It all started with mystartsearch which installed a browser plugin and redirecting my home page to its website. I uninstalled it via the control panel and removed the browser plugin, after a couple days I found blocknsurf 'ads' and coupon popups and generally a new window would open every once in a while when I'm browsing.
Currently I'm running Avira Free and CCleaner
I've followed the 4-step process:
I'm facing a issue with DDS with the following message "DDS is not meant to run in 'Compatibility Mode'. The program shall now exit."
here is the log from MBAM:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 31-01-2015
Scan Time: 10:24:48 PM
Logfile: MBAM scan 31-Jan-2015.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.31.04
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Alaistair
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 335804
Time Elapsed: 6 min, 36 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 26
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [b838f4098efb82b445e8d42a3fc38c74],
PUP.Optional.SoftwareUpdater.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SoftwareUpdater, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.Webinstr.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\webinstrNHKT, Quarantined, [856b5da0addccd69f33a90f1e122f40c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [ec049667f49547ef238c7645e81b1ee2],
PUP.Optional.CinemaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CinPlus-2.7cV26.01, Quarantined, [0be509f43356ba7c97463652a65d0bf5],
PUP.Optional.CinemaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CinPlus-2.7cV26.01-nv, Quarantined, [0ae67588cebbee489845c6c240c3fb05],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, Quarantined, [31bfe4195534023451911a68996ab64a],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, Quarantined, [6d837786fa8fca6c7a4b7e0ce41f58a8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [7c74817cec9d47efb23fa8f8af544bb5],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [0ae659a4bacf60d60aa52497f80b7888],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [db15d22b48411d199c221fe10cf909f7],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [866a5ba25d2ce155bf00ab550203fe02],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [5a96e51813767bbb38b4800dd62da060],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CinPlus-2.7cV26.01-nv, Delete-on-Reboot, [c52b926ba7e2a88ea13d04848f7407f9],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\BlockAndSurf, Delete-on-Reboot, [26cae31af89148ee25bc019c5ca7bf41],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\CinPlus-2.7cV26.01, Delete-on-Reboot, [e40c22dbe5a4c4728758e5a34cb7b44c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Delete-on-Reboot, [ad436895395096a06476494bf310bc44],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Cinema Plus2.7hV26.01, Delete-on-Reboot, [07e9728bf99056e0ef6f7712ef142ed2],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\CLSID\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{D5A07853-7ABD-108A-8F7C-09E0CCB418A5}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C14C09A-E6AA-569A-779D-6E3215903171}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C14C09A-E6AA-569A-779D-6E3215903171}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{D5A07853-7ABD-108A-8F7C-09E0CCB418A5}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Delete-on-Reboot, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Delete-on-Reboot, [a54b36c7f990c4724141e7ccb154b749],
Registry Values: 2
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [7c74817cec9d47efb23fa8f8af544bb5]
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SOFTWAREUPDATER|UninstallString, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\Uninstall.exe, Quarantined, [f5fb7885f2972b0b54faff00bb49659b]
Registry Data: 13
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...),Replaced,[7f711be2aadf90a6e26459480ef73bc5]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[9858bd405732db5b147ce9b830d5b44c]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[1fd1ae4ff198ca6cace3e2bf2bdaab55]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[bd33f00d5a2fb77f47d1258a5fa6da26]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[d9170eefc6c31b1b6928990829dce31d]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[60901de06f1aa29460ff7b323bcade22]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...),Replaced,[9d5369946722290df155950cda2baf51]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[cc2453aad0b9cd69068a8b16679ec040]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[e60a96675e2b142298f7138e0ff6a55b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[846c8875cfba4beb37e1f9b656af728e]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[3fb112eb8cfd81b5236e911011f45fa1]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[80709865bbce8caa4817cfde0df83fc1]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...-on-Reboot,[bf31b5486c1dcc6a72209e03eb1a5ea2]
Folders: 2
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
Files: 26
PUP.Optional.Nova.A, C:\Program Files (x86)\24ca4bef-13f4-41f4-9407-1aa1d58eb814\d8d03eda-719d-4cf3-9080-2a2abcf39db2.dll, Quarantined, [519fb647038656e063169570aa58926e],
PUP.Optional.Nova.A, C:\Program Files (x86)\Apple Software Update\437322b1-3a5f-49b0-b8ea-abbf70e56304.dll, Quarantined, [db15c736d6b32c0a98e18f76c43e1ae6],
PUP.Optional.Cgminer, C:\Windows\Installer\233679.msi, Quarantined, [955b6499d1b865d1223f1850fc057c84],
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, Quarantined, [be3264994b3e40f653b30a7752b10000],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\Uninstall.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\SoftwareUpdater.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\surunasu.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\SUSetup.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\UpdateNotifier.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.Webinstr.A, C:\Windows\System32\drivers\webinstrNHKT.sys, Quarantined, [856b5da0addccd69f33a90f1e122f40c],
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf, Quarantined, [a24ecf2e0c7d6dc980b4bac8877c49b7],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder\RootCert.cer, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder\makecert.exe, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder\storage.bin, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-1, Quarantined, [3bb5609d771230069b51326e63a0669a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-2, Quarantined, [5a966499553477bf13d9e5bbe91ace32],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5, Quarantined, [ac44a954cbbe4cea2fbdecb4758e9f61],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5_user, Quarantined, [f6fa9c61e3a631051ece6b356f9424dc],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-6, Quarantined, [945c53aab6d35cdaec001888d23137c9],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-7, Quarantined, [678909f41c6dbc7a4d9f1e82a16225db],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-1.job, Quarantined, [4da38d7032579c9abe9d1ae47c88b14f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-2.job, Quarantined, [569a2ad38bfe4beba2b9758933d1ac54],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5.job, Quarantined, [e80818e5becbce689ebd8b73ce36c53b],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5_user.job, Quarantined, [965a23da90f995a13f1c708e16eefe02],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-6.job, Quarantined, [b33d96671277c373332848b6e2221de3],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-7.job, Quarantined, [529e54a90980f046f962748a11f337c9],
Physical Sectors: 0
(No malicious items detected)
(end)
Currently I'm running Avira Free and CCleaner
I've followed the 4-step process:
I'm facing a issue with DDS with the following message "DDS is not meant to run in 'Compatibility Mode'. The program shall now exit."
here is the log from MBAM:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 31-01-2015
Scan Time: 10:24:48 PM
Logfile: MBAM scan 31-Jan-2015.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.31.04
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Alaistair
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 335804
Time Elapsed: 6 min, 36 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 26
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [b838f4098efb82b445e8d42a3fc38c74],
PUP.Optional.SoftwareUpdater.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SoftwareUpdater, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.Webinstr.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\webinstrNHKT, Quarantined, [856b5da0addccd69f33a90f1e122f40c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [ec049667f49547ef238c7645e81b1ee2],
PUP.Optional.CinemaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CinPlus-2.7cV26.01, Quarantined, [0be509f43356ba7c97463652a65d0bf5],
PUP.Optional.CinemaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CinPlus-2.7cV26.01-nv, Quarantined, [0ae67588cebbee489845c6c240c3fb05],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, Quarantined, [31bfe4195534023451911a68996ab64a],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, Quarantined, [6d837786fa8fca6c7a4b7e0ce41f58a8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [7c74817cec9d47efb23fa8f8af544bb5],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [0ae659a4bacf60d60aa52497f80b7888],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [db15d22b48411d199c221fe10cf909f7],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [866a5ba25d2ce155bf00ab550203fe02],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [5a96e51813767bbb38b4800dd62da060],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CinPlus-2.7cV26.01-nv, Delete-on-Reboot, [c52b926ba7e2a88ea13d04848f7407f9],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\BlockAndSurf, Delete-on-Reboot, [26cae31af89148ee25bc019c5ca7bf41],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\CinPlus-2.7cV26.01, Delete-on-Reboot, [e40c22dbe5a4c4728758e5a34cb7b44c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Delete-on-Reboot, [ad436895395096a06476494bf310bc44],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Cinema Plus2.7hV26.01, Delete-on-Reboot, [07e9728bf99056e0ef6f7712ef142ed2],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\CLSID\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{D5A07853-7ABD-108A-8F7C-09E0CCB418A5}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C14C09A-E6AA-569A-779D-6E3215903171}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C14C09A-E6AA-569A-779D-6E3215903171}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{D5A07853-7ABD-108A-8F7C-09E0CCB418A5}, Quarantined, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Delete-on-Reboot, [a54b36c7f990c4724141e7ccb154b749],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C330D4EC-AFE2-9A69-CAAD-C5E77FABCBCB}, Delete-on-Reboot, [a54b36c7f990c4724141e7ccb154b749],
Registry Values: 2
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [7c74817cec9d47efb23fa8f8af544bb5]
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SOFTWAREUPDATER|UninstallString, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\Uninstall.exe, Quarantined, [f5fb7885f2972b0b54faff00bb49659b]
Registry Data: 13
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...),Replaced,[7f711be2aadf90a6e26459480ef73bc5]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[9858bd405732db5b147ce9b830d5b44c]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[1fd1ae4ff198ca6cace3e2bf2bdaab55]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[bd33f00d5a2fb77f47d1258a5fa6da26]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[d9170eefc6c31b1b6928990829dce31d]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[60901de06f1aa29460ff7b323bcade22]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=...),Replaced,[9d5369946722290df155950cda2baf51]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[cc2453aad0b9cd69068a8b16679ec040]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[e60a96675e2b142298f7138e0ff6a55b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...),Replaced,[846c8875cfba4beb37e1f9b656af728e]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://www.mystartsearch.com/web/?t...840XEVOX120GB_S1D5NSAF599506N&q={searchTerms}, Good: (www.google.com), Bad: (http://www.mystartsearch.com/web/?t...),Replaced,[3fb112eb8cfd81b5236e911011f45fa1]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[80709865bbce8caa4817cfde0df83fc1]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2463482003-2002589441-2981365847-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.mystartsearch.com/?type=...uid=SamsungXSSDX840XEVOX120GB_S1D5NSAF599506N, Good: (www.google.com), Bad: (http://www.mystartsearch.com/?type=...-on-Reboot,[bf31b5486c1dcc6a72209e03eb1a5ea2]
Folders: 2
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
Files: 26
PUP.Optional.Nova.A, C:\Program Files (x86)\24ca4bef-13f4-41f4-9407-1aa1d58eb814\d8d03eda-719d-4cf3-9080-2a2abcf39db2.dll, Quarantined, [519fb647038656e063169570aa58926e],
PUP.Optional.Nova.A, C:\Program Files (x86)\Apple Software Update\437322b1-3a5f-49b0-b8ea-abbf70e56304.dll, Quarantined, [db15c736d6b32c0a98e18f76c43e1ae6],
PUP.Optional.Cgminer, C:\Windows\Installer\233679.msi, Quarantined, [955b6499d1b865d1223f1850fc057c84],
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, Quarantined, [be3264994b3e40f653b30a7752b10000],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\Uninstall.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\SoftwareUpdater.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\surunasu.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\SUSetup.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.SoftwareUpdater.A, C:\Users\Alaistair\AppData\Roaming\SoftwareUpdater\UpdateNotifier.exe, Quarantined, [3ab659a47118ee48b756d8a955aef907],
PUP.Optional.Webinstr.A, C:\Windows\System32\drivers\webinstrNHKT.sys, Quarantined, [856b5da0addccd69f33a90f1e122f40c],
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf, Quarantined, [a24ecf2e0c7d6dc980b4bac8877c49b7],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder\RootCert.cer, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder\makecert.exe, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
PUP.Optional.TheAnswerFinder.A, C:\Users\Alaistair\AppData\Roaming\TheAnswerFinder\storage.bin, Quarantined, [48a8ec1129606bcbb731107717ec7e82],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-1, Quarantined, [3bb5609d771230069b51326e63a0669a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-2, Quarantined, [5a966499553477bf13d9e5bbe91ace32],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5, Quarantined, [ac44a954cbbe4cea2fbdecb4758e9f61],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5_user, Quarantined, [f6fa9c61e3a631051ece6b356f9424dc],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-6, Quarantined, [945c53aab6d35cdaec001888d23137c9],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-7, Quarantined, [678909f41c6dbc7a4d9f1e82a16225db],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-1.job, Quarantined, [4da38d7032579c9abe9d1ae47c88b14f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-2.job, Quarantined, [569a2ad38bfe4beba2b9758933d1ac54],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5.job, Quarantined, [e80818e5becbce689ebd8b73ce36c53b],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-5_user.job, Quarantined, [965a23da90f995a13f1c708e16eefe02],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-6.job, Quarantined, [b33d96671277c373332848b6e2221de3],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\92a6edf7-aafc-44a2-92cb-71df4e170c31-7.job, Quarantined, [529e54a90980f046f962748a11f337c9],
Physical Sectors: 0
(No malicious items detected)
(end)