoc.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib\core.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib\curve255.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib\dh.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib\eddsa.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jodid25519\lib\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\example.html, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\example.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\jsbn\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\CHANGELOG.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\nacl-fast.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\nacl-fast.min.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\nacl.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\nacl.min.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\http-signature\node_modules\sshpk\node_modules\tweetnacl\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\is-typedarray\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\is-typedarray\LICENSE.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\is-typedarray\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\is-typedarray\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\is-typedarray\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\.jshintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\isstream.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\LICENSE.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\isstream\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\CHANGELOG.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\Makefile, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\stringify.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\test\mocha.opts, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\json-stringify-safe\test\stringify_test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\HISTORY.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db\db.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db\HISTORY.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\mime-types\node_modules\mime-db\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\bower.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\component.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\LICENSE.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\uuid.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\benchmark\bench.gnu, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\benchmark\bench.sh, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\benchmark\benchmark-native.c, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\benchmark\benchmark.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\benchmark\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\bin\uuid, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\test\compare_v1.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\test\test.html, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\node-uuid\test\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\oauth-sign\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\oauth-sign\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\oauth-sign\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\oauth-sign\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\oauth-sign\test.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\.eslintignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\.eslintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\bower.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\CHANGELOG.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\component.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\CONTRIBUTING.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\dist\qs.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\lib\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\lib\parse.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\lib\stringify.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\lib\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\test\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\test\parse.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\test\stringify.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\qs\test\utils.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\.npmignore, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\.travis.yml, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\example.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\LICENSE.txt, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\stringstream\stringstream.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib\cookie.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib\memstore.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib\pathMatch.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib\permuteDomain.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib\pubsuffix.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tough-cookie\lib\store.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tunnel-agent\.jshintrc, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tunnel-agent\index.js, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tunnel-agent\LICENSE, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tunnel-agent\package.json, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\app\node_modules\request\node_modules\tunnel-agent\README.md, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\credits.html, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\d3dcompiler_47.dll, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\ffmpegsumo.dll, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\icudtl.dat, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\libEGL.dll, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\libGLESv2.dll, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\nw.exe, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\nw.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\nwjc.exe, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\hr.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\am.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ar.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\bg.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\bn.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ca.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\cs.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\da.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\de.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\el.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\en-GB.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\en-US.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\es-419.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\es.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\et.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\fa.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\fi.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\fil.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\fr.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\gu.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\hi.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\hu.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\id.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\it.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\iw.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ja.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\kn.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ko.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\lt.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\lv.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ml.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\mr.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ms.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\nl.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\no.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\pl.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\pt-BR.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\pt-PT.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ro.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ru.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\sk.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\sl.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\sr.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\sv.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\sw.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\ta.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\te.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\th.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\tr.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\uk.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\vi.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\zh-CN.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.ContentPush, C:\Program Files (x86)\ContentPush\app\bin\locales\zh-TW.pak, Quarantined, [c75e235b9513ce68fb50ec26cd330ef2],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\client.time, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\mobo.uuid, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Source.mu, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Data\mobogenie_u_user_dl.mg, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.MoboGenie, C:\Users\Niko\AppData\Local\Mobogenie\Version\CacheVersion\release-update.xml, Quarantined, [7aab7905d9cf88aefae2d660817f748c],
PUP.Optional.Linkury, C:\ProgramData\NetworkPacketManitor\Config.xml, Quarantined, [4adb7905baee8caa0bafbaae51af0ff1],
PUP.Optional.Linkury, C:\ProgramData\NetworkPacketManitor\Nettrans.exe.config, Quarantined, [4adb7905baee8caa0bafbaae51af0ff1],
PUP.Optional.Elex, C:\Program Files (x86)\WinSaber\SaberSvcLog.log, Quarantined, [bb6a6d11842478be3064f583837d7987],
PUP.Optional.Elex, C:\ProgramData\ChelfNotify\9.3.6494.400.manifest, Quarantined, [8c995d218f1916201aaa017930d009f7],
PUP.Optional.Elex, C:\ProgramData\ChelfNotify\BIT5DE3.tmp, Quarantined, [8c995d218f1916201aaa017930d009f7],
PUP.Optional.Elex, C:\ProgramData\ChelfNotify\BIT5EE5.tmp, Quarantined, [8c995d218f1916201aaa017930d009f7],
PUP.Optional.Elex, C:\ProgramData\ChelfNotify\BrowserUpdate.exe, Quarantined, [8c995d218f1916201aaa017930d009f7],
PUP.Optional.Elex, C:\ProgramData\ChelfNotify\chrome_elf.dll, Quarantined, [8c995d218f1916201aaa017930d009f7],
PUP.Optional.Kuaizip, C:\Users\Niko\AppData\Roaming\KuaiZip\KuaiZip.log, Quarantined, [81a4542ae2c635017f60485f8f71e020],
Adware.MoboGenie, C:\Program Files (x86)\Mobogenie\ok.htm, Quarantined, [5ec7a7d7d9cf80b6dd51e4ddba464eb2],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\preference.ini, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\iDesk\desk.ini, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log\install.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log\iSafeTray.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log\logreport.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log\uninstall.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log\upgrade.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\ipcdl.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\ipcproxy.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeBS.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeKrnlCall.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeKrnlMonCall.log, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeSvc.LOG, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeSvc2.LOG, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeTaskHelper.LOG, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Users\Niko\AppData\Roaming\Elex-tech\YAC\log_bak\iSafeTHlp64.LOG, Delete-on-Reboot, [e0458af4891f7fb79317e7af32d07d83],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafembp.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\bugreport.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\eDelayinfo.edb, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iddmgr.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iDesk.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iDskDllPatch.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iDskDllPatch64.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ipcdl.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafe.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafeadfv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafetbv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeTHlp.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeTHlp64.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iStart.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemclv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemgc.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeMon.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeMon64.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemoptv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemsmv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeNetFilter.sys, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafesmgr.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafesopt.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafesptv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafesv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libeay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\libpng.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\main, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcp110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\msvcr110.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ouilibx.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\sqlite3x64.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\ssleay32.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\uninstall.inst, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeBugReport.exe, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafechlp.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafeclc.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafeclcv.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlBoot.sys, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall64.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlShell.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\isafemadwc.dll, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\ccc.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\customscan.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\dbucg.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\hyperscan.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\isafe.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\quickscan.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\scanfilter.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\ucg.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\cfg\updatedb.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\adb.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\bas.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\bts.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\bwd.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\cls.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\clx.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\eas.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\ess.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\fst.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\gcs.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\gcx.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\hs.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\mic.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\nlu.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\plx.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\rms.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\sta.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\stu.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\tbc.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\uis.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\was.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\data\ysm.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\cache\index.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\defs\bs.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\defs\sr.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\defs\vn.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\engine\defs\ws.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\font\segoeui.ttf, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\font\segoeuib.ttf, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\AdBlock_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\adwclean_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\bugreport.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\clean_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\clean_scanfilter_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\common_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\dsk_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\fblang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\iSafeRKScanShell.lang, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\iSafeSet_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\Lottery_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\NewVirusScan_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\new_clean_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\optimize_lang2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\PCClinicUI_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\plugin_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\SafeProtect_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\shell.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\softmgr_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\startup_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\taskhelper_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\ToolBox_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\tray2_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_appstore_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_desk_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_feedback_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_floaty_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_nodisturb_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_protect_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\trayplugin_startupassist_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\lang\uninstall_lang.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\bugreport.LOG, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\ipcproxy.log, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeBS.log, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeKrnlCall.log, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeKrnlMonCall.log, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeSvc.LOG, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeSvc2.LOG, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeTaskHelper.LOG, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\log\iSafeTHlp64.LOG, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\edit_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\AdblockToggle.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\adb_set.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\adb_set_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\adb_set_hide.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\adb_set_hide_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\adb_set_show.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\adb_set_show_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\Add.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\Beta.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\Delete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\FilterDesc.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\FilterDesc_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\lock_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\LogDetail.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\LogDetail_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\opt_arrow_down.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\popup_menu_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\popup_menu_itemskin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\Resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\unlocked_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\WhiteList.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\image\default\WhiteList_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\layout\default\AdBlockView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\AdBlock\style\Style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\about_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\activity.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\activity_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\appstore_new.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\appstore_refresh.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\BG.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\btn_set.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\check_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\check_indeterminate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\check_uncheck.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\cm_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\combo_browser_dropdown_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\connecting_anim.gif, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\dbup_dlg_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\dbup_dlg_bk_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\dbup_dlg_onekey_up_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\dbup_dlg_reboot_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\head_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\head_indeteminate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\head_unchecked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_adblock.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_adw_clean.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_appstore.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_avira.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_deep_clean.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_exam.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_netmon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_optimize.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_protect.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_recovery.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_softmgr.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_toolbox.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\icon_virusscan.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\if_block.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\if_prompt.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\if_question.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\if_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\language_selected_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\like.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\like_count.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\line1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\line2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\listctrlbtn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\menu_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\menu_bkg2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\menu_item_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\menu_nation_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\msgbox_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\number_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\number_bg2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\pop_sys_button2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\pop_sys_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\progressbar_anim.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\progressbar_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\progressbar_image.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\language_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\menu_setting_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\recovery.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\startmenu_deepclean.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\setting.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\setting_img_list.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\slidebutton_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\small_dl.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\small_download.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\small_new.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\small_progress.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\small_progress_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\special_line.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\sub_toggle_btn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\sys_imglist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\tab_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\updatedlg_ok_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_cheking.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_chk_err.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_chk_ok.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_client_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_downlodaing.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_error.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_latest.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\update_server_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\wifi_logo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\bk_bag.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\bk_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\bk_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\bk_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\btn_repair.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_adblock_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_back_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_cancel.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_do.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_number_0.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_health_number_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_health_number_pressed.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_health_plus_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_number_hover.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_number_hover_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_number_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_number_normal_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_number_pressed.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_number_pressed_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_ok_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_plus_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_rubbish_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_rubbish_icon_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_safe_protect_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_safe_protect_icon_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_scanning_mid.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_scanning_pic.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_scanning_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_softmgr_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_softmgr_icon_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_sys_opt_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_sys_opt_icon_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_tip_wnd_arrow_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_tip_wnd_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_tip_wnd_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_type_btn_bottom_line.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_bn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_gb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_health_bn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_health_kn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_health_mn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_kb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_kn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_mb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\green_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\icon_big_home.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\manual_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\manual_item.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\number_big_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\number_big_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\number_big_red2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\opt_arrow_down.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\opt_arrow_up.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\right_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\score_none.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\warning_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\warning_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\warning_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\warning_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\yellow_wrong.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_result_health_number_hover.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\exam_unit_mn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\image\new\exam\ignore_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\aboutdlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\dbupdatedlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\DemoApp.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\language_select.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\maindlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\msgbox.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\slide_button_wnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\tipwnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\layout\new\updatedlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\app\style\style_new.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\crash_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\detail_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\error_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\input.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\reset_yac_btn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\send_btn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\smell_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\sorry_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\sucess_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\wait.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\waitting_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\image\default\res\wait_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\layout\default\detailwnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\layout\default\mainwnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\bugreport\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_quick_clean_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_advance_item_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_advance_item_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_adware_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_auto_clean_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_clean_smile_face.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_full_scan_virus_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_junk_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_list_header_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_plugin_can_delete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_plugin_can_disable.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_plugin_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_plugin_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_plugin_type_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_privacy_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_quickclean_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_registry_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_reg_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_rubbish_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_scan_check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_scan_detail_dlg_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_share_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_sysmenu_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\cl_trace_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\opt_new_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\opt_rightkeymenu_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\opt_sendto_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_button_open.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_button_bk1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_button_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_button_bk3.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_button_bk4.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_button_bk5.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_button_bk6.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_box_select_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_default_image.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_eye_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_file_browser.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_path_edit.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_progress_animate.gif, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_pop_tipwnd_warnning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\clean_togbtn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\cl_combo_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\cl_down_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\cl_menu_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\cl_menu_item_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\image\default\clean_pop_res\cl_up_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout\default\NewCleanPFSettingDlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout\default\NewCleanPopDlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout\default\NewCleanView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout\default\ScanDetailDlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\layout\default\Tipswnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\clean\style\clean_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\head_unchecked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\msgbox_close_btn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\arrow_down.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\arrow_up.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\check_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\check_indeterminate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\check_uncheck.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\close_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\color_blue_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\color_green_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\color_red_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\color_yellow_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\common_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\common_dlg_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\common_faq_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\common_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\common_tip_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\feedback_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\head_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\head_indeteminate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\if_block.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\if_prompt.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\if_question.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\if_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\min_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\msgbox2_button_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\msgbox2_button_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\msgbox2_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\msgbox_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\msgbox_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\nation_icon_list.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\progressbar_anim.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\progressbar_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\progressbar_image.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\pvb_line.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\pvb_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\scanview_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\scan_check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\scan_complete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\scan_scanning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\scan_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\switch_button_off.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\switch_button_on.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\toggle_btn_pop_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\image\default\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\layout\msgbox.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\layout\msgbox2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\common\style\common_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_file_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\close_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_add_file_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_add_file_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_btn_bk1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_btn_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_complete_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_ctrl_close_btn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_edit_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_file_ctrl_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_live_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_msgbox_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_msgbox_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_pay_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_problem_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_report_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_suggestion_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_tip_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_wait_anim.gif, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_warning_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\fb_yac_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\image\default\tab_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\layout\default\feedback_view.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\layout\default\mainwnd2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\layout\default\msgbox.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\fbSkin\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg_list.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg\desk_bkg_1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg\desk_bkg_2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg\desk_bkg_3.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg\desk_bkg_4.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg\desk_bkg_5.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\desk_bkg\desk_bkg_default.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\foldericon\app.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\foldericon\file.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\foldericon\folder.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\foldericon\picture.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\add_list_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\add_list_til_line.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\app.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrange_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrow_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrow_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\btn_accelerate_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\button_delete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\button_selected.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\check_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\check_uncheck.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\cloud_flash.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\combo_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\combo_skin_op.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\customize.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\default_file.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\delete_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_all_import.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_bkg_default.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_btn_dkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_button_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_cmd_list.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_default_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_dlg_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_edit_light.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_fbar.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_import_arrow_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_import_arrow_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_import_button_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_import_gridctrl_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_import_icon_add_other.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_import_icon_list_add.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_list.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_loading.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_main_panel_edge.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_menu.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_more.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_pc.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_plus_import_bkg_a.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_plus_import_bkg_b.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_power_off.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_power_off_light.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_power_off_unlight.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\edit_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\edit_skin_op.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\file.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\focus_next.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\focus_prev.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\folder.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\icon_adblock_18-18.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\icon_adblock_22-22.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\deskbtnbk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_edit.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\desk_list_light.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\icon_arrange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_noad.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\new_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\pic-info.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\icon_Tip.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\idesk_pre_view.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\idesk_pre_view_a.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\import_scroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\improve_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\large_add_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\line-foot.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\list_scroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\logo_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menuitem_selbk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_accelerate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_help.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_import.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_open.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_quit.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_restore.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_sendto.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\menu_set.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\monitor_button_next.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\monitor_button_pre.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\mousechoose.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\mypc_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\new_icon_large.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\new_icon_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\new_icon_xp.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\normal_button_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\nothing.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\PageBtnBkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\PageBtnBkg_focus.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\PageNavigate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\pic-error.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\pic-question.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\pic-warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\picture.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\plus_action_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\search_box.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\search_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\search_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\selected.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\shutdown_button_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\shutdown_more_button_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\start_button_hover.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\start_panel_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\start_shutdown_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\switch_style.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_ctrl_panel.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_imglist.bmp, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_local_driver.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_lock.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_menu_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_net_connect.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_recycle.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_restart.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\sys_sleep.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tips_button_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\title_bar.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\user_account_default.bmp, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\WIN7_bjSmall_X.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\WIN7_bjSmall_Y.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\WIN7_bj_X.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\WIN7_bj_Y.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\win8_desk_16_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\win8_desk_32_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\XP_bj_hover.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\XP_bj_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\arrange_arrow_b.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\arrange_arrow_l.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\arrange_arrow_r.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\arrange_arrow_t.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\btn_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\btn_green_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\check_uncheck.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\arrangedesktop\main_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_firstrun_bottom.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_firstrun_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_firstrun_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_firstrun_top.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_introduce_bottom.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_introduce_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_introduce_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\desk_tip_introduce_top.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_add_focus.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_arrow_bottom.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_arrow_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_arrow_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_arrow_right_large.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_browser_focus.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_focus_mask_point.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_focus_mask_rect.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_item_drag.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_guide_item_focus.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\image\default\tip\tip_point.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\add_shortcut_tip.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\arrange_desktop.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\desk_bkg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\desk_taskbar_help_tip1.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\desk_taskbar_help_tip2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\main_import_icon.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\main_panel.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\main_setting.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\main_start.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\my_pc_menu.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\plus_import_icon.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\rename.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\layout\default\taskbar.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iDesk\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\about.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\adb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\bep.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\bth.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\dse.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\emailprotect.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\fw.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\general.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\iSafeSet_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\jfm.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\lang.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\lang_btn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\image\default\nation_icon_list.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\layout\default\iSafeSetView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\iSafeSet\style\iSafeSet_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_indeterminate.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_arrow_down.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_arrow_up.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_button_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_close_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_loading.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_logo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_minimum_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_num.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_num_percent.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_num_white.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_brush.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_complete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_dl_brush.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_dl_complete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_dl_start.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_install_brush.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_normal.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_op_complete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_picture_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_point.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_select.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_speed_bar.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_unable.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_unit_b.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_unit_gb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_unit_kb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_unit_mb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\new_clean_unselect.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\image\newclean\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\layout\newclean\NewCleanDlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\layout\newclean\tipsWnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\NewClean\style\new_clean_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_combo_bk_top.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\optimize_btn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\optimize_empty.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\optimize_restore_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_appsvc_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_arrow_down_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_arrow_up_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_boottime_nodata_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_combo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_combo_bk_bottom.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_combo_dropdown_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_menu_item_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_startup_app_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_sysmenu_def_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_syssvc_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_taskschedule_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_type_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\opt_vert_line.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\pop_OptDlg_BG.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\st_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\st_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\st_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\image\default\syssvc_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\layout\default\OptimizeView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\layout\default\optimize_popdlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\optimize2\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default\plugin_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default\plug_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default\plug_norm.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default\plug_sec_level.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default\plug_should_del.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\image\default\plug_should_dis.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\layout\default\PluginView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\plugin\style\plugin_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\empty.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\locked_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\bing_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\blank_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\bo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\bp.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\bw.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\cdbh.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\cdsh.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\chph.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\chrome_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\cseh.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\dp.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\edit_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\edit_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\edit_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\exam_dlg_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\exam_radio_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\exam_radio_unchecked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\firefix_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\fr.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\google_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\google_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\ie_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\iph.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\lastsession_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\lock_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\oh.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\opera_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\opt.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\opt_vert_line.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\popup_menu_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\popup_menu_itemskin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\pop_OptDlg_BG.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\pop_toggle_btn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\pwb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\query_btn_safe.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\SafeProtect_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\savebtn_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\syssvc_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\to.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\tp.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\tw.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\unlocked_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\yac_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\yahoo_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\image\default\yahoo_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\layout\default\examdlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\layout\default\SafeProtectView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\layout\default\SafeProtect_popdlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\SafeProtect\style\SafeProtect_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_check_arrow_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_close_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_collapse_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_expand_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_folder_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_opt_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_progbar_anim_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_progbar_indicator.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_progbar_indicator_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_search_box_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_search_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_software_def_ico_48.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_step_found.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_step_nofound.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_uninst_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_warning_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm2_whirling_pic.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_common_btn_bk1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_common_btn_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_menu_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_menu_item_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_remain_ctrl_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_software_def_ico_20.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\sm_warning_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\image\default\softmgr_res.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\SoftMgrView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\SoftMgrView2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\softmgr_guide.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\softmgr_guide2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\layout\default\softmgr_result.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\softmgr\style\softmgr_style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\btn_bg_1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\btn_bg_2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\smell_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\sorry_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\taskhlp_ac_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\taskhlp_ac_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\wait.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\image\default\res\wait_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\layout\default\autoclean_guide.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\layout\default\softuninstallwnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\TaskHelper\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image\default\Resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image\default\tb_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image\default\tb_default.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image\default\tb_download.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\image\default\tb_new.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\layout\default\ToolBoxView.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\ToolBox\style\Style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\if_block.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\if_prompt.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\if_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\notify_bk_dang.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\notify_bk_safe.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\notify_bk_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\pop_sys_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_bk_dang.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_bk_safe.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_bk_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_btn_dang.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_btn_safe.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\query_btn_warning.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\traymenu_dlg_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\image\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\layout\traydlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\layout\pop\tippop.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\tray2\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\adblock_guide_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\ad_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_off1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_off2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_on1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\pic_ad_on2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\rubbish.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\image\traymenu_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\adblockguide.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\cleartrash.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\strongUnist.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\layout\traydlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Feedback\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\arrowdown_green.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\arrowup_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\clean_junk_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\default_program_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\download.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\download_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\floattray_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\flow_number.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\flow_unit.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\IPicon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\menu_bkg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\menu_item_over.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\pop_memory_btn_green_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\pop_memory_btn_yellow_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\pop_network_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\speed_number.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\speed_unit.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\sys_imglist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_light.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\testspeed_light1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\test_speed_download.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\test_speed_upload.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\trayfloatarrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\trayfloatnetbtnico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\traymenu_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\upload.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\upload_gray.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\upload_gray_mark.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\yaclogo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\trayF_float_tips_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\trayF_float_tips_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_acc_circle_list_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_acc_circle_list_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_acc_circle_list_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_dec_circle_list_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_dec_circle_list_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_left_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_left_bk_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_left_bk_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_right_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_round_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_round_bk_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_round_bk_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_shadow_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_shadow_bk_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_shadow_bk_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_whirling_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_whirling_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_btn_close_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_menu_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_net_down_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_net_flow_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_net_up_arrow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_numer.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_percent_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_percent_bk_orange.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_percent_bk_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_shadow_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_shadow_sh_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_speed_test_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rb.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rb_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rt.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_arrow_rt_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_close_btn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_go_btn_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_wnd_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_tip_wnd_bk_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_rope_btn_bk_gl.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_rope_btn_bk_roulette.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_swing_anim_bk_gl.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_swing_anim_bk_roulette.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_throw_anim_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_throw_anim_round_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_dec_circle_list_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_anim_whirling_red.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\image\float\tray_float_shadow_sv_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\floatplugin.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\floattipwnd.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\floattipwnd_hide.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\swing_anim.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\throwdlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\traydlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloaty2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloatypop2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloatypop2_bottom.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayTaskbar.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayTaskbar_wifi.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\app.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\file.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\folder.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\picture.ico, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\idesk_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\traymenu_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\app.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_cancel.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_green_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\file.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\folder.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\logo_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\main_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\picture.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\yac_logo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout\arrange_desktop.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout\traydlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout\default\MsgCenterDlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\logo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\Msg_BG.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\Resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\style\Style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\pop_startup_slow_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\pop_startup_warning_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_pop_cancel_btn2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_pop_ico_query.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\tray_radio_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\tray_radio_unchecked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout\traydlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout\traymenupop.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\bing_16_16.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\chrome_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_browser2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_browser_dropdown_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_skin4.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\firefix_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\google_16_16.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\ie_16_16.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\ie_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\isafe_16.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\pop_startup_slow_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\pop_startup_warning_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_iconlist.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_pop_cancel_btn2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_pop_ico_query.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\tray_radio_checked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\tray_radio_unchecked.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\yahoo_16_16.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\accesslink.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\blockblacklist.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\lock_guide.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\querymodify.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\querymodify2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\traydlg.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\traymenupop.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\Location_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\new_left.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\new_right.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_assistant_blue_number.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_assistant_yellow_number.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startupass_comb_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startupass_vscoll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_fast_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_slow_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_warning_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_close.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_Setting.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_star.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_anim_expand_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_anim_expand_bk_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_m.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_percent.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_s.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_close_btn_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_close_btn_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_drop_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_drop_bk_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_skin_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_skin_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_itemhover_bk_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_itemhover_bk_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_location_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_location_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_news_line_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_news_line_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_number.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_number_fuzzy.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_optimize_btn.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_large.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_middle.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_late_night_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_late_night_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_morning_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_morning_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_nightfall_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_nightfall_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_noon_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_vscoll_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_vscoll_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_cloudy_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_cloudy_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_icon_large.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_icon_small.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_line_blue.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_line_yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_rain_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_nomall_button.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_noon_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_rain_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_snow_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_snow_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_thunder_blue.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_thunder_yellow.jpg, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_yac_logo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\weather_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\yellow.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\daily_news.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_2.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_3.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_weather.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\exam_tip_wnd_arrow_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\inst_cover_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func_up.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\av_authority_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\combo_list.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\custom_check.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\custom_uncheck.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_antymal_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_clean_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_optimize_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_protect_icon.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\exam_tip_wnd_bk2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\ico_app.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\ico_face.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\ico_upgrade.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_combo_skin.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_logo.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_prog_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_prog_meter.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\open_dir.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\popup_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\resource.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\soft_cof_button_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\soft_remove_button_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_3.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_4.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_5.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_6.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_7.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_acc.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_btn_bg1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_btn_bg2.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_clean.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_complete.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_cry.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func1.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func3.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func_intr.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_input.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_progress.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_prog_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_protect.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_spliter.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\upgrade_bg.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\upgrade_prog_bk.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\upgrade_prog_meter.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\vscroll.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\yac_side_ico.png, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\cover.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\install.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\uninstallpro.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\uninstall_logo_fade.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\upgrade.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\style\style.xml, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\update\temp\dlcfg.ini, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\update\temp\upcfg.ini, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\brset.ini, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\cbss.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\co.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\sie.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\softcache2.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\svc2.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
FraudTool.YAC, C:\Program Files (x86)\Elex-tech\YAC\user\svc2_com.dat, Delete-on-Reboot, [5cc9e39b159341f53e6df3a340c2e11f],
PUP.Optional.LuckyBrowse.ShrtCln, C:\ProgramData\LuckyBrowse\install.dat, Quarantined, [ee37f787594f290d6ba5822937cb1ae6],
PUP.Optional.ConduitTB.Gen, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\CT3289075\CT3289075.fullUserID, Quarantined, [5acb5826307883b326b54e6034ced52b],
PUP.Optional.ConduitTB.Gen, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\CT3289075\CT3289075.UserID, Quarantined, [5acb5826307883b326b54e6034ced52b],
PUP.Optional.Elex.Generic, C:\Program Files (x86)\89uBD7E\tknBDAD.bat, Quarantined, [4bda146a3e6acd69c85335f95ca43bc5],
PUP.Optional.Ghokswa, C:\ProgramData\ozilla ireox.lnk.bat, Good: (), Bad: (start "" "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "http://www.trotux.com/?z=f07b9995b1e7f1a5e30e6d8g2zdm8g1b9ofq4mbq8c&from=epf1&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1&type=hp"), Replaced,[9b8a334b2d7b63d3e8c1f94412ee02fe]
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Quoteexs\ff.HP, Quarantined, [1e0736484e5a5cda8d97715d11ef9b65],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Quoteexs\ff.NT, Quarantined, [1e0736484e5a5cda8d97715d11ef9b65],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Quoteexs\snp.sc, Quarantined, [1e0736484e5a5cda8d97715d11ef9b65],
PUP.Optional.Linkury.ACMB1, C:\Users\Niko\AppData\Roaming\Config.xml, Quarantined, [2500a3db11972f078c8150bb0400d42c],
PUP.Optional.Linkury.ACMB1, C:\Users\Niko\AppData\Roaming\InstallationConfiguration.xml, Quarantined, [8f96740a31777db934da51ba2bd9669a],
PUP.Optional.Amisites.ShrtCln, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "http://www.amisites.com/?type=hp&ts=1482955869&z=5614d51f004ae6def90ed2ag2zcb0oet1wew0b5mbg&from=che0812&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1");), Replaced,[40e58bf32a7e4aec47929101a0603cc4]
PUP.Optional.Amisites.ShrtCln, C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\et6305sn.default-1482858172314\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "http://www.amisites.com/?type=hp&ts=1483453719&z=95dd8210a375af38020c13ag3z5b5c6zaw9cfm3oeg&from=archer1028&uid=ST3500418AS_9VMC74Z1XXXX9VMC74Z1");), Replaced,[2ef7ff7f6d3b3402fadf5b37659be21e]
RiskWare.DontStealOurSoftware, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (0.0.0.0                   keystone.mwbsys.com), Replaced,[978e6717b2f64beb1fa32a696c9402fe]

Physical Sectors: 0
(No malicious items detected)


(end)

Junkware txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Ultimate x64
Ran by Niko (Administrator) on ¨ 20/01/2017 at 19:34:01,72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


File System: 52

Successfully deleted: C:\ProgramData\microleaves (Folder)
Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\genienext (Folder)
Successfully deleted: C:\Users\Niko\AppData\Roaming\elex-tech (Folder)
Successfully deleted: C:\Users\Niko\AppData\Roaming\goforfiles (Folder)
Successfully deleted: C:\Users\Niko\AppData\Roaming\microleaves (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)
Successfully deleted: C:\Program Files (x86)\elex-tech (Folder)
Successfully deleted: C:\Program Files (x86)\similarsites (Folder)
Successfully deleted: C:\Program Files (x86)\weatherchickn (Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0VKK1DX9 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1P73IO32 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1RD08XOH (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5ZVULIXJ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\82XAD943 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HBOTCAAR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IEM3OKII (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JG5YEKZ7 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LEEE2LVY (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q90FSJXA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R0YH43IB (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SZFX53T2 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T2QFO360 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WGV7J0KD (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Niko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YE2SSO9C (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0VKK1DX9 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1P73IO32 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1RD08XOH (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5ZVULIXJ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\82XAD943 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HBOTCAAR (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IEM3OKII (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JG5YEKZ7 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LEEE2LVY (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q90FSJXA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R0YH43IB (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SZFX53T2 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T2QFO360 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WGV7J0KD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YE2SSO9C (Temporary Internet Files Folder)

 

Registry: 1

Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl\\Default (Registry Value)

 


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ¨ 20/01/2017 at 19:36:07,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Check browsers LNK log file:

Check Browsers' LNK  by Alex Dragokas & regist                                 ver. 2.2.0.8 ( Beta )

OS:       x64 Windows 7 (Ultimate), 6.1.7601, Service Pack: 1        ( SingleUserTS / Workstation )
Time:     20.01.2017 - 19:38
Language: OS: English (0x409). Display: Greek (0x408). Non-Unicode: Greek (0x408). Codepage: OEM - c_737.nls (!), ANSI - c_1253.nls (!)
Elevated: Yes
User:     Niko    (group: Administrator) on NIKO-PC


* Suspicious objects will be marked with prefix >>>

===========================================================================
              ((((((        BROWSER shortcuts        ))))))
===========================================================================

[_______________________  Target does not exist  _________________________]

>>>  "C:\Users\Niko\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\UCB11A~1.LNK" ("C:\Users\Niko\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UC浏览器.lnk")          -> ["C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"]

[=========================================================================]
                ((((((       Other shortcuts       ))))))
===========================================================================

[______________________  Suspicious ( low risk )  ________________________]

-[HTTP] "C:\Users\Niko\AppData\Local\MICROS~1\Windows\GAMEEX~1\{1604B~1\SUPPOR~1\0\6A5B~1.LNK" ("C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{1604B427-5F37-4B09-868E-B37367B3FE76}\SupportTasks\0\Υποστήριξη.lnk")     -> ["(Internet Explorer)"  =>> hxxp://support.vugames.com/]
-[HTTP] "C:\Users\Niko\AppData\Local\MICROS~1\Windows\GAMEEX~1\{73B1E~1\SUPPOR~1\0\MICROS~1.LNK" ("C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{73B1EF7E-F5D8-4F57-B57B-6E2858ADAAF7}\SupportTasks\0\Περισσότερα παιχνίδια από την Microsoft.lnk")    -> ["(Internet Explorer)"  =>> hxxp://vvv.blizzard.com/star/star.htm/]
-[HTTP] "C:\Users\Niko\AppData\Local\MICROS~1\Windows\GAMEEX~1\{CCEE7~1\SUPPOR~1\0\MICROS~1.LNK" ("C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{CCEE727D-6F72-4DA6-98EC-8CF603180C67}\SupportTasks\0\Περισσότερα παιχνίδια από την Microsoft.lnk")    -> ["(Internet Explorer)"  =>> hxxp://vvv.needforspeed.com/]
-[HTTP] "C:\Users\Niko\AppData\Local\MICROS~1\Windows\GAMEEX~1\{CCEE7~1\SUPPOR~1\1\6A5B~1.LNK" ("C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{CCEE727D-6F72-4DA6-98EC-8CF603180C67}\SupportTasks\1\Υποστήριξη.lnk")     -> ["(Internet Explorer)"  =>> hxxp://techsupport.ea.com/]
-[HTTP] "C:\Users\Niko\AppData\Local\MICROS~1\Windows\GAMEEX~1\{CF2C4~1\SUPPOR~1\0\MICROS~1.LNK" ("C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{CF2C4999-A9C4-451F-9801-71A667DF94A0}\SupportTasks\0\Περισσότερα παιχνίδια από την Microsoft.lnk")    -> ["(Internet Explorer)"  =>> hxxp://vvv.quake3arena.com/]
-[HTTP] "C:\Users\Niko\AppData\Local\MICROS~1\Windows\GAMEEX~1\{CF2C4~1\SUPPOR~1\1\6A5B~1.LNK" ("C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{CF2C4999-A9C4-451F-9801-71A667DF94A0}\SupportTasks\1\Υποστήριξη.lnk")     -> ["(Internet Explorer)"  =>> hxxp://vvv.idsoftware.com/support/index.html/]
-[HTTP] "C:\Users\Niko\Favorites\NCH Software Download Site.lnk"       -> ["(Internet Explorer)"  =>> hxxp://vvv.nchsoftware.com/index.html]
-[HTTP] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Need for Speed™ Carbon\Web.lnk"  -> ["(Internet Explorer)"  =>> hxxp://vvv.eagames.com/nfs/carbon/us/home.jsp]

[_______________________  Target does not exist  _________________________]

>>>  "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{24F52AFD-4CB3-4031-BDD4-FF9EDE6183F0}\PlayTasks\0\Играй.lnk"     -> ["D:\Gamesexe\Diablo II - Lord of Destruction (1.13d Direct Play)\Нова папка\Diablo II\Diablo II.exe"]
>>>  "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{46988FA6-027A-47FD-8695-ADCCAE7855F7}\PlayTasks\0\Играй.lnk"     -> ["D:\Gameinst\age\Age of Empires III Gold Edition\age3.exe"]
>>>  "C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tamagotchi Simulator\Tamagotchi.lnk"           -> ["C:\Program Files\Tamagotchi Simulator\Tamagotchi.exe"  =>> Tamagotchi]
>>>  "C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tamagotchi Simulator\Uninstall.lnk"  -> ["C:\Program Files\Tamagotchi Simulator\fimain.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound\Rapture3D - Help.lnk"   -> ["C:\Program Files (x86)\BRS\rapture3dgame.chm"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound\Rapture3D - Speaker Layout.lnk"   -> ["C:\Program Files (x86)\BRS\UserLayout.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II\Diablo II - Lord of Destruction.lnk"      -> ["D:\Gameinst\dib\Diablo II\Diablo II.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II\Lord of Destruction Read Me.lnk"          -> ["D:\Gameinst\dib\Diablo II\xreadme.htm"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\3DSetup.exe.lnk"         -> ["D:\Gameinst\3DSetup\3DSetup.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\SetupReg.exe.lnk"        -> ["D:\Gameinst\SetupReg.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\Speed.exe.lnk"           -> ["D:\Gameinst\Speed.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\Uninstall SK Games.lnk"  -> ["D:\Gameinst\setup\uninst.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2\Dedicated Server Readme.lnk"          -> ["D:\Gameinst\sam\Serious Sam 2\Content\SeriousSam2\DedicatedServer_ENU.html"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2\Dedicated Server.lnk"       -> ["D:\Gameinst\sam\Serious Sam 2\Bin\DedicatedServer.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Uninstall.lnk"     -> ["C:\Windows\System32\C2MP\Uninst.exe"]
>>>  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Helpful Resources\How to play unusual files.lnk"           -> ["C:\Windows\SysWOW64\C2MP\doc_open_with.pdf"]

[=========================================================================]
                 ((((((      Internet shortcuts       ))))))
===========================================================================

- "C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Serious Sam 2 Patch 2.066.00\Play Serious Sam 2 Patch 2.066.00 Online with GameSpy Arcade.url"  ->           hxxp://vvv.gamespyarcade.com/features/launch.asp?svcname=serioussam2&distID=1154
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Need for Speed Underground 2\Check For Update.url"  -> hxxp://patches.ea.com/nfs_underground2/EN-US/home.html
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Need for Speed™ Carbon\Check For Update.url"  ->               hxxp://patches.ea.com/nfs_carbon/home.html
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games\Plants vs. Zombies\Visit PopCap.com.url"  ->       hxxp://vvv.popcap.com/?cid=PVZ_PC_DLD_EN_AB1
- "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Package Homepage.url"  -> hxxp://vvv.windows7codecs.com/

[_________________________   Microsoft Games   ___________________________]

- "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{1604B427-5F37-4B09-868E-B37367B3FE76}\SupportTasks\0\Поддръжка.lnk"  -> hxxp://support.vugames.com/
- "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{24F52AFD-4CB3-4031-BDD4-FF9EDE6183F0}\SupportTasks\0\Начална уеб страница.lnk"  ->     hxxp://vvv.blizzard.com/diablo2/
- "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{46988FA6-027A-47FD-8695-ADCCAE7855F7}\SupportTasks\0\Начална уеб страница.lnk"  ->     hxxp://vvv.ageofempires3.com/
- "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{73B1EF7E-F5D8-4F57-B57B-6E2858ADAAF7}\SupportTasks\0\Начална уеб страница.lnk"  ->     hxxp://vvv.blizzard.com/star/star.htm/
- "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{CF2C4999-A9C4-451F-9801-71A667DF94A0}\SupportTasks\0\Начална уеб страница.lnk"  ->     hxxp://vvv.quake3arena.com/
- "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{CF2C4999-A9C4-451F-9801-71A667DF94A0}\SupportTasks\1\Поддръжка.lnk"  -> hxxp://vvv.idsoftware.com/support/index.html/
- "C:\ProgramData\Microsoft\Windows\GameExplorer\{A0DED0E8-0C78-45BE-A72A-36EAFD71D0A8}\SupportTasks\0\Web.lnk"  ->     hxxp://fifa.easports.com/
- "C:\ProgramData\Microsoft\Windows\GameExplorer\{A0DED0E8-0C78-45BE-A72A-36EAFD71D0A8}\SupportTasks\1\Check for updates.lnk"  ->      hxxp://vvv.easportsfootball.co.uk/pc-patch

[____________________ Statistics ___________________]

Threats found:      17
Files listed:       176833 (folders: 33478, shortcuts: 298)
Time spent:         11 sec. (search: 8 sec., analysis: 2 sec.)

Been verified:
C:\Users\Niko
C:\Users\Default
C:\Users\Public
C:\ProgramData
_____________________________ End of Log _________________________________

[______________________ Maximum of file objects __________________________]
1154  ( 1154 )  - C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending
2636  ( 2636 )  - C:\ProgramData\Bluestacks\UserData\InputMapper
5619  ( 5619 )  - C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Quarantine
14    ( 5647 )  - C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware

_________________________________________________________________________19544 bytes, CRC32: FFFFFFFF. Sign: 濓쇭

Само да спомена Malwarebytes след сканирането откри 3000+ заплахи......останах шокиран.

Надявам се съм испълнил точно инструкциите.

 

преди 8 минути, niko4 написа:

Само да спомена Malwarebytes след сканирането откри 3000+ заплахи......останах шокиран.

Не се учудвайте..състоянието на системата ви е много плачевно...! Нещата са сериозни..! Сериозно заразена система...!Ще я оправим ама имаме доста работа..! Търпение му е майката...!

102.jpg?1414583023 Моля, изтеглете ClearLNK by Dragokas & regist.

  • Запомнете архива на вашия декстоп,разархивирате програмата ClearLNK
  • Влачите и пускате файла Check_Browsers_LNK.log (логът генериран от програмата Check Browsers LNK в предния ми инструкция) на иконката на програмата ClearLNK.


[IMG]

  • Ще се генерира отчет ClearLNK-<Дата>.log, който ще бъде създаден в папката LOG. Публикувайте дневника в следващия си пост.

 

Направете ново  сканиране с Farbar Recovery Scan Tool

 

Сканиране с Farbar Recovery Scan

  • Моля изтеглете icon1337953436.pngFarbar Recovery Scan Tool (според версията на Windows изберете 32 битовата или 64 битовата версия) и го запазете надесктопа.
  • Стартирайте файла FRST.exe (или FRST64.exe)
  • Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение.
  • Натиснете бутона YClYkft.jpg.
  • Изчакайте търпеливо проверката да приключи.
  • Ще се създадат два лог файла с името - FRST.txt и Addition.txt надесктопа.
  • Копирайте съдържанието на файла FRST.txt в следващия си пост.Прикачете Addition.txt в коментар си (погледнете опцията Прикачване на файлове, когато публикувате мнение).

 

 Дневници
 
В следващия си отговор, моля да включите (като копирате целите съдържания ) следните дневници:

  • Дневник ClearLNK-<Дата>.log
  • FRST.txt (копирате цялото съдържание)
  • Addition.txt (прикачате..) 
преди 25 минути, niko4 написа:

Здравейте отново завърших всичко от постът по горе единствено не успя да завърши ADV cleaner след като го стартирах откри 137 заплахи след натискане на бутонът почистване компютърът забива исключих го пренудително пак пуснах програмата отново откри 137 заплахи и отново след натискане на бутона почистване заби оставх го час и половина и нямаше промяна.

И това ще оправим..! :)

  • Автор

Надявам се да го оправим направо се стреснах.....добре че обърнах внимание че се запълва C.....

Ето и файловете.

ClearLNK-20.01.2017_21-22:

ClearLNK by Alex Dragokas                                 ver. 2.9.0.11

OS:       x64 Windows 7 Ultimate, 6.1.7601, Service Pack: 1
Time:     20.01.2017 - 21:22
Language: OS: EN (0x409). Display: el-GR (0x408). Non-Unicode: el-GR (0x408)
Elevated: Yes
User:     Niko    (group: Administrator)

_____________________________ Begin of Log ______________________________
.
[DEL ] 1  "C:\Users\Niko\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\UCB11A~1.LNK"    (target was not recovered)
[DEL ] 2  "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{24F52AFD-4CB3-4031-BDD4-FF9EDE6183F0}\PlayTasks\0\Играй.lnk"    (target was not recovered)
[DEL ] 3  "C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{46988FA6-027A-47FD-8695-ADCCAE7855F7}\PlayTasks\0\Играй.lnk"    (target was not recovered)
[DEL ] 4  "C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tamagotchi Simulator\Tamagotchi.lnk"    (target was not recovered)
[DEL ] 5  "C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tamagotchi Simulator\Uninstall.lnk"    (target was not recovered)
[DEL ] 6  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound\Rapture3D - Help.lnk"    (target was not recovered)
[DEL ] 7  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound\Rapture3D - Speaker Layout.lnk"    (target was not recovered)
[DEL ] 8  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II\Diablo II - Lord of Destruction.lnk"    (target was not recovered)
[DEL ] 9  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II\Lord of Destruction Read Me.lnk"    (target was not recovered)
[DEL ] 10 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\3DSetup.exe.lnk"    (target was not recovered)
[DEL ] 11 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\SetupReg.exe.lnk"    (target was not recovered)
[DEL ] 12 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\Speed.exe.lnk"    (target was not recovered)
[DEL ] 13 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7\Uninstall SK Games.lnk"    (target was not recovered)
[DEL ] 14 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2\Dedicated Server Readme.lnk"    (target was not recovered)
[DEL ] 15 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2\Dedicated Server.lnk"    (target was not recovered)
[DEL ] 16 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Uninstall.lnk"    (target was not recovered)
[DEL ] 17 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Helpful Resources\How to play unusual files.lnk"    (target was not recovered)
.
______________________________ Statistics _______________________________
Cure ran per today: 1 times.

  Total processed:  17

         Deleted:   17
______________________________ End of Log _______________________________
______________________________ Debug Info _______________________________
20/1/2017 9:22:23 μμ - Parser.GetLinkInfoTarget - #52  Bad file name or number. LastDllError = 3. File:  C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{24F52AFD-4CB3-4031-BDD4-FF9EDE6183F0}\PlayTasks\0\?????.lnk
20/1/2017 9:22:23 μμ - Parser.GetLinkInfoTarget - #52  Bad file name or number. LastDllError = 3. File:  C:\Users\Niko\AppData\Local\Microsoft\Windows\GameExplorer\{46988FA6-027A-47FD-8695-ADCCAE7855F7}\PlayTasks\0\?????.lnk
___________________________ End of debugging ____________________________CRC32: 20C75584

FRST файл:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-01-2017
Ran by Niko (administrator) on NIKO-PC (20-01-2017 21:23:41)
Running from C:\Users\Niko\Desktop
Loaded Profiles: Niko (Available Profiles: Niko)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Αγγλικά (Ηνωμένων Πολιτειών)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKU\S-1-5-18\...\Run: [] => 0
ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} =>  -> No File
GroupPolicy\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{A9E20E9E-792A-4F68-89E1-1415384AFC8B}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/el-gr/?ocid=iehp
URLSearchHook: HKLM-x32 -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-02] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-02] (Oracle Corporation)
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll [2013-05-21] ()
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File

FireFox:
========
FF DefaultProfile: edks5xtv.Προκαθορισμένος χρήστης
FF DefaultProfile: xjoysaf1.default
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default [2017-01-20]
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\et6305sn.default-1482858172314 [2017-01-20]
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης [2017-01-20]
FF Homepage: Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης -> www.google.gr
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Firefox\Firefox\Profiles\xjoysaf1.default [2017-01-20]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-18] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-18] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll [2012-03-29] ( Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-09-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3399182300-3254828621-142692518-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [445976 2016-10-21] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [425496 2016-10-21] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [466456 2016-10-21] (BlueStack Systems, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSLN; C:\ProgramData\Microsoft\IdentityCRL\ppcrlconf.dll [501248 2017-01-18] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 ed2kidle; "C:\Program Files (x86)\amuleC\ed2k.exe" -downloadwhenidle [X] <==== ATTENTION

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [305920 2011-10-24] (AVEO)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-10-21] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-10-07] (Bluestack System Inc. )
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-24] (Disc Soft Ltd)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-20 21:23 - 2017-01-20 21:24 - 00011111 _____ C:\Users\Niko\Desktop\FRST.txt
2017-01-20 21:21 - 2016-11-29 21:28 - 00462976 _____ (Alex Dragokas) C:\Users\Niko\Desktop\ClearLNK.exe
2017-01-20 21:20 - 2017-01-20 21:20 - 00200975 _____ C:\Users\Niko\Desktop\ClearLNK.zip
2017-01-20 19:38 - 2017-01-20 21:22 - 00000000 ____D C:\Users\Niko\Desktop\LOG
2017-01-20 17:13 - 2017-01-20 17:27 - 00000000 ____D C:\AdwCleaner
2017-01-20 17:12 - 2017-01-20 17:12 - 03988944 _____ C:\Users\Niko\Downloads\adwcleaner_6.042.exe
2017-01-20 17:10 - 2017-01-20 17:10 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-01-20 17:10 - 2017-01-20 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-20 17:10 - 2017-01-20 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-20 16:24 - 2017-01-20 19:44 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-20 16:24 - 2017-01-20 16:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-01-20 16:24 - 2017-01-20 16:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-01-20 16:24 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-01-20 16:24 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2017-01-20 16:24 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-01-20 16:16 - 2017-01-20 16:16 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Firefox
2017-01-20 16:16 - 2017-01-20 16:16 - 00000000 ____D C:\Users\Niko\AppData\Local\Firefox
2017-01-20 16:14 - 2017-01-20 16:14 - 00000000 ____D C:\Windows\SysWOW64\extensions
2017-01-20 16:13 - 2017-01-20 16:13 - 00000000 ____D C:\ProgramData\wintooll
2017-01-20 16:13 - 2017-01-20 16:13 - 00000000 ____D C:\ProgramData\ie8
2017-01-20 16:02 - 2017-01-20 16:05 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Geek Uninstaller
2017-01-20 16:02 - 2017-01-12 03:10 - 06963736 _____ (Geek Unіnstaller) C:\Users\Niko\Desktop\geek.exe
2017-01-20 15:25 - 2017-01-20 15:25 - 00000000 ____D C:\Users\Niko\AppData\LocalLow\uTorrent
2017-01-20 15:17 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2017-01-20 15:17 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2017-01-20 15:17 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2017-01-20 14:44 - 2017-01-20 21:23 - 00000000 ____D C:\FRST
2017-01-20 14:44 - 2017-01-20 14:44 - 02419712 _____ (Farbar) C:\Users\Niko\Desktop\FRST64.exe
2017-01-20 14:20 - 2017-01-20 14:20 - 00003136 _____ C:\Windows\System32\Tasks\{F6FB8D9F-8D03-4028-8AFD-441580394D90}
2017-01-20 14:17 - 2017-01-20 14:21 - 00000000 ____D C:\Program Files\Trojan Killer
2017-01-19 17:21 - 2017-01-19 17:21 - 00003558 _____ C:\Windows\System32\Tasks\Milimili
2017-01-19 17:21 - 2017-01-19 17:21 - 00000000 ____D C:\Program Files (x86)\MIO
2017-01-19 14:23 - 2017-01-19 19:24 - 00000040 _____ C:\Program Files (x86)\settings.dat
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 ____D C:\Users\Niko\AppData\Local\Applefat
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 ____D C:\Program Files (x86)\reports
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 _____ C:\Program Files (x86)\metadata
2017-01-19 14:21 - 2017-01-19 14:21 - 00000019 _____ C:\Users\Public\Documents\cc.ini
2017-01-18 16:47 - 2017-01-20 16:57 - 00002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-18 16:46 - 2017-01-18 16:46 - 00000000 ____D C:\Program Files (x86)\Applefat
2017-01-16 14:02 - 2009-10-15 09:44 - 00809560 ____R (Creative Labs Inc.) C:\Windows\SysWOW64\tmp9676.tmp
2017-01-12 15:08 - 2017-01-18 14:46 - 00000000 ____D C:\ProgramData\wintools
2017-01-09 12:45 - 2017-01-09 12:45 - 00000000 ____D C:\Program Files (x86)\rf4derqf
2017-01-07 21:29 - 2017-01-07 21:29 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Frogwares
2017-01-07 21:28 - 2017-01-20 16:57 - 00000838 _____ C:\Users\Public\Desktop\The Testament of Sherlock Holmes.lnk
2017-01-07 21:28 - 2017-01-07 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus Home Interactive
2017-01-05 17:03 - 2017-01-05 17:20 - 00000000 ____D C:\ProgramData\NFS Underground
2017-01-05 17:02 - 2017-01-20 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7
2017-01-02 22:10 - 2017-01-02 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2017-01-02 21:41 - 2017-01-02 21:41 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003778 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003766 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003590 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003530 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-01-02 21:41 - 2016-12-12 04:37 - 01854400 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01452480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2017-01-02 21:40 - 2017-01-02 21:40 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-02 21:40 - 2016-12-12 04:37 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-01-02 21:40 - 2016-12-11 20:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-01-02 21:40 - 2016-09-09 20:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-01-02 21:40 - 2016-09-09 20:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2017-01-02 21:40 - 2016-09-09 20:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-01-02 21:40 - 2016-09-09 20:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2017-01-02 21:37 - 2016-12-12 04:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 17436808 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03479744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00491536 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00212936 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00101824 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00091584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-01-02 21:37 - 2016-12-12 04:37 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2017-01-02 21:31 - 2017-01-02 21:31 - 00000000 ____D C:\Windows\Sun
2017-01-01 22:47 - 2017-01-01 22:47 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Easeware
2016-12-27 14:24 - 2016-12-27 14:24 - 00000000 ____D C:\Program Files (x86)\mtdh7czn
2016-12-26 14:54 - 2017-01-20 16:53 - 00000000 ____D C:\ProgramData\cficf

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-20 21:22 - 2014-05-06 21:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2
2017-01-20 21:22 - 2014-04-04 17:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II
2017-01-20 21:22 - 2014-03-19 14:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack
2017-01-20 21:22 - 2013-12-28 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
2017-01-20 21:22 - 2013-09-26 19:12 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tamagotchi Simulator
2017-01-20 20:44 - 2016-10-06 20:58 - 00000454 _____ C:\Windows\Tasks\UCBrowserUpdater.job
2017-01-20 19:38 - 2016-11-24 10:40 - 00000000 ____D C:\Users\Niko\AppData\LocalLow\Mozilla
2017-01-20 19:38 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-20 19:38 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-20 19:36 - 2015-01-25 06:54 - 04084676 _____ C:\Windows\system32\perfh008.dat
2017-01-20 19:36 - 2015-01-25 06:54 - 01285800 _____ C:\Windows\system32\perfc008.dat
2017-01-20 19:36 - 2009-07-14 07:13 - 00006208 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-20 19:34 - 2013-08-23 18:50 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-20 19:31 - 2016-09-29 01:38 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-01-20 19:31 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-20 17:10 - 2016-09-29 01:39 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-01-20 16:59 - 2009-07-14 06:45 - 00000000 ____D C:\Windows\ServiceProfiles
2017-01-20 16:58 - 2013-08-23 18:39 - 00001389 _____ C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-20 16:57 - 2016-10-25 17:16 - 00001855 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2017-01-20 16:57 - 2016-02-02 23:43 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-20 16:57 - 2015-07-01 13:00 - 00001110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2017-01-20 16:57 - 2014-10-18 00:07 - 00001488 _____ C:\Users\Niko\Desktop\short.lnk
2017-01-20 16:57 - 2014-05-23 18:14 - 00000359 _____ C:\Users\Niko\Desktop\computer.lnk
2017-01-20 16:57 - 2013-09-02 05:55 - 00001149 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player PRO.lnk
2017-01-20 16:57 - 2013-08-24 04:14 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2017-01-20 16:57 - 2013-08-24 04:14 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2017-01-20 16:57 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2017-01-20 16:57 - 2009-07-14 06:57 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-01-20 16:57 - 2009-07-14 06:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2017-01-20 16:57 - 2009-07-14 06:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2017-01-20 16:57 - 2009-07-14 06:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2017-01-20 16:57 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2017-01-20 16:53 - 2016-12-19 23:01 - 00000000 ____D C:\ProgramData\ficfi
2017-01-20 16:53 - 2016-11-23 12:47 - 00000000 ____D C:\ProgramData\bfibe
2017-01-20 16:53 - 2016-11-09 00:46 - 00000000 ____D C:\ProgramData\behbe
2017-01-20 16:53 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\cfibf
2017-01-20 16:53 - 2016-10-21 13:48 - 00000000 ____D C:\ProgramData\jcfic
2017-01-20 16:30 - 2016-09-29 01:38 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-01-20 16:24 - 2013-08-28 03:22 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-20 16:15 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\QQBrowser
2017-01-20 16:14 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\ttff
2017-01-20 16:10 - 2016-04-19 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2017-01-20 16:10 - 2016-04-19 08:22 - 00000000 ____D C:\Program Files (x86)\Seagate
2017-01-20 16:10 - 2013-08-24 03:47 - 00000000 ____D C:\Users\Niko\AppData\Roaming\uTorrent
2017-01-20 15:34 - 2013-09-08 15:49 - 00000000 ____D C:\ProgramData\Skype
2017-01-20 15:23 - 2014-11-04 23:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-01-20 15:23 - 2013-09-03 05:16 - 00000000 ____D C:\Users\Niko\Documents\My Games
2017-01-20 15:23 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-01-20 15:17 - 2016-04-25 03:50 - 00000000 ____D C:\Windows\SysWOW64\directx
2017-01-19 14:23 - 2014-01-21 14:42 - 00000000 ____D C:\Users\Niko\AppData\Local\Google
2017-01-16 18:21 - 2016-02-19 08:41 - 00000000 ____D C:\Users\Niko\AppData\Local\CrashDumps
2017-01-16 14:03 - 2013-09-03 05:16 - 00000000 ____D C:\ProgramData\Codemasters
2017-01-16 14:02 - 2013-12-28 23:20 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00122968 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2017-01-16 13:52 - 2013-08-24 03:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-01-10 22:52 - 2015-03-23 06:57 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-07 21:30 - 2013-10-17 17:02 - 00000000 ____D C:\Users\Niko\AppData\Roaming\NVIDIA
2017-01-02 22:15 - 2014-04-25 21:36 - 00000000 ____D C:\Users\Niko\Documents\NFS Carbon
2017-01-02 21:44 - 2014-01-20 06:31 - 00000000 ____D C:\Users\Niko\AppData\Local\NVIDIA Corporation
2017-01-02 21:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-01-02 21:42 - 2013-08-23 18:50 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-02 21:41 - 2013-08-23 18:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-02 21:41 - 2013-08-23 18:49 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-02 21:29 - 2013-08-24 03:06 - 00059144 _____ C:\Users\Niko\AppData\Local\GDIPFONTCACHEV1.DAT
2017-01-02 21:28 - 2009-07-14 06:45 - 04893920 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-02 21:26 - 2014-02-18 15:20 - 00000000 ____D C:\ProgramData\HP
2017-01-02 21:16 - 2013-08-23 18:55 - 00000000 ____D C:\Users\Niko\AppData\Local\NVIDIA
2017-01-02 20:39 - 2016-02-18 07:59 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-02 00:50 - 2014-07-24 20:30 - 00000000 ____D C:\Users\Niko\Documents\NFS Most Wanted
2016-12-31 20:36 - 2013-09-02 05:37 - 00000000 ____D C:\Users\Niko\AppData\Roaming\BSplayer Pro
2016-12-27 19:03 - 2016-08-22 02:47 - 00000000 ____D C:\Users\Niko\AppData\Local\Profiles
2016-12-27 19:03 - 2016-08-22 02:44 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Profiles

==================== Files in the root of some directories =======

2017-01-19 14:23 - 2017-01-19 14:23 - 0000000 _____ () C:\Program Files (x86)\metadata
2017-01-19 14:23 - 2017-01-19 19:24 - 0000040 _____ () C:\Program Files (x86)\settings.dat
2016-10-06 20:54 - 2016-10-06 20:54 - 0140288 _____ () C:\Users\Niko\AppData\Roaming\Installer.dat
2016-10-06 20:55 - 2016-10-06 20:55 - 0018432 _____ () C:\Users\Niko\AppData\Roaming\Main.dat
2014-01-27 14:18 - 2014-01-27 14:18 - 0003584 _____ () C:\Users\Niko\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-09 23:48 - 2016-03-09 23:48 - 0000000 _____ () C:\Users\Niko\AppData\Local\{17E571E6-9009-4609-B1E3-75C6FB68244D}
2014-07-12 18:23 - 2014-07-12 18:23 - 0000000 _____ () C:\Users\Niko\AppData\Local\{46DE8AB8-CF21-4A09-B2D9-AA70260696B5}
2014-02-18 15:20 - 2017-01-02 21:27 - 0014081 _____ () C:\ProgramData\hpzinstall.log
2015-11-19 08:17 - 2015-11-19 08:17 - 0000040 _____ () C:\ProgramData\ra3.ini

Some files in TEMP:
====================
C:\Users\Niko\AppData\Local\Temp\6_Offer_4.exe
C:\Users\Niko\AppData\Local\Temp\7za.exe
C:\Users\Niko\AppData\Local\Temp\AutoRun.exe
C:\Users\Niko\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Niko\AppData\Local\Temp\binkw32.dll
C:\Users\Niko\AppData\Local\Temp\BluestacksUninstaller.exe
C:\Users\Niko\AppData\Local\Temp\Browser_V5.6.14087.902_f_4674_(Build1608021049).exe
C:\Users\Niko\AppData\Local\Temp\CmdLineExt03.dll
C:\Users\Niko\AppData\Local\Temp\d2l_Install.exe
C:\Users\Niko\AppData\Local\Temp\d2l_PlayD2.exe
C:\Users\Niko\AppData\Local\Temp\E060.tmp.exe
C:\Users\Niko\AppData\Local\Temp\EAInstall.dll
C:\Users\Niko\AppData\Local\Temp\eauninstall.exe
C:\Users\Niko\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Niko\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Niko\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe
C:\Users\Niko\AppData\Local\Temp\geek64.exe
C:\Users\Niko\AppData\Local\Temp\HD-LibraryHandler.dll
C:\Users\Niko\AppData\Local\Temp\HD-Logger-Native.dll
C:\Users\Niko\AppData\Local\Temp\htmlayout.dll
C:\Users\Niko\AppData\Local\Temp\ins6068.tmp.exe
C:\Users\Niko\AppData\Local\Temp\inst12.exe
C:\Users\Niko\AppData\Local\Temp\iv_uninstall.exe
C:\Users\Niko\AppData\Local\Temp\kernel32.dll
C:\Users\Niko\AppData\Local\Temp\KuaiZip.exe
C:\Users\Niko\AppData\Local\Temp\libeay32.dll
C:\Users\Niko\AppData\Local\Temp\msvcr120.dll
C:\Users\Niko\AppData\Local\Temp\Need for Speed Most Wanted_uninst.exe
C:\Users\Niko\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\Niko\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Niko\AppData\Local\Temp\nvStInst.exe
C:\Users\Niko\AppData\Local\Temp\nvstlink.exe
C:\Users\Niko\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Niko\AppData\Local\Temp\patchw32.dll
C:\Users\Niko\AppData\Local\Temp\setup.exe
C:\Users\Niko\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Niko\AppData\Local\Temp\SoHuVA_4.2.0.16-c20762-ng-nti-s-tp-x.exe
C:\Users\Niko\AppData\Local\Temp\speed.exe
C:\Users\Niko\AppData\Local\Temp\sqlite3.dll
C:\Users\Niko\AppData\Local\Temp\tmd_34012506.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34013739.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34014067.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34014502.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34016590.exe
C:\Users\Niko\AppData\Local\Temp\tmp17ED.exe
C:\Users\Niko\AppData\Local\Temp\Uninstall.exe
C:\Users\Niko\AppData\Local\Temp\uninstall13306027.exe
C:\Users\Niko\AppData\Local\Temp\Utils.dll
C:\Users\Niko\AppData\Local\Temp\_is44EB.exe
C:\Users\Niko\AppData\Local\Temp\_is84A9.exe
C:\Users\Niko\AppData\Local\Temp\_isC1F7.exe
C:\Users\Niko\AppData\Local\Temp\_isEAAC.exe
C:\Users\Niko\AppData\Local\Temp\~ct2EF0.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct4D55.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct4F87.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct5C53.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct697C.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct932.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct959B.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctA85C.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctAB3D.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctAC56.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctB654.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctBA5A.tmp.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-13 00:58

==================== End of FRST.txt ============================

Надявам се че се справям добре със инструкциите който ми даваш

и много благодаря че ми обръщаш внимание и се занимаваш със моята система.

БЛАГОДАРЯ

Addition.txt

Фикс с Farbar Recovery Scan Tool
 
icon13.gif Изтеглете прикачения файл - fixlist.txt и го запазете там, където сте свалили FRST.exe
Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.

Press%20the%20FIX%20button_zpsdd5zi3mt.p


Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.
 
ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

 

BY4dvz9.png Сканиране с AdwCleaner

 
Моля, изтеглете и стартирайте програмата Malwarebytes AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте A49sxPr.pngScan (провери).
  • След завършване, кликнете на 6cyn5v5.pngLogfile (дневник).Ще се отвори прозорец в който се намира дневника (AdwCleaner [S0] .txt).Кликнете два пъти върх реда и ще се отвори съдържанието на дневника.Публикувайте го в следващия си пост
  • Върнете се към основния прозорец на AdwCleaner .маркирайте MqHawIb.pngClean (Почисти)
  • Следвайте указанията и разрешете на компютъра да се рестартира.
  • След рестарта ще се отвори дневник AdwCleaner[C0].txt . Моля копирайте съдържанието на лог файла в следващия си пост.

 

25.jpg?1426074241   Сканиране с SecurityCheck by glax24

  • Изтеглете SecurityCheck by glax24 от тук и запомнете инструмента на десктопа .
  • Стартирате програмата (ако използвате Windows XP) или стартирате с десен бутон на мишката от името на администратор (ако използватеWindows Vista/7/8/10)
  • Изчакайте да приключи сканирането.Ще се отвори в текстов файл с имеSecurityCheck.txt. Копирайте съдържанието на  този файл  следващия си пост
  • Можете да намерите този файл в основната директория на системния диск в папка с име SecurityCheck, напр. C:\SecurityCheck\SecurityCheck.txt

 

pfNZP4A.png  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • FixLog.txt
  • AdwCleaner.txt
  • SecurityCheck.txt (копирате съдържанието)
  • Автор

Здравейте отново

старирах фикс програмката и ми заби но ми извади фикс файл.

adwcleaner ми заби след натискане на бутона почисти но ми извади дневник след сканирането.

ето и файловете.

Фикс:

Fix result of Farbar Recovery Scan Tool (x64) Version: 18-01-2017
Ran by Niko (21-01-2017 12:41:18) Run:1
Running from C:\Users\Niko\Desktop
Loaded Profiles: Niko (Available Profiles: Niko)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-18\...\Run: [] => 0
ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} =>  -> No File
GroupPolicy\User: Restriction <======= ATTENTION
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File
FF Plugin HKU\S-1-5-21-3399182300-3254828621-142692518-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
S2 ed2kidle; "C:\Program Files (x86)\amuleC\ed2k.exe" -downloadwhenidle [X] <==== ATTENTION
C:\Program Files (x86)\amuleC\ed2k.exe
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION
C:\Windows\System32\DRIVERS\ucguard.sys
2017-01-20 14:17 - 2017-01-20 14:21 - 00000000 ____D C:\Program Files\Trojan Killer
2017-01-09 12:45 - 2017-01-09 12:45 - 00000000 ____D C:\Program Files (x86)\rf4derqf
2016-12-27 14:24 - 2016-12-27 14:24 - 00000000 ____D C:\Program Files (x86)\mtdh7czn
C:\Users\Niko\AppData\Local\Temp\6_Offer_4.exe
C:\Users\Niko\AppData\Local\Temp\7za.exe
C:\Users\Niko\AppData\Local\Temp\AutoRun.exe
C:\Users\Niko\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Niko\AppData\Local\Temp\binkw32.dll
C:\Users\Niko\AppData\Local\Temp\BluestacksUninstaller.exe
C:\Users\Niko\AppData\Local\Temp\Browser_V5.6.14087.902_f_4674_(Build1608021049).exe
C:\Users\Niko\AppData\Local\Temp\CmdLineExt03.dll
C:\Users\Niko\AppData\Local\Temp\d2l_Install.exe
C:\Users\Niko\AppData\Local\Temp\d2l_PlayD2.exe
C:\Users\Niko\AppData\Local\Temp\E060.tmp.exe
C:\Users\Niko\AppData\Local\Temp\EAInstall.dll
C:\Users\Niko\AppData\Local\Temp\eauninstall.exe
C:\Users\Niko\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Niko\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Niko\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe
C:\Users\Niko\AppData\Local\Temp\geek64.exe
C:\Users\Niko\AppData\Local\Temp\HD-LibraryHandler.dll
C:\Users\Niko\AppData\Local\Temp\HD-Logger-Native.dll
C:\Users\Niko\AppData\Local\Temp\htmlayout.dll
C:\Users\Niko\AppData\Local\Temp\ins6068.tmp.exe
C:\Users\Niko\AppData\Local\Temp\inst12.exe
C:\Users\Niko\AppData\Local\Temp\iv_uninstall.exe
C:\Users\Niko\AppData\Local\Temp\kernel32.dll
C:\Users\Niko\AppData\Local\Temp\KuaiZip.exe
C:\Users\Niko\AppData\Local\Temp\libeay32.dll
C:\Users\Niko\AppData\Local\Temp\msvcr120.dll
C:\Users\Niko\AppData\Local\Temp\Need for Speed Most Wanted_uninst.exe
C:\Users\Niko\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Niko\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\Niko\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Niko\AppData\Local\Temp\nvStInst.exe
C:\Users\Niko\AppData\Local\Temp\nvstlink.exe
C:\Users\Niko\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Niko\AppData\Local\Temp\patchw32.dll
C:\Users\Niko\AppData\Local\Temp\setup.exe
C:\Users\Niko\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Niko\AppData\Local\Temp\SoHuVA_4.2.0.16-c20762-ng-nti-s-tp-x.exe
C:\Users\Niko\AppData\Local\Temp\speed.exe
C:\Users\Niko\AppData\Local\Temp\sqlite3.dll
C:\Users\Niko\AppData\Local\Temp\tmd_34012506.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34013739.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34014067.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34014502.exe
C:\Users\Niko\AppData\Local\Temp\tmd_34016590.exe
C:\Users\Niko\AppData\Local\Temp\tmp17ED.exe
C:\Users\Niko\AppData\Local\Temp\Uninstall.exe
C:\Users\Niko\AppData\Local\Temp\uninstall13306027.exe
C:\Users\Niko\AppData\Local\Temp\Utils.dll
C:\Users\Niko\AppData\Local\Temp\_is44EB.exe
C:\Users\Niko\AppData\Local\Temp\_is84A9.exe
C:\Users\Niko\AppData\Local\Temp\_isC1F7.exe
C:\Users\Niko\AppData\Local\Temp\_isEAAC.exe
C:\Users\Niko\AppData\Local\Temp\~ct2EF0.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct4D55.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct4F87.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct5C53.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct697C.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct932.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ct959B.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctA85C.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctAB3D.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctAC56.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctB654.tmp.dll
C:\Users\Niko\AppData\Local\Temp\~ctBA5A.tmp.dll
Task: {6A2ECC27-450B-43F5-A501-EA67814833A3} - System32\Tasks\RunAsStdUser Task => C:\Users\Niko\AppData\Local\Oxy\Application\oxy.exe <==== ATTENTION
Task: {F244EF39-2AC7-4C74-8D83-23563DAD65F1} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe [2016-08-02] (UCWeb Inc) <==== ATTENTION
Task: C:\Windows\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION
MSCONFIG\startupreg: svchost0 => "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"\UUC0789.exe
cmd: del %temp%\*.* /f /s /q
cmd: rd /s /q %temp%
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
emptytemp:
reboot:
end

 

*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj2 => key removed successfully
HKCR\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} => key not found.
C:\Windows\system32\GroupPolicy\User => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKCR\PROTOCOLS\Handler\skype4com => key not found.
HKCR\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} => key not found.
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\MozillaPlugins\ubisoft.com/uplaypc => key removed successfully
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll => not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => key removed successfully
HKLM\System\CurrentControlSet\Services\ed2kidle => key removed successfully
ed2kidle => service removed successfully
"C:\Program Files (x86)\amuleC\ed2k.exe" => not found.

adwcleaner След сканиране файл:

# AdwCleaner v6.042 - Logfile created 21/01/2017 at 13:01:14
# Updated on 06/01/2017 by Malwarebytes
# Database : 2017-01-20.2 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : Niko - NIKO-PC
# Running from : C:\Users\Niko\Desktop\adwcleaner_6.042.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support

 

***** [ Services ] *****

Service Found:  UCGuard


***** [ Folders ] *****

Folder Found:  C:\Users\Niko\AppData\Local\Oxy
Folder Found:  C:\Users\Niko\AppData\Roaming\Oxy
Folder Found:  C:\Users\Niko\AppData\Roaming\Softlink
Folder Found:  C:\Users\Niko\Documents\Mobogenie
Folder Found:  C:\ProgramData\QQBrowser
Folder Found:  C:\ProgramData\chuvc
Folder Found:  C:\ProgramData\BaofengUpdate_U
Folder Found:  C:\ProgramData\jcfic
Folder Found:  C:\ProgramData\gjdgj
Folder Found:  C:\ProgramData\Application Data\QQBrowser
Folder Found:  C:\ProgramData\Application Data\chuvc
Folder Found:  C:\ProgramData\Application Data\BaofengUpdate_U
Folder Found:  C:\ProgramData\Application Data\jcfic
Folder Found:  C:\ProgramData\Application Data\gjdgj
Folder Found:  C:\Program Files (x86)\UvConverter
Folder Found:  C:\Windows\SysWOW64\C2MP
Folder Found:  C:\Users\Niko\AppData\Local\Temp\Kuaizip
Folder Found:  C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
Folder Found:  C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\aMule
Folder Found:  C:\Users\Niko\AppData\Local\app
Folder Found:  C:\ProgramData\WinTools


***** [ Files ] *****

File Found:  C:\Users\Niko\daemonprocess.txt
File Found:  C:\Windows\SysNative\log\iSafeKrnlCall.log
File Found:  C:\Windows\SysNative\drivers\ucguard.sys
File Found:  C:\TOSTACK
File Found:  C:\Users\Niko\AppData\Local\Temp\Utils.dll


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

No infected shortcut found.


***** [ Scheduled Tasks ] *****

No malicious task found.


***** [ Registry ] *****

Key Found:  HKLM\SOFTWARE\Classes\UCHTML
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.CRX
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTM
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTML
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.MHT
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTM
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTML
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.WEBP
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHT
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHTML
Key Found:  HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
Key Found:  [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
Key Found:  HKLM\SOFTWARE\Classes\AppID\{9CC34070-3A38-4C7A-89CB-EF8177EF07A1}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{BE89FFB3-7F9C-4A16-B475-98B195A06628}
Value Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Conduit
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Escolade
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\GoforFiles
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Installer
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\UCBrowser
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\UCBrowserPID
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\AutoTime
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\SNDA
Key Found:  HKCU\Software\Conduit
Key Found:  HKCU\Software\Escolade
Key Found:  HKCU\Software\GoforFiles
Key Found:  HKCU\Software\Installer
Key Found:  HKCU\Software\UCBrowser
Key Found:  HKCU\Software\UCBrowserPID
Key Found:  HKCU\Software\AutoTime
Key Found:  HKCU\Software\SNDA
Key Found:  HKLM\SOFTWARE\Conduit
Key Found:  HKLM\SOFTWARE\Elex-tech
Key Found:  HKLM\SOFTWARE\GoforFiles
Key Found:  HKLM\SOFTWARE\SiteFinder
Key Found:  HKLM\SOFTWARE\UCBrowser
Key Found:  HKLM\SOFTWARE\UCBrowserPID
Key Found:  HKLM\SOFTWARE\ScreenShot
Key Found:  HKLM\SOFTWARE\InterHop
Key Found:  HKLM\SOFTWARE\amule-custom
Key Found:  HKLM\SOFTWARE\mylucky123Software
Key Found:  HKLM\SOFTWARE\SoEasySvc
Key Found:  HKLM\SOFTWARE\UvConverter
Key Found:  HKLM\SOFTWARE\Microleaves
Key Found:  [x64] HKCU\Software\Conduit
Key Found:  [x64] HKCU\Software\Escolade
Key Found:  [x64] HKCU\Software\GoforFiles
Key Found:  [x64] HKCU\Software\Installer
Key Found:  [x64] HKCU\Software\UCBrowser
Key Found:  [x64] HKCU\Software\UCBrowserPID
Key Found:  [x64] HKCU\Software\AutoTime
Key Found:  [x64] HKCU\Software\SNDA
Key Found:  [x64] HKLM\SOFTWARE\InterSect Alliance
Key Found:  HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
Key Found:  HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B68CE107A2DED706DC47D6BC4BF3C4C1
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C767D9D7BB3F9C4B839FF09B6C80DCF
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE2F0310EBEC29A0C48C035C43786AA
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2A47D6F1D42DD81A292C027724D291
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02C076B2283AB74D88D5E4D34BC497FF
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
Value Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
Value Found:  HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
Value Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
Key Found:  HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found:  HKCU\Software\Microsoft\Internet Explorer\DOMStorage\colorask.com
Key Found:  HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mylucky123.com
Key Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\colorask.com
Key Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mylucky123.com
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\apphide
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\mobilegeni daemon
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\svchost0
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\app
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\oxy.exe
Key Found:  HKLM\SOFTWARE\Clients\StartMenuInternet\UCBrowser
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
Value Found:  HKLM\SOFTWARE\RegisteredApplications [UCBrowser]
Key Found:  HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
Value Found:  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
Value Found:  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [ArcherGroupEx]
Key Found:  HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\KuaiZip2ShlExt
Key Found:  HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\KuaiZip2ShlExt
Key Found:  HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KuaiZip2ShlExt
Key Found:  HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KZipShell2Ext
Value Found:  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [GubedZLGroupEx]


***** [ Web browsers ] *****

No malicious Firefox based browser items found.
No malicious Chromium based browser items found.

*************************

C:\AdwCleaner\AdwCleaner[S0].txt - [9714 Bytes] - [20/01/2017 17:15:35]
C:\AdwCleaner\AdwCleaner[S1].txt - [9786 Bytes] - [20/01/2017 17:27:10]
C:\AdwCleaner\AdwCleaner[S2].txt - [8707 Bytes] - [21/01/2017 13:01:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [8780 Bytes] ##########

SecurityCheck файл:

SecurityCheck by glax24 & Severnyj v.1.4.0.46 [22.09.16]
WebSite: www.safezone.cc
DateLog: 21.01.2017 13:16:18
Path starting: C:\Users\Niko\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Niko
VersionXML: 3.78is-21.01.2017
___________________________________________________________________________

Windows 7(6.1.7601) Service Pack 1 (x64) Ultimate Lang: English(0409)
Installation date OS: 23.08.2013 16:37:55
LicenseStatus: Windows(R) 7, Ultimate edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
SystemDrive: C: FS: [NTFS] Capacity: [68.8 Gb] Used: [61.1 Gb] Free: [7.7 Gb]
------------------------------- [ Windows ] -------------------------------
Internet Explorer 10.0.9200.16576 Warning! Download Update
Online installation. Last version available when Windows update is enabled throught the Internet.
User Account Control disabled
The elevation prompt for administrators disabled
^It is recommended to enable: Win+R typing UserAccountControlSettings and Enter^
Never check for updates
Windows Update (wuauserv) - The service is running
Κέντρο ασφαλείας (wscsvc) - The service is running
Απομακρυσμένο μητρώο (RemoteRegistry) - The service has stopped
Εντοπισμός SSDP (SSDPSRV) - The service is running
Υπηρεσίες απομακρυσμένης επιφάνειας εργασίας (TermService) - The service has stopped
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
--------------------------- [ FirewallWindows ] ---------------------------
Τείχος προστασίας των Windows (MpsSvc) - The service is running
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Windows Defender (enabled and out of date)
-------------------------- [ SecurityUtilities ] --------------------------
Malwarebytes Anti-Malware version 2.2.0.1024 v.2.2.0.1024
--------------------------- [ OtherUtilities ] ----------------------------
WinRAR 5.00 beta 7 (64-bit) v.5.00.7 Warning! Download Update
VLC media player 2.1.0 v.2.1.0 Warning! Download Update
Microsoft Silverlight v.4.1.10329.0 Warning! Download Update
--------------------------------- [ P2P ] ---------------------------------
µTorrent v.3.4.9.43085 Warning! P2P-client.
-------------------------------- [ Java ] ---------------------------------
Java 7 Update 67 v.7.0.670 Warning! This software is no longer supported. Please uninstall it and use Java SE 8 (jre-8u121-windows-i586.exe).
--------------------------- [ AdobeProduction ] ---------------------------
Adobe AIR v.3.9.0.1210 Warning! Download Update
Adobe Flash Player 24 NPAPI v.24.0.0.186 Warning! Download Update
Adobe Acrobat Reader DC v.15.023.20056
------------------------------- [ Browser ] -------------------------------
Mozilla Firefox 50.1.0 (x86 el) v.50.1.0
--------------------------- [ RunningProcess ] ----------------------------
C:\Program Files (x86)\Mozilla Firefox\firefox.exe v.50.1.0.6186
------------------ [ AntivirusFirewallProcessServices ] -------------------
MBAMService (MBAMService) - The service has stopped
Windows Defender (WinDefend) - The service is running
----------------------------- [ End of Log ] ------------------------------

 

Странна работа..! Той дневника от фикса също не е пълен..! Рестартира ли се системата след изпълнението му...? Да не би да не сте го копирали целия..?

Освен това проблема с AdwCeleanr  - всичко това което е засякъл след сканирането е зловредно...Трябва да го изчистим.....!!! Моля да преинсатлирате AdwCeleanr и отново да направите процедурата по горната ми инструкция..!

 

+ горното...:

icon1337347931.png  Сканиране с RKill

  • Отворете следния сайт и изтеглете RKill.exe и ги запазете на вашия десктоп.
  • Стартирате програмата с двоен клик върху файла и изчакайте търпеливо.
  • След приключване на проверката ще се генерира лог файл с извършените процедури.
  • Прикачете лог файла в следващия си пост.

 

Сканиране с ComboFix

i_arrow-r.gif Изтеглете ComboFix combofix.gif от тук и го запазете на десктопа си.
How to use ComboFix
icon_exclaim.gif Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to disable your security applications by amateur
icon_arrow.gif Стартирайте Combo-Fix.com combofix.gif и следвайте инструкциите.
Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:ComboFix.txt в следващия Ви коментар в тази тема.
i_exclaim.gif Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

 

 Дневници

В следващия си отговор, моля да включите следните дневници:

 

  • ComboFix.txt (копирано съдържание)
  • Лог файл от RKill

 

 

  • Автор

Здравейте

Отново не приключиха по горните две програмки,фиксът го оставих да работи 17 часа и нямаше промяна другата програмка я оставих почти 12 часа без промяна забиват и двете

ето и останалите две който приключиха

ComboFix файл:

ComboFix 17-01-13.01 - Niko 22/01/2017  17:26:12.1.2 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1253.30.1033.18.3070.1465 [GMT 2:00]
Running from: c:\users\Niko\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\behbe
c:\programdata\behbe\regkey.exe
c:\programdata\bfibe
c:\programdata\bfibe\regkey.exe
c:\programdata\cficf
c:\programdata\cficf\de_svr.exe
c:\programdata\cficf\regkey.exe
c:\windows\SysWow64\tmp65D.tmp
c:\windows\SysWow64\tmp65E.tmp
c:\windows\SysWow64\tmp69CA.tmp
c:\windows\SysWow64\tmp69CB.tmp
c:\windows\SysWow64\tmp9675.tmp
c:\windows\SysWow64\tmp9676.tmp
.
Infected copy of c:\windows\System32\cleanmgr.exe was found and disinfected
Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_6.1.7600.16385_none_c9392808773cd7da\cleanmgr.exe
.
Infected copy of c:\windows\System32\credwiz.exe was found and disinfected
Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-credwiz_31bf3856ad364e35_6.1.7600.16385_none_fbcfa2528586252f\credwiz.exe
.
.
(((((((((((((((((((((((((   Files Created from 2016-12-22 to 2017-01-22  )))))))))))))))))))))))))))))))
.
.
2017-01-22 15:33 . 2017-01-22 15:33    --------    d-----w-    c:\users\Default\AppData\Local\temp
2017-01-21 11:39 . 2017-01-21 14:08    --------    d-----w-    c:\users\Niko\AppData\Roaming\Might & Magic Heroes VI
2017-01-21 11:39 . 2017-01-21 11:57    --------    d-----w-    c:\users\Niko\AppData\Local\Ubisoft Game Launcher
2017-01-21 11:34 . 2017-01-21 11:34    --------    d-----w-    c:\program files (x86)\Ubisoft
2017-01-21 11:13 . 2017-01-21 11:16    --------    d-----w-    C:\SecurityCheck
2017-01-20 15:13 . 2017-01-21 11:01    --------    d-----w-    C:\AdwCleaner
2017-01-20 15:10 . 2017-01-20 15:10    --------    d-----w-    c:\program files (x86)\Mozilla Maintenance Service
2017-01-20 14:24 . 2017-01-20 17:44    192216    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-01-20 14:24 . 2017-01-20 14:24    --------    d-----w-    c:\program files (x86)\Malwarebytes Anti-Malware
2017-01-20 14:24 . 2015-10-05 07:50    63704    ----a-w-    c:\windows\system32\drivers\mwac.sys
2017-01-20 14:24 . 2015-10-05 07:50    109272    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2017-01-20 14:24 . 2015-10-05 07:50    25816    ----a-w-    c:\windows\system32\drivers\mbam.sys
2017-01-20 14:16 . 2017-01-20 14:16    --------    d-----w-    c:\users\Niko\AppData\Roaming\Firefox
2017-01-20 14:16 . 2017-01-20 14:16    --------    d-----w-    c:\users\Niko\AppData\Local\Firefox
2017-01-20 14:14 . 2017-01-20 14:14    --------    d-----w-    c:\windows\SysWow64\extensions
2017-01-20 14:13 . 2017-01-20 14:13    --------    d-----w-    c:\programdata\wintooll
2017-01-20 14:13 . 2017-01-20 14:13    --------    d-----w-    c:\programdata\ie8
2017-01-20 14:02 . 2017-01-20 14:05    --------    d-----w-    c:\users\Niko\AppData\Roaming\Geek Uninstaller
2017-01-20 13:20 . 2017-01-20 13:20    --------    d-----w-    c:\windows\Migration
2017-01-20 13:17 . 2007-04-04 16:54    107368    ----a-w-    c:\windows\system32\xinput1_3.dll
2017-01-20 13:17 . 2006-07-28 07:31    83736    ----a-w-    c:\windows\system32\xinput1_2.dll
2017-01-20 13:17 . 2006-03-31 10:39    83664    ----a-w-    c:\windows\system32\xinput1_1.dll
2017-01-20 12:44 . 2017-01-21 14:28    --------    d-----w-    C:\FRST
2017-01-20 12:17 . 2017-01-20 12:21    --------    d-----w-    c:\program files\Trojan Killer
2017-01-19 15:21 . 2017-01-19 15:21    --------    d-----w-    c:\program files (x86)\MIO
2017-01-19 12:23 . 2017-01-19 12:23    --------    d-----w-    c:\users\Niko\AppData\Local\Applefat
2017-01-19 12:23 . 2017-01-19 12:23    --------    d-----w-    c:\program files (x86)\reports
2017-01-18 14:47 . 2017-01-18 07:50    501248    ----a-w-    c:\programdata\Microsoft\IdentityCRL\ppcrlconf.dll
2017-01-18 14:46 . 2017-01-18 14:46    --------    d-----w-    c:\program files (x86)\Applefat
2017-01-16 11:51 . 2017-01-16 11:51    --------    d-----w-    c:\users\Niko\AppData\Roaming\InstallShield
2017-01-13 00:45 . 2017-01-13 00:45    75888    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{67200A9F-DA28-4060-8EA2-ABCBCB724C01}\offreg.dll
2017-01-12 13:08 . 2017-01-18 12:46    --------    d-----w-    c:\programdata\wintools
2017-01-09 10:45 . 2017-01-09 10:45    --------    d-----w-    c:\program files (x86)\rf4derqf
2017-01-07 19:29 . 2017-01-07 19:29    --------    d-----w-    c:\users\Niko\AppData\Roaming\Frogwares
2017-01-05 15:03 . 2017-01-05 15:20    --------    d-----w-    c:\programdata\NFS Underground
2017-01-02 19:41 . 2016-12-12 02:37    1854400    ----a-w-    c:\windows\system32\nvspcap64.dll
2017-01-02 19:41 . 2016-12-12 02:37    1755072    ----a-w-    c:\windows\system32\nvspbridge64.dll
2017-01-02 19:41 . 2016-12-12 02:37    1452480    ----a-w-    c:\windows\SysWow64\nvspcap.dll
2017-01-02 19:41 . 2016-12-12 02:37    1317312    ----a-w-    c:\windows\SysWow64\nvspbridge.dll
2017-01-02 19:41 . 2016-12-12 02:37    120256    ----a-w-    c:\windows\system32\NvRtmpStreamer64.dll
2017-01-02 19:40 . 2016-12-11 18:23    134712    ----a-w-    c:\windows\SysWow64\nvStreaming.exe
2017-01-02 19:40 . 2017-01-02 19:40    --------    d-----w-    c:\program files (x86)\VulkanRT
2017-01-02 19:40 . 2016-09-09 18:24    125216    ----a-w-    c:\windows\system32\vulkaninfo.exe
2017-01-02 19:40 . 2016-09-09 18:25    269600    ----a-w-    c:\windows\SysWow64\vulkan-1.dll
2017-01-02 19:40 . 2016-09-09 18:25    110880    ----a-w-    c:\windows\SysWow64\vulkaninfo.exe
2017-01-02 19:40 . 2016-09-09 18:25    261920    ----a-w-    c:\windows\system32\vulkan-1.dll
2017-01-02 19:40 . 2016-12-12 02:37    1951    ----a-w-    c:\windows\NvContainerRecovery.bat
2017-01-02 19:31 . 2017-01-02 19:31    --------    d-----w-    c:\windows\Sun
2017-01-01 20:47 . 2017-01-01 20:47    --------    d-----w-    c:\users\Niko\AppData\Roaming\Easeware
2016-12-27 12:24 . 2016-12-27 12:24    --------    d-----w-    c:\program files (x86)\mtdh7czn
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-01-16 12:02 . 2013-12-28 21:20    466520    ----a-w-    c:\windows\system32\wrap_oal.dll
2017-01-16 12:02 . 2013-12-28 21:20    445016    ----a-w-    c:\windows\SysWow64\wrap_oal.dll
2017-01-16 12:02 . 2013-12-28 21:20    122968    ----a-w-    c:\windows\system32\OpenAL32.dll
2017-01-16 12:02 . 2013-12-28 21:20    109144    ----a-w-    c:\windows\SysWow64\OpenAL32.dll
2016-12-18 15:17 . 2013-08-23 16:46    802904    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2016-12-18 15:17 . 2013-08-23 16:46    144472    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-12-12 02:37 . 2016-04-25 01:08    14410472    ----a-w-    c:\windows\SysWow64\nvd3dum.dll
2016-12-12 02:37 . 2016-04-22 23:09    17376896    ----a-w-    c:\windows\SysWow64\nvwgf2um.dll
2016-12-12 02:37 . 2013-08-23 16:50    1595456    ----a-w-    c:\windows\system32\nvhdagenco6420103.dll
2016-12-12 02:37 . 2013-08-23 16:50    3941536    ----a-w-    c:\windows\system32\nvapi64.dll
2016-12-12 02:37 . 2013-08-23 16:50    19947472    ----a-w-    c:\windows\system32\nvwgf2umx.dll
2016-12-11 18:47 . 2013-08-23 16:50    6384576    ----a-w-    c:\windows\system32\nvcpl.dll
2016-12-11 18:47 . 2013-08-23 16:50    2475968    ----a-w-    c:\windows\system32\nvsvc64.dll
2016-12-11 18:47 . 2016-02-18 06:14    81856    ----a-w-    c:\windows\system32\nv3dappshextr.dll
2016-12-11 18:47 . 2016-02-18 06:14    548408    ----a-w-    c:\windows\system32\nv3dappshext.dll
2016-12-11 18:47 . 2013-09-19 16:38    1764408    ----a-w-    c:\windows\system32\nvsvcr.dll
2016-12-11 18:47 . 2013-08-23 16:50    71224    ----a-w-    c:\windows\system32\nvshext.dll
2016-12-11 18:47 . 2013-08-23 16:50    392128    ----a-w-    c:\windows\system32\nvmctray.dll
2016-12-09 08:52 . 2013-08-23 16:50    7639617    ----a-w-    c:\windows\system32\nvcoproc.bin
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x]
R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x]
R3 AVEO;STARTEC UVC Driver;c:\windows\system32\DRIVERS\AVEOdcnt.sys;c:\windows\SYSNATIVE\DRIVERS\AVEOdcnt.sys [x]
R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiaga.sys;c:\windows\SYSNATIVE\drivers\bxdiaga.sys [x]
R3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x64.sys;c:\windows\SYSNATIVE\drivers\Xeno7x64.sys [x]
R3 BstHdAndroidSvc;BlueStacks Android Service ;c:\program files (x86)\Bluestacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\Bluestacks\HD-Service.exe BstHdAndroidSvc Android [x]
R3 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\Bluestacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [x]
R3 BstHdPlusAndroidSvc;BlueStacks Plus Android Service ;c:\program files (x86)\Bluestacks\HD-Plus-Service.exe BstHdPlusAndroidSvc Android;c:\program files (x86)\Bluestacks\HD-Plus-Service.exe BstHdPlusAndroidSvc Android [x]
R3 BstkDrv;BlueStacks Plus Hypervisor;c:\program files (x86)\Bluestacks\BstkDrv.sys;c:\program files (x86)\Bluestacks\BstkDrv.sys [x]
R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys;c:\windows\SYSNATIVE\drivers\bxfcoe.sys [x]
R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys;c:\windows\SYSNATIVE\drivers\bxois.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\System32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
R3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;c:\windows\System32\Drivers\EtronSTOR.sys;c:\windows\SYSNATIVE\Drivers\EtronSTOR.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\System32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys;c:\windows\SYSNATIVE\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys;c:\windows\SYSNATIVE\Drivers\qd262x64.sys [x]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
R3 NvStreamKms;NVIDIA KMS;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\Bluestacks\HD-LogRotatorService.exe;c:\program files (x86)\Bluestacks\HD-LogRotatorService.exe [x]
S2 MSLN;Microsoft Sln Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
S2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x]
S2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
kuaizip2updatesvc    REG_MULTI_SZ       Kuaizip Update Checker
ArcherGroupEx    REG_MULTI_SZ       Archer
LocalServices    REG_MULTI_SZ       MSLN
WinSAPSvc    REG_MULTI_SZ       WinSAPSvc
GubedZLGroupEx    REG_MULTI_SZ       GubedZL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{65122CB0-EA0F-47DF-A953-017170ED12F9}]
2016-10-06 18:56    1126800    ----a-w-    c:\program files (x86)\UCBrowser\Application\5.6.14087.902\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2016-12-23 18:10    323152    ----a-w-    c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Contents of the 'Scheduled Tasks' folder
.
2017-01-22 c:\windows\Tasks\UCBrowserUpdater.job
- c:\program files (x86)\UCBrowser\Application\update_task.exe [2016-10-06 13:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2016-12-12 1854400]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.google.com
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης\
FF - prefs.js: browser.startup.homepage - www.google.gr
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1 - c:\program files (x86)\BRS\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3399182300-3254828621-142692518-1000\Software\SecuROM\License information*]
"datasecu"=hex:16,13,7b,a0,0f,de,f5,bc,c0,d4,2d,c7,92,e4,26,ef,8f,64,5c,e1,64,
   43,10,7b,91,08,81,36,8f,e7,a3,52,5b,fb,67,d1,43,6e,72,3e,30,0b,12,c1,3f,20,\
"rkeysecu"=hex:82,14,81,fe,ae,da,92,e5,e9,98,4a,24,34,da,58,bf
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
c:\program files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
c:\program files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
.
**************************************************************************
.
Completion time: 2017-01-22  17:38:11 - machine was rebooted
ComboFix-quarantined-files.txt  2017-01-22 15:38
.
Pre-Run: 6.336.860.160 διαθέσιμα byte
Post-Run: 25 Κατάλογοι 14.947.659.776 διαθέσιμα byte
.
- - End Of File - - B159B1ACDAD7F862305FD43CAEC1EF22
A36C5E4F47E84449FF07ED3517B43A31

Надявам се че съм ги оставил достатъчно да роботят предните две които забиват за да сме сигурни че забиват.

 

Rkill.txt

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

ClearJavaCache::

File::
c:\program files (x86)\UCBrowser\Application\5.6.14087.902\Installer\chrmstp.exe
c:\program files (x86)\UCBrowser\Application\update_task.exe
c:\windows\Tasks\UCBrowserUpdater.job

Folder::
c:\program files\Trojan Killer
c:\program files (x86)\rf4derqf
c:\program files (x86)\mtdh7czn

driver::
kuaizip2updatesvc
WinSAPSvc
ArcherGroupEx
GubedZLGroupEx 

Registry::
[-HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{65122CB0-EA0F-47DF-A953-017170ED12F9}]

RegNull::
[HKEY_USERS\S-1-5-21-3399182300-3254828621-142692518-1000\Software\SecuROM\License information*]

 

 След съхранението преместете  CFScript.txt на иконата на ComboFix.exe

CFScriptB-4.gif

Генерирания рапорт копирайте и го поставете в следващия си коментар...!

  • Автор

Готов,ето рапортът надявам се да съм го направил както трябва :):)

ComboFix 17-01-13.01 - Niko 22/01/2017  23:04:32.2.2 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1253.30.1033.18.3070.1876 [GMT 2:00]
Running from: c:\users\Niko\Desktop\ComboFix.exe
Command switches used :: c:\users\Niko\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files (x86)\UCBrowser\Application\5.6.14087.902\Installer\chrmstp.exe"
"c:\program files (x86)\UCBrowser\Application\update_task.exe"
"c:\windows\Tasks\UCBrowserUpdater.job"
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\mtdh7czn
c:\program files (x86)\rf4derqf
c:\program files\Trojan Killer
c:\program files\Trojan Killer\7z32.dll
c:\program files\Trojan Killer\7z64.dll
c:\program files\Trojan Killer\database\upd001.c
c:\program files\Trojan Killer\database\upd002.c
c:\program files\Trojan Killer\database\upd003.c
c:\program files\Trojan Killer\database\upd004.c
c:\program files\Trojan Killer\database\upd005.c
c:\program files\Trojan Killer\database\upd006.c
c:\program files\Trojan Killer\database\upd007.c
c:\program files\Trojan Killer\database\upd009.c
c:\program files\Trojan Killer\database\upd00A.c
c:\program files\Trojan Killer\database\upd00B.c
c:\program files\Trojan Killer\database\upd00D.c
c:\program files\Trojan Killer\database\upd00E.c
c:\program files\Trojan Killer\database\upd00F.c
c:\program files\Trojan Killer\database\upd010.c
c:\program files\Trojan Killer\database\upd101.c
c:\program files\Trojan Killer\database\upd102.c
c:\program files\Trojan Killer\database\upd105.c
c:\program files\Trojan Killer\database\upd10B.c
c:\program files\Trojan Killer\database\upd10F.c
c:\program files\Trojan Killer\database\updates\upd008.c
c:\program files\Trojan Killer\libmem32.dll
c:\program files\Trojan Killer\libmem64.dll
c:\program files\Trojan Killer\offreg32.dll
c:\program files\Trojan Killer\offreg64.dll
c:\program files\Trojan Killer\tk.exe
c:\program files\Trojan Killer\tk.ini
c:\program files\Trojan Killer\tk32.exe
c:\program files\Trojan Killer\tk64.exe
.
Infected copy of c:\windows\System32\cleanmgr.exe was found and disinfected
Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_6.1.7600.16385_none_c9392808773cd7da\cleanmgr.exe
.
Infected copy of c:\windows\System32\credwiz.exe was found and disinfected
Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-credwiz_31bf3856ad364e35_6.1.7600.16385_none_fbcfa2528586252f\credwiz.exe
.
.
(((((((((((((((((((((((((   Files Created from 2016-12-22 to 2017-01-22  )))))))))))))))))))))))))))))))
.
.
2017-01-22 21:10 . 2017-01-22 21:10    --------    d-----w-    c:\users\Default\AppData\Local\temp
2017-01-21 11:39 . 2017-01-21 14:08    --------    d-----w-    c:\users\Niko\AppData\Roaming\Might & Magic Heroes VI
2017-01-21 11:39 . 2017-01-21 11:57    --------    d-----w-    c:\users\Niko\AppData\Local\Ubisoft Game Launcher
2017-01-21 11:34 . 2017-01-21 11:34    --------    d-----w-    c:\program files (x86)\Ubisoft
2017-01-21 11:13 . 2017-01-21 11:16    --------    d-----w-    C:\SecurityCheck
2017-01-20 15:13 . 2017-01-21 11:01    --------    d-----w-    C:\AdwCleaner
2017-01-20 15:10 . 2017-01-20 15:10    --------    d-----w-    c:\program files (x86)\Mozilla Maintenance Service
2017-01-20 14:24 . 2017-01-20 17:44    192216    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-01-20 14:24 . 2017-01-20 14:24    --------    d-----w-    c:\program files (x86)\Malwarebytes Anti-Malware
2017-01-20 14:24 . 2015-10-05 07:50    63704    ----a-w-    c:\windows\system32\drivers\mwac.sys
2017-01-20 14:24 . 2015-10-05 07:50    109272    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2017-01-20 14:24 . 2015-10-05 07:50    25816    ----a-w-    c:\windows\system32\drivers\mbam.sys
2017-01-20 14:16 . 2017-01-20 14:16    --------    d-----w-    c:\users\Niko\AppData\Roaming\Firefox
2017-01-20 14:16 . 2017-01-20 14:16    --------    d-----w-    c:\users\Niko\AppData\Local\Firefox
2017-01-20 14:14 . 2017-01-20 14:14    --------    d-----w-    c:\windows\SysWow64\extensions
2017-01-20 14:13 . 2017-01-20 14:13    --------    d-----w-    c:\programdata\wintooll
2017-01-20 14:13 . 2017-01-20 14:13    --------    d-----w-    c:\programdata\ie8
2017-01-20 14:02 . 2017-01-20 14:05    --------    d-----w-    c:\users\Niko\AppData\Roaming\Geek Uninstaller
2017-01-20 13:20 . 2017-01-20 13:20    --------    d-----w-    c:\windows\Migration
2017-01-20 13:17 . 2007-04-04 16:54    107368    ----a-w-    c:\windows\system32\xinput1_3.dll
2017-01-20 13:17 . 2006-07-28 07:31    83736    ----a-w-    c:\windows\system32\xinput1_2.dll
2017-01-20 13:17 . 2006-03-31 10:39    83664    ----a-w-    c:\windows\system32\xinput1_1.dll
2017-01-20 12:44 . 2017-01-21 14:28    --------    d-----w-    C:\FRST
2017-01-19 15:21 . 2017-01-19 15:21    --------    d-----w-    c:\program files (x86)\MIO
2017-01-19 12:23 . 2017-01-19 12:23    --------    d-----w-    c:\users\Niko\AppData\Local\Applefat
2017-01-19 12:23 . 2017-01-19 12:23    --------    d-----w-    c:\program files (x86)\reports
2017-01-18 14:47 . 2017-01-18 07:50    501248    ----a-w-    c:\programdata\Microsoft\IdentityCRL\ppcrlconf.dll
2017-01-18 14:46 . 2017-01-18 14:46    --------    d-----w-    c:\program files (x86)\Applefat
2017-01-16 11:51 . 2017-01-16 11:51    --------    d-----w-    c:\users\Niko\AppData\Roaming\InstallShield
2017-01-13 00:45 . 2017-01-13 00:45    75888    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{67200A9F-DA28-4060-8EA2-ABCBCB724C01}\offreg.dll
2017-01-12 13:08 . 2017-01-18 12:46    --------    d-----w-    c:\programdata\wintools
2017-01-07 19:29 . 2017-01-07 19:29    --------    d-----w-    c:\users\Niko\AppData\Roaming\Frogwares
2017-01-05 15:03 . 2017-01-05 15:20    --------    d-----w-    c:\programdata\NFS Underground
2017-01-02 19:41 . 2016-12-12 02:37    1854400    ----a-w-    c:\windows\system32\nvspcap64.dll
2017-01-02 19:41 . 2016-12-12 02:37    1755072    ----a-w-    c:\windows\system32\nvspbridge64.dll
2017-01-02 19:41 . 2016-12-12 02:37    1452480    ----a-w-    c:\windows\SysWow64\nvspcap.dll
2017-01-02 19:41 . 2016-12-12 02:37    1317312    ----a-w-    c:\windows\SysWow64\nvspbridge.dll
2017-01-02 19:41 . 2016-12-12 02:37    120256    ----a-w-    c:\windows\system32\NvRtmpStreamer64.dll
2017-01-02 19:40 . 2016-12-11 18:23    134712    ----a-w-    c:\windows\SysWow64\nvStreaming.exe
2017-01-02 19:40 . 2017-01-02 19:40    --------    d-----w-    c:\program files (x86)\VulkanRT
2017-01-02 19:40 . 2016-09-09 18:24    125216    ----a-w-    c:\windows\system32\vulkaninfo.exe
2017-01-02 19:40 . 2016-09-09 18:25    269600    ----a-w-    c:\windows\SysWow64\vulkan-1.dll
2017-01-02 19:40 . 2016-09-09 18:25    110880    ----a-w-    c:\windows\SysWow64\vulkaninfo.exe
2017-01-02 19:40 . 2016-09-09 18:25    261920    ----a-w-    c:\windows\system32\vulkan-1.dll
2017-01-02 19:40 . 2016-12-12 02:37    1951    ----a-w-    c:\windows\NvContainerRecovery.bat
2017-01-02 19:31 . 2017-01-02 19:31    --------    d-----w-    c:\windows\Sun
2017-01-01 20:47 . 2017-01-01 20:47    --------    d-----w-    c:\users\Niko\AppData\Roaming\Easeware
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-01-16 12:02 . 2013-12-28 21:20    466520    ----a-w-    c:\windows\system32\wrap_oal.dll
2017-01-16 12:02 . 2013-12-28 21:20    445016    ----a-w-    c:\windows\SysWow64\wrap_oal.dll
2017-01-16 12:02 . 2013-12-28 21:20    122968    ----a-w-    c:\windows\system32\OpenAL32.dll
2017-01-16 12:02 . 2013-12-28 21:20    109144    ----a-w-    c:\windows\SysWow64\OpenAL32.dll
2016-12-18 15:17 . 2013-08-23 16:46    802904    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2016-12-18 15:17 . 2013-08-23 16:46    144472    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-12-12 02:37 . 2016-04-25 01:08    14410472    ----a-w-    c:\windows\SysWow64\nvd3dum.dll
2016-12-12 02:37 . 2016-04-22 23:09    17376896    ----a-w-    c:\windows\SysWow64\nvwgf2um.dll
2016-12-12 02:37 . 2013-08-23 16:50    1595456    ----a-w-    c:\windows\system32\nvhdagenco6420103.dll
2016-12-12 02:37 . 2013-08-23 16:50    3941536    ----a-w-    c:\windows\system32\nvapi64.dll
2016-12-12 02:37 . 2013-08-23 16:50    19947472    ----a-w-    c:\windows\system32\nvwgf2umx.dll
2016-12-11 18:47 . 2013-08-23 16:50    6384576    ----a-w-    c:\windows\system32\nvcpl.dll
2016-12-11 18:47 . 2013-08-23 16:50    2475968    ----a-w-    c:\windows\system32\nvsvc64.dll
2016-12-11 18:47 . 2016-02-18 06:14    81856    ----a-w-    c:\windows\system32\nv3dappshextr.dll
2016-12-11 18:47 . 2016-02-18 06:14    548408    ----a-w-    c:\windows\system32\nv3dappshext.dll
2016-12-11 18:47 . 2013-09-19 16:38    1764408    ----a-w-    c:\windows\system32\nvsvcr.dll
2016-12-11 18:47 . 2013-08-23 16:50    71224    ----a-w-    c:\windows\system32\nvshext.dll
2016-12-11 18:47 . 2013-08-23 16:50    392128    ----a-w-    c:\windows\system32\nvmctray.dll
2016-12-09 08:52 . 2013-08-23 16:50    7639617    ----a-w-    c:\windows\system32\nvcoproc.bin
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x]
R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x]
R3 AVEO;STARTEC UVC Driver;c:\windows\system32\DRIVERS\AVEOdcnt.sys;c:\windows\SYSNATIVE\DRIVERS\AVEOdcnt.sys [x]
R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiaga.sys;c:\windows\SYSNATIVE\drivers\bxdiaga.sys [x]
R3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x64.sys;c:\windows\SYSNATIVE\drivers\Xeno7x64.sys [x]
R3 BstHdAndroidSvc;BlueStacks Android Service ;c:\program files (x86)\Bluestacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\Bluestacks\HD-Service.exe BstHdAndroidSvc Android [x]
R3 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\Bluestacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [x]
R3 BstHdPlusAndroidSvc;BlueStacks Plus Android Service ;c:\program files (x86)\Bluestacks\HD-Plus-Service.exe BstHdPlusAndroidSvc Android;c:\program files (x86)\Bluestacks\HD-Plus-Service.exe BstHdPlusAndroidSvc Android [x]
R3 BstkDrv;BlueStacks Plus Hypervisor;c:\program files (x86)\Bluestacks\BstkDrv.sys;c:\program files (x86)\Bluestacks\BstkDrv.sys [x]
R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys;c:\windows\SYSNATIVE\drivers\bxfcoe.sys [x]
R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys;c:\windows\SYSNATIVE\drivers\bxois.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\System32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
R3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;c:\windows\System32\Drivers\EtronSTOR.sys;c:\windows\SYSNATIVE\Drivers\EtronSTOR.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\System32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys;c:\windows\SYSNATIVE\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys;c:\windows\SYSNATIVE\Drivers\qd262x64.sys [x]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
R3 NvStreamKms;NVIDIA KMS;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\Bluestacks\HD-LogRotatorService.exe;c:\program files (x86)\Bluestacks\HD-LogRotatorService.exe [x]
S2 MSLN;Microsoft Sln Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
S2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x]
S2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
kuaizip2updatesvc    REG_MULTI_SZ       Kuaizip Update Checker
ArcherGroupEx    REG_MULTI_SZ       Archer
LocalServices    REG_MULTI_SZ       MSLN
WinSAPSvc    REG_MULTI_SZ       WinSAPSvc
GubedZLGroupEx    REG_MULTI_SZ       GubedZL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2016-12-23 18:10    323152    ----a-w-    c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Contents of the 'Scheduled Tasks' folder
.
2017-01-22 c:\windows\Tasks\UCBrowserUpdater.job
- c:\program files (x86)\UCBrowser\Application\update_task.exe [2016-10-06 13:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2016-12-12 1854400]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.google.com
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης\
FF - prefs.js: browser.startup.homepage - www.google.gr
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1 - c:\program files (x86)\BRS\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
c:\program files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
.
**************************************************************************
.
Completion time: 2017-01-22  23:15:45 - machine was rebooted
ComboFix-quarantined-files.txt  2017-01-22 21:15
ComboFix2.txt  2017-01-22 15:38
.
Pre-Run: 24 Κατάλογοι 14.539.898.880 διαθέσιμα byte
Post-Run: 25 Κατάλογοι 14.245.486.592 διαθέσιμα byte
.
- - End Of File - - 854FBDF68F2A12139FB796309E44FBAB
A36C5E4F47E84449FF07ED3517B43A31

 

Здравейте..! Вижда се светлина в тунела..;) Тези инструкции ще ви помоля да изпълните в безопасен режим (  Safe mode )

https://www.google.bg/search?q=безопасен+режим&rlz=1C1AOHY_bgBG708BG710&oq=безопасен+режим&aqs=chrome..69i57j0l5.2495j0j7&sourceid=chrome&ie=UTF-8#q=как+се+влиза+в+safe+mode+на+windows+7

 

Фикс с Farbar Recovery Scan Tool
 
icon13.gif Изтеглете прикачения файл - fixlist.txt и го запазете там, където сте свалили FRST.exe
Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.

Press%20the%20FIX%20button_zpsdd5zi3mt.p


Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.
 
ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

 

BY4dvz9.png Сканиране с AdwCleaner

 
Моля, изтеглете и стартирайте програмата Malwarebytes AdwCleaner (by Xplode):

  • Затворете всички стартирани програми и браузъри
  • Кликнете два пъти върху adwcleaner.exe за да стартирате инструмента.
  • Натиснете OK, за да потвърдите, че всички стартирани програми ще бъдат затворени.
  • Маркирайте A49sxPr.pngScan (провери).
  • След завършване, кликнете на 6cyn5v5.pngLogfile (дневник).Ще се отвори прозорец в който се намира дневника (AdwCleaner [S0] .txt).Кликнете два пъти върх реда и ще се отвори съдържанието на дневника.Публикувайте го в следващия си пост
  • Върнете се към основния прозорец на AdwCleaner .маркирайте MqHawIb.pngClean (Почисти)
  • Следвайте указанията и разрешете на компютъра да се рестартира.
  • След рестарта ще се отвори дневник AdwCleaner[C0].txt . Моля копирайте съдържанието на лог файла в следващия си пост.

 

 

  • Автор

Супер това да се чува.

Безопасният режим наистина помогна и програмите завършиха успешно и двете след като завършиха компютърът се рестартира.ето и дневниците.

adwcleaner файл след сканиране:

# AdwCleaner v6.042 - Logfile created 23/01/2017 at 13:26:55
# Updated on 06/01/2017 by Malwarebytes
# Database : 2017-01-20.2 [Local]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : Niko - NIKO-PC
# Running from : C:\Users\Niko\Desktop\adwcleaner_6.042.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support

 

***** [ Services ] *****

No malicious services found.


***** [ Folders ] *****

Folder Found:  C:\Users\Niko\AppData\Local\Oxy
Folder Found:  C:\Users\Niko\AppData\Roaming\Oxy
Folder Found:  C:\Users\Niko\AppData\Roaming\Softlink
Folder Found:  C:\Users\Niko\Documents\Mobogenie
Folder Found:  C:\ProgramData\QQBrowser
Folder Found:  C:\ProgramData\chuvc
Folder Found:  C:\ProgramData\BaofengUpdate_U
Folder Found:  C:\ProgramData\jcfic
Folder Found:  C:\ProgramData\gjdgj
Folder Found:  C:\ProgramData\Application Data\QQBrowser
Folder Found:  C:\ProgramData\Application Data\chuvc
Folder Found:  C:\ProgramData\Application Data\BaofengUpdate_U
Folder Found:  C:\ProgramData\Application Data\jcfic
Folder Found:  C:\ProgramData\Application Data\gjdgj
Folder Found:  C:\Program Files (x86)\UvConverter
Folder Found:  C:\Windows\SysWOW64\C2MP
Folder Found:  C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
Folder Found:  C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\aMule
Folder Found:  C:\Users\Niko\AppData\Local\app
Folder Found:  C:\ProgramData\WinTools


***** [ Files ] *****

File Found:  C:\Users\Niko\daemonprocess.txt
File Found:  C:\Windows\SysNative\log\iSafeKrnlCall.log
File Found:  C:\TOSTACK


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

No infected shortcut found.


***** [ Scheduled Tasks ] *****

No malicious task found.


***** [ Registry ] *****

Key Found:  HKLM\SOFTWARE\Classes\UCHTML
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.CRX
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTM
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTML
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.MHT
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTM
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTML
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.WEBP
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHT
Key Found:  HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHTML
Key Found:  HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
Key Found:  [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
Key Found:  HKLM\SOFTWARE\Classes\AppID\{9CC34070-3A38-4C7A-89CB-EF8177EF07A1}
Key Found:  HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found:  HKLM\SOFTWARE\Classes\Interface\{BE89FFB3-7F9C-4A16-B475-98B195A06628}
Value Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Conduit
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Escolade
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\GoforFiles
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Installer
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\UCBrowser
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\UCBrowserPID
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\AutoTime
Key Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\SNDA
Key Found:  HKCU\Software\Conduit
Key Found:  HKCU\Software\Escolade
Key Found:  HKCU\Software\GoforFiles
Key Found:  HKCU\Software\Installer
Key Found:  HKCU\Software\UCBrowser
Key Found:  HKCU\Software\UCBrowserPID
Key Found:  HKCU\Software\AutoTime
Key Found:  HKCU\Software\SNDA
Key Found:  HKLM\SOFTWARE\Conduit
Key Found:  HKLM\SOFTWARE\Elex-tech
Key Found:  HKLM\SOFTWARE\GoforFiles
Key Found:  HKLM\SOFTWARE\SiteFinder
Key Found:  HKLM\SOFTWARE\UCBrowser
Key Found:  HKLM\SOFTWARE\UCBrowserPID
Key Found:  HKLM\SOFTWARE\ScreenShot
Key Found:  HKLM\SOFTWARE\InterHop
Key Found:  HKLM\SOFTWARE\amule-custom
Key Found:  HKLM\SOFTWARE\mylucky123Software
Key Found:  HKLM\SOFTWARE\SoEasySvc
Key Found:  HKLM\SOFTWARE\UvConverter
Key Found:  HKLM\SOFTWARE\Microleaves
Key Found:  [x64] HKCU\Software\Conduit
Key Found:  [x64] HKCU\Software\Escolade
Key Found:  [x64] HKCU\Software\GoforFiles
Key Found:  [x64] HKCU\Software\Installer
Key Found:  [x64] HKCU\Software\UCBrowser
Key Found:  [x64] HKCU\Software\UCBrowserPID
Key Found:  [x64] HKCU\Software\AutoTime
Key Found:  [x64] HKCU\Software\SNDA
Key Found:  [x64] HKLM\SOFTWARE\InterSect Alliance
Key Found:  HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
Key Found:  HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B68CE107A2DED706DC47D6BC4BF3C4C1
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C767D9D7BB3F9C4B839FF09B6C80DCF
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE2F0310EBEC29A0C48C035C43786AA
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2A47D6F1D42DD81A292C027724D291
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02C076B2283AB74D88D5E4D34BC497FF
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
Key Found:  [x64] HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
Value Found:  HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
Value Found:  HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
Value Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
Key Found:  HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found:  HKCU\Software\Microsoft\Internet Explorer\DOMStorage\colorask.com
Key Found:  HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mylucky123.com
Key Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
Key Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\colorask.com
Key Found:  [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mylucky123.com
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\apphide
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\mobilegeni daemon
Key Found:  [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\app
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\oxy.exe
Key Found:  HKLM\SOFTWARE\Clients\StartMenuInternet\UCBrowser
Key Found:  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
Value Found:  HKLM\SOFTWARE\RegisteredApplications [UCBrowser]
Key Found:  HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
Value Found:  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
Value Found:  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [ArcherGroupEx]
Key Found:  HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\KuaiZip2ShlExt
Key Found:  HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\KuaiZip2ShlExt
Key Found:  HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KuaiZip2ShlExt
Key Found:  HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KZipShell2Ext
Value Found:  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [GubedZLGroupEx]


***** [ Web browsers ] *****

No malicious Firefox based browser items found.
No malicious Chromium based browser items found.

*************************

C:\AdwCleaner\AdwCleaner[S0].txt - [9714 Bytes] - [20/01/2017 17:15:35]
C:\AdwCleaner\AdwCleaner[S1].txt - [9786 Bytes] - [20/01/2017 17:27:10]
C:\AdwCleaner\AdwCleaner[S2].txt - [8967 Bytes] - [21/01/2017 13:01:14]
C:\AdwCleaner\AdwCleaner[S3].txt - [8534 Bytes] - [23/01/2017 13:26:55]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [8607 Bytes] ##########

adwcleaner:файл след изчистване

# AdwCleaner v6.042 - Logfile created 23/01/2017 at 13:29:07
# Updated on 06/01/2017 by Malwarebytes
# Database : 2017-01-20.2 [Local]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : Niko - NIKO-PC
# Running from : C:\Users\Niko\Desktop\adwcleaner_6.042.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support

 

***** [ Services ] *****

 

***** [ Folders ] *****

[-] Folder deleted: C:\Users\Niko\AppData\Local\Oxy
[-] Folder deleted: C:\Users\Niko\AppData\Roaming\Oxy
[-] Folder deleted: C:\Users\Niko\AppData\Roaming\Softlink
[-] Folder deleted: C:\Users\Niko\Documents\Mobogenie
[-] Folder deleted: C:\ProgramData\QQBrowser
[-] Folder deleted: C:\ProgramData\chuvc
[-] Folder deleted: C:\ProgramData\BaofengUpdate_U
[-] Folder deleted: C:\ProgramData\jcfic
[-] Folder deleted: C:\ProgramData\gjdgj
[#] Folder deleted on reboot: C:\ProgramData\Application Data\QQBrowser
[#] Folder deleted on reboot: C:\ProgramData\Application Data\chuvc
[#] Folder deleted on reboot: C:\ProgramData\Application Data\BaofengUpdate_U
[#] Folder deleted on reboot: C:\ProgramData\Application Data\jcfic
[#] Folder deleted on reboot: C:\ProgramData\Application Data\gjdgj
[-] Folder deleted: C:\Program Files (x86)\UvConverter
[-] Folder deleted: C:\Windows\SysWOW64\C2MP
[-] Folder deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
[-] Folder deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\aMule
[-] Folder deleted: C:\Users\Niko\AppData\Local\app
[-] Folder deleted: C:\ProgramData\WinTools


***** [ Files ] *****

[-] File deleted: C:\Users\Niko\daemonprocess.txt
[-] File deleted: C:\Windows\SysNative\log\iSafeKrnlCall.log
[-] File deleted: C:\TOSTACK


***** [ DLL ] *****

 

***** [ WMI ] *****

 

***** [ Shortcuts ] *****

 

***** [ Scheduled Tasks ] *****

 

***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.CRX
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTM
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTML
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.MHT
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTM
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTML
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.WEBP
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHT
[-] Key deleted: HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHTML
[-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
[#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinSnare
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{9CC34070-3A38-4C7A-89CB-EF8177EF07A1}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{BE89FFB3-7F9C-4A16-B475-98B195A06628}
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{FE69C007-C452-4D3E-86D2-1730DF8BC871}]
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Conduit
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Escolade
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\GoforFiles
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Installer
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\UCBrowser
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\UCBrowserPID
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\AutoTime
[-] Key deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\SNDA
[#] Key deleted on reboot: HKCU\Software\Conduit
[#] Key deleted on reboot: HKCU\Software\Escolade
[#] Key deleted on reboot: HKCU\Software\GoforFiles
[#] Key deleted on reboot: HKCU\Software\Installer
[#] Key deleted on reboot: HKCU\Software\UCBrowser
[#] Key deleted on reboot: HKCU\Software\UCBrowserPID
[#] Key deleted on reboot: HKCU\Software\AutoTime
[#] Key deleted on reboot: HKCU\Software\SNDA
[-] Key deleted: HKLM\SOFTWARE\Conduit
[-] Key deleted: HKLM\SOFTWARE\Elex-tech
[-] Key deleted: HKLM\SOFTWARE\GoforFiles
[-] Key deleted: HKLM\SOFTWARE\SiteFinder
[-] Key deleted: HKLM\SOFTWARE\UCBrowser
[-] Key deleted: HKLM\SOFTWARE\UCBrowserPID
[-] Key deleted: HKLM\SOFTWARE\ScreenShot
[-] Key deleted: HKLM\SOFTWARE\InterHop
[-] Key deleted: HKLM\SOFTWARE\amule-custom
[-] Key deleted: HKLM\SOFTWARE\mylucky123Software
[-] Key deleted: HKLM\SOFTWARE\SoEasySvc
[-] Key deleted: HKLM\SOFTWARE\UvConverter
[-] Key deleted: HKLM\SOFTWARE\Microleaves
[#] Key deleted on reboot: [x64] HKCU\Software\Conduit
[#] Key deleted on reboot: [x64] HKCU\Software\Escolade
[#] Key deleted on reboot: [x64] HKCU\Software\GoforFiles
[#] Key deleted on reboot: [x64] HKCU\Software\Installer
[#] Key deleted on reboot: [x64] HKCU\Software\UCBrowser
[#] Key deleted on reboot: [x64] HKCU\Software\UCBrowserPID
[#] Key deleted on reboot: [x64] HKCU\Software\AutoTime
[#] Key deleted on reboot: [x64] HKCU\Software\SNDA
[-] Key deleted: [x64] HKLM\SOFTWARE\InterSect Alliance
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B68CE107A2DED706DC47D6BC4BF3C4C1
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C767D9D7BB3F9C4B839FF09B6C80DCF
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE2F0310EBEC29A0C48C035C43786AA
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2A47D6F1D42DD81A292C027724D291
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02C076B2283AB74D88D5E4D34BC497FF
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
[-] Value deleted: HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\colorask.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mylucky123.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\colorask.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mylucky123.com
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\apphide
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\mobilegeni daemon
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\app
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\oxy.exe
[-] Key deleted: HKLM\SOFTWARE\Clients\StartMenuInternet\UCBrowser
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
[-] Value deleted: HKLM\SOFTWARE\RegisteredApplications [UCBrowser]
[-] Key deleted: HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [ArcherGroupEx]
[-] Key deleted: HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\KuaiZip2ShlExt
[-] Key deleted: HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\KuaiZip2ShlExt
[-] Key deleted: HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KuaiZip2ShlExt
[-] Key deleted: HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KZipShell2Ext
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [GubedZLGroupEx]


***** [ Web browsers ] *****

 

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [9034 Bytes] - [23/01/2017 13:29:07]
C:\AdwCleaner\AdwCleaner[S0].txt - [9714 Bytes] - [20/01/2017 17:15:35]
C:\AdwCleaner\AdwCleaner[S1].txt - [9786 Bytes] - [20/01/2017 17:27:10]
C:\AdwCleaner\AdwCleaner[S2].txt - [8967 Bytes] - [21/01/2017 13:01:14]
C:\AdwCleaner\AdwCleaner[S3].txt - [8790 Bytes] - [23/01/2017 13:26:55]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [9399 Bytes] ##########

Надявам се съм испълнил точно инструкциите.

 

Fixlog.txt

Чудесно...! Започваме с контролни проверки и приключваме ако всичко е наред..! Какво е състоянието на системата след всички процедури до тук...Има ли промяна..?

 

GfiJrQ9.png Malwarebytes Anti-Malware (MBAM)

Моля, изтеглете Malwarebytes Anti-Malware 2.2.0.1024 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-bc.хххх-х.х.х.хххх.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката. Т.е. премахнете първата отметка:

DkgJ7Zr.png

  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категориятаDetection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.

65ZBqkR.jpg

  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинацияCtrl + V и го публикувайте в следващия си коментар.

 

 

Сканиране с ESET Online Scan

  • Моля изтеглете и стартирайте изпълнимия файл от линка отдолу:
    ESET OnlineScan
  • Сложете отметката пред 4yS3E9O.jpg
  • Натиснете бутона XTRkhju.jpg
  • Сложете отметката пред Enable detection of potentially unwanted applications.
  • Сега кликнете на Advanced Settings и се уверете, че опцията Remove found threats не е маркирана, а следните са маркирани:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
    • Изберете сега бутона Change и изберете само Operating memory и дял C:\

fhSji42.png

  • Натиснете бутона Start.
  • ESET ще започне да сваля и инсталира актуализации за вирусните дефиниции и след това ще започне да сканира компютъра. Бъдете търпеливи, защото процеса е бавен и може да отнеме доста време.
  • След като проверката приключи натиснете бутона gFggK2f.jpg
  • Сега натиснете бутона kINPPCe.jpg, и запазете файла на десктопа с име по избор като например (ESETScan.txt). Копирайте резултата в следващия си коментар.
  • Натиснете бутона ObVLksZ.jpg и след това натиснете бутона OWHYffT.jpg за да затворите приложението.

 

..и последно...:

Сканиране с Farbar Recovery Scan

  • Моля изтеглете icon1337953436.pngFarbar Recovery Scan Tool (според версията на Windows изберете 32 битовата или 64 битовата версия) и го запазете надесктопа.
  • Стартирайте файла FRST.exe (или FRST64.exe)
  • Програмата ще се стартира. Натиснете YES за да се съгласите с лицензионното споразумение.
  • Натиснете бутона YClYkft.jpg.
  • Изчакайте търпеливо проверката да приключи.
  • Ще се създадат два лог файла с името - FRST.txt и Addition.txt надесктопа.
  • Копирайте съдържанието на файла FRST.txt в следващия си пост.Прикачете Addition.txt в коментар си (погледнете опцията Прикачване на файлове, когато публикувате мнение).

 

  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • Дневник от Malwarebytes Anti -Malware
  • Дневник от ESET Online Scanner ( List of found threats )
  • FRST.txt (копирате цялото съдържание)
  • Addition.txt (прикачате..) 

 

  • Автор

Здравей,да има промяна от C ми се освободиха 7 гигабайта....вече не е във червената зона и работи доста по спокойно машината без да зарежда дори когато е оставен само на фон и нешто друго спря да се рестартирва от време на време и вече и мозилата не се отваря когато си поска,като цяло огромна промяна.

исках да попитам NOD 32 откри отново зарази възможно ли е да влизат когато гледам филми онлайн,защото когато пускаш филмът ти искачат различни прозорци със реклами не знам дали на тези им казват popup.....ако е така как мога да си гледам филми и да не влизат тея гадинки или е невъзможно.

ето и лог файловете на програмките по горе.

Malwarebytes Anti-Malware

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 23/1/2017
Scan Time: 10:14 μμ
Logfile:
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2017.01.23.08
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Niko

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 313361
Time Elapsed: 14 min, 42 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

eset лог файл:

C:\AdwCleaner\quarantine\files\acnczdcuasijuhfznwmchwwhdqgyjfqn\de_svr.exe    a variant of Win32/Adware.ELEX.CH application
C:\AdwCleaner\quarantine\files\acnczdcuasijuhfznwmchwwhdqgyjfqn\Gubed.exe    a variant of Win32/Adware.ELEX.CR application
C:\AdwCleaner\quarantine\files\acnczdcuasijuhfznwmchwwhdqgyjfqn\regkey.exe    a variant of Win32/ELEX.KE potentially unwanted application
C:\AdwCleaner\quarantine\files\acnczdcuasijuhfznwmchwwhdqgyjfqn\yacqq.exe    a variant of Win32/Adware.ELEX.BS application
C:\Program Files (x86)\NCH Software\Debut\debut.exe    a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Program Files (x86)\NCH Software\Debut\debutsetup_v2.14.exe    a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Program Files (x86)\UCBrowser\Application\molt_tool.exe    a variant of Win32/Taobao.F potentially unwanted application
C:\Program Files (x86)\UCBrowser\Application\Uninstall.exe    a variant of Win32/Taobao.B potentially unwanted application
C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\stats_uploader.exe    a variant of Win32/Taobao.E potentially unwanted application
C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\UCAgent.exe    a variant of Win32/Taobao.C potentially unwanted application
C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\Installer\chrmstp.exe    a variant of Win32/Taobao.F potentially unwanted application
C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\Installer\setup.exe    a variant of Win32/Taobao.F potentially unwanted application
C:\ProgramData\beibe\[email protected]    a variant of Win32/Adware.ELEX.CJ application
C:\ProgramData\dgjcg\[email protected]    a variant of Win32/Adware.ELEX.CJ application
C:\ProgramData\fibfi\de_svr.exe    a variant of Win32/Adware.ELEX.CH application
C:\ProgramData\fibfi\regkey.exe    a variant of Win32/ELEX.KE potentially unwanted application
C:\ProgramData\fibfi\yacqq.exe    a variant of Win32/ELEX.IJ potentially unwanted application
C:\ProgramData\ficfi\de_svr.exe    a variant of Win32/Adware.ELEX.CH application
C:\ProgramData\ficfi\Gubed.exe    a variant of Win32/Adware.ELEX.CR application
C:\ProgramData\ficfi\regkey.exe    a variant of Win32/ELEX.KE potentially unwanted application
C:\ProgramData\Microsoft\IdentityCRL\ppcrlconf.dll    a variant of Win32/Adware.ELEX.EJ application
C:\ProgramData\wintooll\wintooll.exe    a variant of Win32/Adware.ELEX.EE application
C:\Qoobox\Quarantine\C\ProgramData\behbe\regkey.exe.vir    a variant of Win32/ELEX.KE potentially unwanted application
C:\Qoobox\Quarantine\C\ProgramData\bfibe\regkey.exe.vir    a variant of Win32/ELEX.KE potentially unwanted application
C:\Qoobox\Quarantine\C\ProgramData\cficf\de_svr.exe.vir    a variant of Win32/Adware.ELEX.CH application
C:\Qoobox\Quarantine\C\ProgramData\cficf\regkey.exe.vir    a variant of Win32/ELEX.KE potentially unwanted application
C:\Users\All Users\beibe\[email protected]    a variant of Win32/Adware.ELEX.CJ application
C:\Users\All Users\dgjcg\[email protected]    a variant of Win32/Adware.ELEX.CJ application
C:\Users\All Users\fibfi\de_svr.exe    a variant of Win32/Adware.ELEX.CH application
C:\Users\All Users\fibfi\regkey.exe    a variant of Win32/ELEX.KE potentially unwanted application
C:\Users\All Users\fibfi\yacqq.exe    a variant of Win32/ELEX.IJ potentially unwanted application
C:\Users\All Users\ficfi\de_svr.exe    a variant of Win32/Adware.ELEX.CH application
C:\Users\All Users\ficfi\Gubed.exe    a variant of Win32/Adware.ELEX.CR application
C:\Users\All Users\ficfi\regkey.exe    a variant of Win32/ELEX.KE potentially unwanted application
C:\Users\All Users\Microsoft\IdentityCRL\ppcrlconf.dll    a variant of Win32/Adware.ELEX.EJ application
C:\Users\All Users\wintooll\wintooll.exe    a variant of Win32/Adware.ELEX.EE application
C:\Users\Niko\AppData\Roaming\uTorrent\updates\3.3.1_30017.exe    a variant of Win32/AdkDLLWrapper.A potentially unwanted application
C:\Users\Niko\AppData\Roaming\uTorrent\updates\3.4.2_37754.exe    a variant of Win32/OpenCandy.A potentially unsafe application
C:\Users\Niko\AppData\Roaming\uTorrent\updates\3.4.2_38913.exe    a variant of Win32/OpenCandy.A potentially unsafe application
C:\Users\Public\Documents\Wondershare\drfone-for-android_full1531.exe    multiple threats
C:\Users\Public\Documents\Wondershare\mobilego_full818.exe    multiple threats
C:\Windows\Installer\1114c.msi    a variant of Win32/Adware.ELEX.EL application
C:\Windows\Installer\17de1.msi    multiple threats

FRST лог файл:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-01-2017
Ran by Niko (administrator) on NIKO-PC (23-01-2017 23:46:10)
Running from C:\Users\Niko\Desktop
Loaded Profiles: Niko (Available Profiles: Niko)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Αγγλικά (Ηνωμένων Πολιτειών)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{A9E20E9E-792A-4F68-89E1-1415384AFC8B}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3399182300-3254828621-142692518-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM-x32 -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-02] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-02] (Oracle Corporation)
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll [2013-05-21] ()
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File

FireFox:
========
FF DefaultProfile: edks5xtv.Προκαθορισμένος χρήστης
FF DefaultProfile: xjoysaf1.default
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\a25r7i00.default [2017-01-23]
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\et6305sn.default-1482858172314 [2017-01-23]
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης [2017-01-23]
FF Homepage: Mozilla\Firefox\Profiles\edks5xtv.Προκαθορισμένος χρήστης -> www.google.gr
FF ProfilePath: C:\Users\Niko\AppData\Roaming\Firefox\Firefox\Profiles\xjoysaf1.default [2017-01-20]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-18] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-18] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll [2012-03-29] ( Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-09-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [445976 2016-10-21] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [425496 2016-10-21] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [466456 2016-10-21] (BlueStack Systems, Inc.)
R2 MSLN; C:\ProgramData\Microsoft\IdentityCRL\ppcrlconf.dll [501248 2017-01-18] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [305920 2011-10-24] (AVEO)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-10-21] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-10-07] (Bluestack System Inc. )
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-24] (Disc Soft Ltd)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-23 23:46 - 2017-01-23 23:46 - 00010324 _____ C:\Users\Niko\Desktop\FRST.txt
2017-01-23 22:31 - 2017-01-23 22:31 - 00000000 ____D C:\Program Files (x86)\ESET
2017-01-23 22:30 - 2017-01-23 22:30 - 02870984 _____ (ESET) C:\Users\Niko\Desktop\esetsmartinstaller_enu.exe
2017-01-23 22:12 - 2017-01-23 22:12 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2017-01-23 13:20 - 2017-01-23 13:29 - 00290928 _____ C:\Windows\ntbtlog.txt
2017-01-23 13:16 - 2017-01-23 13:16 - 02420736 _____ (Farbar) C:\Users\Niko\Desktop\FRST64.exe
2017-01-23 13:15 - 2017-01-23 13:15 - 03988944 _____ C:\Users\Niko\Desktop\adwcleaner_6.042.exe
2017-01-22 23:15 - 2017-01-22 23:15 - 00022770 _____ C:\ComboFix.txt
2017-01-22 17:24 - 2017-01-22 23:15 - 00000000 ____D C:\Qoobox
2017-01-22 17:24 - 2017-01-22 23:11 - 00000000 ____D C:\Windows\erdnt
2017-01-22 17:24 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2017-01-22 17:24 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2017-01-22 17:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2017-01-22 17:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2017-01-22 17:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2017-01-22 17:24 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2017-01-22 17:24 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2017-01-22 17:24 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2017-01-22 17:23 - 2017-01-22 17:23 - 05659349 ____R (Swearware) C:\Users\Niko\Desktop\ComboFix.exe
2017-01-21 13:39 - 2017-01-22 23:33 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Might & Magic Heroes VI
2017-01-21 13:39 - 2017-01-21 13:57 - 00000000 ____D C:\Users\Niko\AppData\Local\Ubisoft Game Launcher
2017-01-21 13:34 - 2017-01-21 13:34 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2017-01-21 13:13 - 2017-01-21 13:16 - 00000000 ____D C:\SecurityCheck
2017-01-20 17:13 - 2017-01-23 13:29 - 00000000 ____D C:\AdwCleaner
2017-01-20 17:12 - 2017-01-20 17:12 - 03988944 _____ C:\Users\Niko\Downloads\adwcleaner_6.042.exe
2017-01-20 17:10 - 2017-01-20 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-20 17:10 - 2017-01-20 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-20 16:24 - 2017-01-23 22:14 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-20 16:24 - 2017-01-23 22:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-01-20 16:24 - 2017-01-23 22:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-01-20 16:24 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2017-01-20 16:24 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-01-20 16:24 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-01-20 16:16 - 2017-01-20 16:16 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Firefox
2017-01-20 16:16 - 2017-01-20 16:16 - 00000000 ____D C:\Users\Niko\AppData\Local\Firefox
2017-01-20 16:14 - 2017-01-20 16:14 - 00000000 ____D C:\Windows\SysWOW64\extensions
2017-01-20 16:13 - 2017-01-20 16:13 - 00000000 ____D C:\ProgramData\wintooll
2017-01-20 16:13 - 2017-01-20 16:13 - 00000000 ____D C:\ProgramData\ie8
2017-01-20 16:02 - 2017-01-20 16:05 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Geek Uninstaller
2017-01-20 15:17 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2017-01-20 15:17 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2017-01-20 15:17 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2017-01-20 14:44 - 2017-01-23 23:46 - 00000000 ____D C:\FRST
2017-01-20 14:20 - 2017-01-20 14:20 - 00003136 _____ C:\Windows\System32\Tasks\{F6FB8D9F-8D03-4028-8AFD-441580394D90}
2017-01-19 17:21 - 2017-01-19 17:21 - 00003558 _____ C:\Windows\System32\Tasks\Milimili
2017-01-19 17:21 - 2017-01-19 17:21 - 00000000 ____D C:\Program Files (x86)\MIO
2017-01-19 14:23 - 2017-01-19 19:24 - 00000040 _____ C:\Program Files (x86)\settings.dat
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 ____D C:\Users\Niko\AppData\Local\Applefat
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 ____D C:\Program Files (x86)\reports
2017-01-19 14:23 - 2017-01-19 14:23 - 00000000 _____ C:\Program Files (x86)\metadata
2017-01-19 14:21 - 2017-01-19 14:21 - 00000019 _____ C:\Users\Public\Documents\cc.ini
2017-01-18 16:47 - 2017-01-20 16:57 - 00002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-18 16:46 - 2017-01-18 16:46 - 00000000 ____D C:\Program Files (x86)\Applefat
2017-01-07 21:29 - 2017-01-07 21:29 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Frogwares
2017-01-07 21:28 - 2017-01-07 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus Home Interactive
2017-01-05 17:03 - 2017-01-05 17:20 - 00000000 ____D C:\ProgramData\NFS Underground
2017-01-05 17:02 - 2017-01-20 21:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need For Speed 7
2017-01-02 22:10 - 2017-01-02 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2017-01-02 21:41 - 2017-01-02 21:41 - 00003828 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003828 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003778 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003766 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003590 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00003530 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-02 21:41 - 2017-01-02 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-01-02 21:41 - 2016-12-12 04:37 - 01854400 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01452480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2017-01-02 21:41 - 2016-12-12 04:37 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2017-01-02 21:40 - 2017-01-02 21:40 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-02 21:40 - 2016-12-12 04:37 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-01-02 21:40 - 2016-12-11 20:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-01-02 21:40 - 2016-09-09 20:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-01-02 21:40 - 2016-09-09 20:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2017-01-02 21:40 - 2016-09-09 20:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-01-02 21:40 - 2016-09-09 20:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2017-01-02 21:37 - 2016-12-12 04:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 17436808 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03479744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00491536 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00212936 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00101824 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00091584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00046024 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-01-02 21:37 - 2016-12-12 04:37 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-01-02 21:37 - 2016-12-12 04:37 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-01-02 21:37 - 2016-12-12 04:37 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2017-01-02 21:31 - 2017-01-02 21:31 - 00000000 ____D C:\Windows\Sun
2017-01-01 22:47 - 2017-01-01 22:47 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Easeware

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-23 22:14 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-23 22:14 - 2009-07-14 06:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-23 22:12 - 2015-01-25 06:54 - 04233260 _____ C:\Windows\system32\perfh008.dat
2017-01-23 22:12 - 2015-01-25 06:54 - 01336032 _____ C:\Windows\system32\perfc008.dat
2017-01-23 22:12 - 2009-07-14 07:13 - 00006208 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-23 22:07 - 2016-11-24 10:40 - 00000000 ____D C:\Users\Niko\AppData\LocalLow\Mozilla
2017-01-23 22:07 - 2016-09-29 01:38 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-01-23 22:07 - 2013-08-23 18:50 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-23 22:07 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-23 13:28 - 2016-09-29 16:27 - 00000000 ____D C:\Windows\system32\log
2017-01-23 13:28 - 2013-08-23 18:38 - 00000000 ____D C:\Users\Niko
2017-01-23 00:43 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-01-23 00:35 - 2013-08-24 03:47 - 00000000 ____D C:\Users\Niko\AppData\Roaming\uTorrent
2017-01-22 23:34 - 2016-02-19 08:41 - 00000000 ____D C:\Users\Niko\AppData\Local\CrashDumps
2017-01-22 23:11 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2017-01-21 13:46 - 2014-08-24 18:03 - 00000000 ____D C:\Users\Niko\Documents\Might & Magic Heroes VI
2017-01-21 13:34 - 2013-08-24 03:00 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-01-21 12:53 - 2014-02-06 19:13 - 00000008 __RSH C:\Users\Niko\ntuser.pol
2017-01-21 12:41 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-01-21 12:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2017-01-20 21:22 - 2014-05-06 21:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2
2017-01-20 21:22 - 2014-04-04 17:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II
2017-01-20 21:22 - 2014-03-19 14:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack
2017-01-20 21:22 - 2013-12-28 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
2017-01-20 21:22 - 2013-09-26 19:12 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tamagotchi Simulator
2017-01-20 17:10 - 2016-09-29 01:39 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-01-20 16:59 - 2009-07-14 06:45 - 00000000 ____D C:\Windows\ServiceProfiles
2017-01-20 16:58 - 2013-08-23 18:39 - 00001389 _____ C:\Users\Niko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-20 16:57 - 2016-10-25 17:16 - 00001855 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2017-01-20 16:57 - 2016-02-02 23:43 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-20 16:57 - 2015-07-01 13:00 - 00001110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
2017-01-20 16:57 - 2014-10-18 00:07 - 00001488 _____ C:\Users\Niko\Desktop\short.lnk
2017-01-20 16:57 - 2014-05-23 18:14 - 00000359 _____ C:\Users\Niko\Desktop\computer.lnk
2017-01-20 16:57 - 2013-09-02 05:55 - 00001149 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player PRO.lnk
2017-01-20 16:57 - 2013-08-24 04:14 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2017-01-20 16:57 - 2013-08-24 04:14 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2017-01-20 16:57 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2017-01-20 16:57 - 2009-07-14 06:57 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-01-20 16:57 - 2009-07-14 06:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2017-01-20 16:57 - 2009-07-14 06:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2017-01-20 16:57 - 2009-07-14 06:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2017-01-20 16:57 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2017-01-20 16:53 - 2016-12-19 23:01 - 00000000 ____D C:\ProgramData\ficfi
2017-01-20 16:53 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\cfibf
2017-01-20 16:30 - 2016-09-29 01:38 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-01-20 16:24 - 2013-08-28 03:22 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-20 16:14 - 2016-10-28 13:47 - 00000000 ____D C:\ProgramData\ttff
2017-01-20 16:10 - 2016-04-19 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2017-01-20 16:10 - 2016-04-19 08:22 - 00000000 ____D C:\Program Files (x86)\Seagate
2017-01-20 15:34 - 2013-09-08 15:49 - 00000000 ____D C:\ProgramData\Skype
2017-01-20 15:23 - 2014-11-04 23:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-01-20 15:23 - 2013-09-03 05:16 - 00000000 ____D C:\Users\Niko\Documents\My Games
2017-01-20 15:17 - 2016-04-25 03:50 - 00000000 ____D C:\Windows\SysWOW64\directx
2017-01-19 14:23 - 2014-01-21 14:42 - 00000000 ____D C:\Users\Niko\AppData\Local\Google
2017-01-16 14:03 - 2013-09-03 05:16 - 00000000 ____D C:\ProgramData\Codemasters
2017-01-16 14:02 - 2013-12-28 23:20 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00122968 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2017-01-16 14:02 - 2013-12-28 23:20 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2017-01-10 22:52 - 2015-03-23 06:57 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-07 21:30 - 2013-10-17 17:02 - 00000000 ____D C:\Users\Niko\AppData\Roaming\NVIDIA
2017-01-02 22:15 - 2014-04-25 21:36 - 00000000 ____D C:\Users\Niko\Documents\NFS Carbon
2017-01-02 21:44 - 2014-01-20 06:31 - 00000000 ____D C:\Users\Niko\AppData\Local\NVIDIA Corporation
2017-01-02 21:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-01-02 21:42 - 2013-08-23 18:50 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-02 21:41 - 2013-08-23 18:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-02 21:41 - 2013-08-23 18:49 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-02 21:29 - 2013-08-24 03:06 - 00059144 _____ C:\Users\Niko\AppData\Local\GDIPFONTCACHEV1.DAT
2017-01-02 21:28 - 2009-07-14 06:45 - 04893920 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-02 21:26 - 2014-02-18 15:20 - 00000000 ____D C:\ProgramData\HP
2017-01-02 21:16 - 2013-08-23 18:55 - 00000000 ____D C:\Users\Niko\AppData\Local\NVIDIA
2017-01-02 20:39 - 2016-02-18 07:59 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-02 00:50 - 2014-07-24 20:30 - 00000000 ____D C:\Users\Niko\Documents\NFS Most Wanted
2016-12-31 20:36 - 2013-09-02 05:37 - 00000000 ____D C:\Users\Niko\AppData\Roaming\BSplayer Pro
2016-12-27 19:03 - 2016-08-22 02:47 - 00000000 ____D C:\Users\Niko\AppData\Local\Profiles
2016-12-27 19:03 - 2016-08-22 02:44 - 00000000 ____D C:\Users\Niko\AppData\Roaming\Profiles

==================== Files in the root of some directories =======

2017-01-19 14:23 - 2017-01-19 14:23 - 0000000 _____ () C:\Program Files (x86)\metadata
2017-01-19 14:23 - 2017-01-19 19:24 - 0000040 _____ () C:\Program Files (x86)\settings.dat
2016-10-06 20:54 - 2016-10-06 20:54 - 0140288 _____ () C:\Users\Niko\AppData\Roaming\Installer.dat
2016-10-06 20:55 - 2016-10-06 20:55 - 0018432 _____ () C:\Users\Niko\AppData\Roaming\Main.dat
2014-01-27 14:18 - 2014-01-27 14:18 - 0003584 _____ () C:\Users\Niko\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-09 23:48 - 2016-03-09 23:48 - 0000000 _____ () C:\Users\Niko\AppData\Local\{17E571E6-9009-4609-B1E3-75C6FB68244D}
2014-07-12 18:23 - 2014-07-12 18:23 - 0000000 _____ () C:\Users\Niko\AppData\Local\{46DE8AB8-CF21-4A09-B2D9-AA70260696B5}
2014-02-18 15:20 - 2017-01-02 21:27 - 0014081 _____ () C:\ProgramData\hpzinstall.log
2015-11-19 08:17 - 2015-11-19 08:17 - 0000040 _____ () C:\ProgramData\ra3.ini

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-23 14:57

==================== End of FRST.txt ============================

Addition.txt

Здравейте...! Добре е че нещата вървят към финал..! Поизмъчих ви малко..но поне ще решим проблема..! Виждам че нямате никаква антивирусна защита и никакви добавки против изскачащи прозорци ( popup ) и реклами. Това не е добре..! Трябва да се помисли по въпроса..! Иначе ще си чест посетител на подраздела ни и отново ще се шокирате при засичането на 3000+ бацили..! :)

 

Този софтуер задължително е за обновяване..:

Цитат

Java 7 Update 67 v.7.0.670 Warning! This software is no longer supported. Please uninstall it and use Java SE 8 (jre-8u121-windows-i586.exe).

Adobe AIR v.3.9.0.1210 Warning! Download Update
Adobe Flash Player 24 NPAPI v.24.0.0.186 Warning! Download Update

WinRAR 5.00 beta 7 (64-bit) v.5.00.7 Warning! Download Update
VLC media player 2.1.0 v.2.1.0 Warning! Download Update
Microsoft Silverlight v.4.1.10329.0 Warning! Download Update

Internet Explorer 10.0.9200.16576 Warning! Download Update

 

Фикс с Farbar Recovery Scan Tool
 
icon13.gif Изтеглете прикачения файл fixlist.txt и го запазете там, където сте свалили FRST.exe
Стартирайте отново FRST.exe и натиснете бутона Fix веднъж и изчакайте.

Press%20the%20FIX%20button_zpsdd5zi3mt.p


Ще се създаде нов лог файла FixLog.txt. Прикачете съдържанието му в следващия си коментар.
 
ЗАБЕЛЕЖКА: Този скрипт е написан специално за този потребител,и за тази конкретна машина. Изпълнението на фикса, на друг компютър може да доведе до увреждане на  операционната ви система

pfNZP4A.png  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • FixLog.txt
  • Автор

Имах проблеми със интернетът затова не успях да отговоря по със време СТРАХОТНО фиксът който ми бяхте постнали го направи не във сигурен режим а нормален от Ц ми се освободи още място от 6 гигабайта във началото сега е на 16,4 гигабайта като цяло е по стабилна и вече почти 10 дни без да се рестартира сам.....

Малкия който играе игрите си тук споделя че вървят по добре

Благодаря ти много за помоща и за времето което отдели за да ми помогнеш СТРАХОТЕН СИ :):)

Исках само да попитам каква антивирусна програма ми препоръчваш да ме пази добре и да не искачат тези прозорци повреме на пускане на филм онлайн.Ще си я закупя за да е защитен добре компютърът.

Чудесно..! Да премахнем  програмите които използвахме:

icon_arrow.gif Изтеглете DelFix и го стартирайте. Сложете отметка пред:

  • Remove disinfection tools
  • Purge system restore

delfix.JPG
 
..и след това натиснете бутона Run

  • След като операцията е завърши,ще се създаде дневник
  • Копирате го и го поставите в следващия си отговор

Инструмента ще се самоизтрие след като приключи своята задача!

 

Имам едно излизане по задачи и като се върна ще пиша някои неща като превенции..!

 

pfNZP4A.png  Дневници
 
В следващия си отговор, моля да включите следните дневници:

  • DelFix
  • Автор

Ето и логът от програмката

# DelFix v1.013 - Logfile created 28/01/2017 at 21:02:15
# Updated 17/04/2016 by Xplode
# Username : Niko - NIKO-PC
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\SecurityCheck
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Niko\Desktop\Fixlog.txt
Deleted : C:\Users\Niko\Desktop\FRST64.exe
Deleted : C:\Users\Niko\Downloads\adwcleaner_6.042.exe
Deleted : C:\Windows\grep.exe
Deleted : C:\Windows\PEV.exe
Deleted : C:\Windows\NIRCMD.exe
Deleted : C:\Windows\MBR.exe
Deleted : C:\Windows\SED.exe
Deleted : C:\Windows\SWREG.exe
Deleted : C:\Windows\SWSC.exe
Deleted : C:\Windows\SWXCACLS.exe
Deleted : C:\Windows\Zip.exe
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #258 [Restore Point Created by FRST | 01/25/2017 12:23:46]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########


Ще ти бъда много благодарен ако споделиш някои тънкости,трикове,съвети,каквото и да е :)

Избора на антивирусна програма е въпрос на който аз избягвам да отговарям.За мен това е строго индивидуален избор който би трябвало да се базира на вашите нужди, техническите умения, опит и възможности, предлаганите от антивирусните компании  ръководства за употреба. лекота на актуализиране (и модернизация на нова версия на програмата), лесна инсталация, техническа поддръжка  и цена.Освен това много важни фактори при избора на антивирусна програма са..: проценти и методи за откриване, ефективност на сканиране  колко често се обновяват  вирусните дефиниции, количеството ресурси които програмата използва, как това може да повлияе на производителността на системата и какво ще работи най-добре за вашата система. Ако една  антивирусна програма работи добре за една компютърна система.. не може да работи така  за друга. Не съществува универсално "един еталон подходящ за всички", което работи за всички. Няма една единствена най-добра антивирусна програма.   В раздела Сигурност и антивирусна защита  има достатъчно теми ,обсъждания ,коментари..Така че може да си прочетете и да си вземете решение ..!

.В допълнение към антивирусен софтуер, който дава  защита в реално време, трябва да имаме On-demand скенер (антивирусни скенери  по заявка). Препоръчвам такава програма Malwarebytes' Anti-Malware като  периодично да сканирате системата си с нея (поне един -два пъти в седмицата),като не забравяйте да обновите дефинициите и преди всяко сканиране..  Напомням че това не е антивирусна програма а едно изключително добро допълнение към нея..!

 

icon_arrow.gif Още няколко програмки по мое мнение задължителни за всеки компютър:
 
- CryptoPrevent - за защита срещу CryptoLocker и подобни заплахи Имайте предвид, че ако изберете високо ниво на защита в CryptoPrevent след това можете да срещнете някои проблеми с инсталираните приложения. Може да се наложи да се намали нивото на защита, ако се натъкнете на подобни проблеми или да добавите вписванията към белия списък:
 
mtBkCIZ.jpg


 
 
- Unchecky - която автоматично ще премахва всички нежелани допълнения  по време на инсталирането на софтуера. Това помага за предотвратяване на инсталиране на зловреден код.

 

Unchecky-Logo_jpg.png


 

- Malwarebytes Anti-Exploit - за информация  MBAE (Malwarebytes Anti-Exploit) vs All EKs (Exploit Kits)
 
screenshot_2014-04-29_004.png

 

- McShield - за предотвратяване на инфекции, разпространявани чрез сменяеми носители

1.JPG

 

Съвети за сигурност - силно препоръчително четене:

 

icon_arrow.gif Едно от важните неща са MICROSOFT UPDATES. Чрез тях можете да получите всички критични актуализации за вашата операционна система и Internet Explorer. Поддържането на вашата операционна система и браузър с актуални ъпдейти, ще помогне да  направи системата по-малко податлива на атаки от троянски коне и вируси. Освен това зловредния софтуер се създава почти всеки ден. Много от тези заплахи, са насочени към уязвими места във вашия  софтуер. Софтуерните компании редовно публикуват актуализации, които определят тези уязвимости.За да останете защитени, трябва да актуализирате редовно целия  си софтуер. Основно внимание на следните програми:

  • Adobe Reader;
  • Adobe Flash Player;
  • Sun Java;
  • Apple QuickTime;
  • Базите и модулите на антивирусните програми
  • наличните браузъри  - обновени и с със задължителни следните аддони:

 

- За Firefox, използвайте NoScript , Adblock , Web Of Trust
- За Chrome използвайте  ScriptSafe ,Adblock Plus for Chrome, WOT (Web от Trust)

 

Цитат

User Account Control disabled
The elevation prompt for administrators disabled
^It is recommended to enable: Win+R typing UserAccountControlSettings and Enter^

icon_arrow.gif Не деактивирайте UAC ..Причината ..: Malwares атакуват компютрите чрез модифициране на системните файлове и регистъра, така че тя ще бъде изпълнена автоматично всеки път, когато компютърът се включи. С включен UAC ще се поиска нашето разрешение преди  malwares атакуват компютрите ни.

 

Прверявайте вашата система за актуални обновления и уязвимости с помощта на следните програми:

 

Накрая, не пренебрегвайте резервно копие на важните данни и файлове на регулярна основа. Създаването на резервно копие е сред най-важните моменти,който трябва да се извършва редовно. Някои инфекции, могат да направят вашия компютър  да не се стартира по време на или преди процеса на дезинфекция. Дори и  компютъра да  не е заразен, архивиране и е част от най-добрите практики в случай на хардуерна или софтуерна или повреда на системата.

back up your important data and files

Също така е добра практика да се направи изображение на диск ( disk image ) с инструмент за възпроизвеждане на изображения ( imaging tool ) - Acronis True Image, Drive Image, Ghost, Macrium Reflect, etc  Disk Imaging ви позволява да направите пълен моментна снимка (изображение) на вашия твърд диск, което може да се използва за възстановяване на системата в случай на проблем.

 

Ако нямате други проблеми и въпроси да приключваме...Маркирам случая за "Решен"...! Пожелавам лека ден и безопасен интернет..! :)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.