While checking on another problem I checked Process Guards always allowed list and found 2 instances of WhenU allways allowed. Now all I can think of is they were part of something else I allowed as I would not have allowed that on any machine. I did delete them and reran my spyware scans. Found no more trace of whenU. None of my spyware scanners had detected it, I guess cause it was in the Guards protected list? Is that correct?