WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionNeed to remove "Mystartsearch"  EmptyNeed to remove "Mystartsearch"

more_horiz
Hey

Everytime I open my internet an extra tab called "mystartsearch" opens as well.
I have gone into the settings tab and removed all add ons, but it keeps coming back.
I have also run the 3 programs you suggest and will now include the reports.

Regards,
Marthinus

Report 1

# AdwCleaner v4.105 - Report created 12/12/2014 at 10:27:58
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : user - USER-PC
# Running from : C:\Users\user\Downloads\adwcleaner_4.105.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Skype C2C Service

***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17420


-\\ Google Chrome v39.0.2171.71

[C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.mystartsearch.com/?type=hp&ts=1417369056&from=wpc&uid=HitachiXHTS545025B9A300_091113PB42061SCV2AELX
[C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.mystartsearch.com/?type=hp&ts=1417369056&from=wpc&uid=HitachiXHTS545025B9A300_091113PB42061SCV2AELX

*************************

AdwCleaner[R0].txt - [3443 octets] - [31/10/2013 10:54:44]
AdwCleaner[R1].txt - [10599 octets] - [21/06/2014 16:14:59]
AdwCleaner[R2].txt - [1460 octets] - [26/09/2014 15:10:07]
AdwCleaner[R3].txt - [1164 octets] - [02/10/2014 20:01:33]
AdwCleaner[R4].txt - [1310 octets] - [17/10/2014 12:47:33]
AdwCleaner[R5].txt - [1709 octets] - [22/11/2014 15:59:51]
AdwCleaner[R6].txt - [1773 octets] - [22/11/2014 16:04:21]
AdwCleaner[R7].txt - [3092 octets] - [30/11/2014 20:32:13]
AdwCleaner[R8].txt - [2541 octets] - [12/12/2014 10:19:39]
AdwCleaner[S0].txt - [3495 octets] - [31/10/2013 10:57:33]
AdwCleaner[S1].txt - [8952 octets] - [21/06/2014 16:17:33]
AdwCleaner[S2].txt - [1539 octets] - [26/09/2014 15:11:14]
AdwCleaner[S3].txt - [1226 octets] - [02/10/2014 20:03:08]
AdwCleaner[S4].txt - [1367 octets] - [17/10/2014 12:49:37]
AdwCleaner[S5].txt - [1846 octets] - [22/11/2014 16:06:01]
AdwCleaner[S6].txt - [3779 octets] - [30/11/2014 20:35:13]
AdwCleaner[S7].txt - [2476 octets] - [12/12/2014 10:27:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S7].txt - [2536 octets] ##########

Report 2:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2014/12/12
Scan Time: 09:38:05 AM
Logfile: mbam 12-12-2014_1.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2014.12.12.02
Rootkit Database: v2014.12.08.03
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: user

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 340920
Time Elapsed: 20 min, 44 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
PUP.Optional.MyStartSearch.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage, Quarantined, [1dd5461b304c3501a8f0ce7f7390738d],
PUP.Optional.MyStartSearch.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage-journal, Quarantined, [1fd3e8795527979fdbbd56f733d0da26],

Physical Sectors: 0
(No malicious items detected)


(end)

Malwarebytes Anti-Malware
www.malwarebytes.org


Update, 2014/12/12 09:34:22 AM, SYSTEM, USER-PC, Manual, program, 2.0.3.1025, 2.0.4.1028,
Update, 2014/12/12 09:35:57 AM, SYSTEM, USER-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 2014/12/12 09:35:57 AM, SYSTEM, USER-PC, Manual, Rootkit Database, 2014.11.18.1, 2014.12.8.3,
Update, 2014/12/12 09:36:24 AM, SYSTEM, USER-PC, Manual, Malware Database, 2014.11.20.6, 2014.12.12.2,
Scan, 2014/12/12 10:12:16 AM, SYSTEM, USER-PC, Manual, Start:2014/12/12 09:38:05 AM, Duration:20 min 44 sec, Threat Scan, Completed, 0 Malware Detections, 2 Non-Malware Detections,

(end)

Report 3:

Results of screen317's Security Check version 0.99.93  
Windows 7 Service Pack 1 x86 (UAC is disabled!)  
Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!  
Microsoft Security Essentials  
Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 51  
Java 8    
Java version 32-bit out of Date!
 Adobe Flash Player 15.0.0.239 Flash Player out of Date!  
Adobe Reader XI  
Google Chrome (39.0.2171.65)
Google Chrome (39.0.2171.71)
````````Process Check: objlist.exe by Laurent````````  
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.


First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
*********************************************
Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.

descriptionNeed to remove "Mystartsearch"  EmptyRemoving Mystartsearch (BuyNsave)

more_horiz
Hey Dave

Thanx for your prompt reply!
My Google Chrome went totally haywire yesterday, but luckily I was able to follow your instructions from Windows Internet Explorer.

I have noticed that in Google Chrome the addon: BuyNsave 3,64 is added evrytime even if I delete it.
Crome seems to be working fine now OK, but the extra tab with Mystartsearch still loads automatically evrytime.

Here are the two logs you asked for:

Mbar:
Malwarebytes Anti-Rootkit BETA 1.08.2.1001
www.malwarebytes.org

Database version: v2014.12.13.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17501
user :: USER-PC [administrator]

2014/12/13 11:24:24 AM
mbar-log-2014-12-13 (11-24-24).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 343637
Time elapsed: 23 minute(s), 9 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)


System-log:

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.08.2.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 11.0.9600.17501

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.095000 GHz
Memory total: 2072956928, free: 1146998784

Downloaded database version: v2014.12.13.02
Downloaded database version: v2014.12.08.03
Downloaded database version: v2014.12.06.01
Initializing...
======================
------------ Kernel report ------------
12/13/2014 11:24:06
------------ Loaded modules -----------
\SystemRoot\system32\ntkrnlpa.exe
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\vmbus.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\DRIVERS\MpFilter.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\igdkmd32.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\NETw5s32.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\L1C62x86.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\DKbFltr.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_msahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\vodafone_zte_cdc_acm.sys
\SystemRoot\system32\drivers\modem.sys
\SystemRoot\system32\DRIVERS\vodafone_zte_ecm_enum.sys
\SystemRoot\system32\DRIVERS\vodafone_zte_ecm_enum_filter.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\vodafone_zte_cdc_ecm.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\NisDrvWFP.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\System32\Drivers\mvusbews.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\setupapi.dll
\Windows\System32\msctf.dll
\Windows\System32\imagehlp.dll
\Windows\System32\msvcrt.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\difxapi.dll
\Windows\System32\ws2_32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\nsi.dll
\Windows\System32\gdi32.dll
\Windows\System32\wininet.dll
\Windows\System32\normaliz.dll
\Windows\System32\Wldap32.dll
\Windows\System32\shell32.dll
\Windows\System32\sechost.dll
\Windows\System32\kernel32.dll
\Windows\System32\imm32.dll
\Windows\System32\advapi32.dll
\Windows\System32\psapi.dll
\Windows\System32\usp10.dll
\Windows\System32\oleaut32.dll
\Windows\System32\user32.dll
\Windows\System32\ole32.dll
\Windows\System32\lpk.dll
\Windows\System32\urlmon.dll
\Windows\System32\clbcatq.dll
\Windows\System32\iertutil.dll
\Windows\System32\shlwapi.dll
\Windows\System32\wintrust.dll
\Windows\System32\comctl32.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\userenv.dll
\Windows\System32\devobj.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\profapi.dll
\Windows\System32\msasn1.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff85a1b030
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-0\
Lower Device Object: 0xffffffff8593b030
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff85a1b030, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff85a1bd10, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff85a1b030, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8593b030, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 240E2C87

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 204800
Partition file system is NTFS
Partition is bootable

Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 206848 Numsec = 488187904

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 250059350016 bytes
Sector size: 512 bytes

Done!
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to you download folder you will need to copy it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:

Need to remove "Mystartsearch"  NSIS_disclaimer_ENG

Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:

Need to remove "Mystartsearch"  NSIS_extraction

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.

Need to remove "Mystartsearch"  RcAuto1

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Need to remove "Mystartsearch"  Whatnext

Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

descriptionNeed to remove "Mystartsearch"  EmptyCombofix report

more_horiz
Hey

Followed the steps. Here's the report you requested.

ComboFix 14-12-10.03 - user 2014/12/14 11:43:08.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.27.1033.18.1977.1147 [GMT 2:00]
Running from: c:\users\user\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2014-11-14 to 2014-12-14 )))))))))))))))))))))))))))))))
.
.
2014-12-14 09:49 . 2014-12-14 09:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-14 09:49 . 2014-12-14 09:49 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-12-14 09:33 . 2014-12-14 09:33 39464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9E6CFF6-3C6B-41DA-91CE-36E114939772}\MpKsl9f5ee3b9.sys
2014-12-13 10:03 . 2014-11-02 04:17 8941456 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9E6CFF6-3C6B-41DA-91CE-36E114939772}\mpengine.dll
2014-12-13 09:24 . 2014-12-13 09:48 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-12-13 08:21 . 2014-12-13 08:21 -------- d-----w- c:\program files\Common Files\Java
2014-12-12 07:29 . 2014-11-11 02:44 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-12-12 07:27 . 2014-11-27 01:10 815280 ----a-w- c:\program files\Internet Explorer\iexplore.exe
2014-12-12 07:26 . 2014-09-17 05:52 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9D215B8B-0F5F-469F-B912-BB38B129121F}\gapaengine.dll
2014-12-12 07:25 . 2014-11-02 04:17 8941456 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-11-30 18:29 . 2014-11-30 18:31 -------- d-----w- c:\programdata\MFAData
2014-11-30 18:29 . 2014-11-30 18:29 -------- d--h--w- c:\programdata\Common Files
2014-11-30 18:29 . 2014-11-30 18:29 -------- d-----w- c:\users\user\AppData\Local\MFAData
2014-11-30 18:29 . 2014-11-30 18:29 -------- d-----w- c:\users\user\AppData\Local\Avg2015
2014-11-30 17:27 . 2014-11-30 17:27 -------- d-----w- c:\programdata\gponcfdndaijlkafcapmlahdmgofnjoe
2014-11-19 03:45 . 2014-11-11 02:44 186880 ----a-w- c:\windows\system32\pku2u.dll
2014-11-19 03:45 . 2014-11-11 02:44 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-11-18 12:56 . 2014-11-18 12:56 1202848 ----a-w- c:\windows\system32\FM20.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-13 18:52 . 2012-12-11 10:08 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-13 18:52 . 2012-12-11 10:08 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-12-13 09:24 . 2014-09-26 13:19 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-13 09:22 . 2014-09-26 13:18 79576 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-12-13 09:19 . 2014-02-10 06:46 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-11-21 04:14 . 2014-09-26 13:18 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-21 04:14 . 2014-09-26 13:18 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-10-30 11:24 . 2012-12-12 12:11 229000 ------w- c:\windows\system32\MpSigStub.exe
2014-10-25 01:32 . 2014-11-12 04:12 67584 ----a-w- c:\windows\system32\packager.dll
2014-10-18 01:33 . 2014-11-12 04:12 571904 ----a-w- c:\windows\system32\oleaut32.dll
2014-10-14 01:56 . 2014-11-12 04:11 136632 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-10-14 01:50 . 2014-11-12 04:11 523776 ----a-w- c:\windows\system32\termsrv.dll
2014-10-14 01:50 . 2014-11-12 04:11 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-10-14 01:47 . 2014-11-12 04:11 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-10-14 01:46 . 2014-11-12 04:11 681984 ----a-w- c:\windows\system32\adtschema.dll
2014-10-12 14:30 . 2014-08-21 06:06 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-10-10 00:45 . 2014-11-12 04:12 2379264 ----a-w- c:\windows\system32\win32k.sys
2014-10-09 12:52 . 2014-08-14 14:01 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-10-03 01:44 . 2014-11-12 04:12 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2014-10-03 01:44 . 2014-11-12 04:12 275968 ----a-w- c:\windows\system32\EncDump.dll
2014-10-03 01:44 . 2014-11-12 04:12 475136 ----a-w- c:\windows\system32\audiosrv.dll
2014-10-03 01:44 . 2014-11-12 04:12 374784 ----a-w- c:\windows\system32\AudioEng.dll
2014-10-03 01:44 . 2014-11-12 04:12 195584 ----a-w- c:\windows\system32\AudioSes.dll
2014-09-19 09:23 . 2014-11-12 04:12 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-09-19 09:23 . 2014-11-12 04:12 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-09-19 09:23 . 2014-11-12 04:12 248832 ----a-w- c:\windows\system32\schannel.dll
2014-09-19 09:23 . 2014-11-12 04:12 221184 ----a-w- c:\windows\system32\ncrypt.dll
2014-09-19 09:23 . 2014-11-12 04:12 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-09-19 09:23 . 2014-11-12 04:12 17408 ----a-w- c:\windows\system32\credssp.dll
2014-09-17 05:52 . 2013-03-27 09:20 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\user\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GarminExpressTrayApp"="c:\program files\Garmin\Express Tray\ExpressTray.exe" [2013-11-08 1095000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-08-18 1157640]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2011-07-14 279552]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-11-20 1021128]
.
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-11-13 35419192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag.sys [2014-05-27 23168]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem.sys [2014-05-27 27776]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-11-22 102912]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 95920]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2014-08-22 288120]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 vodafone_zte_cpo;Vodafone Vodafone ZTE Install;c:\windows\system32\DRIVERS\vodafone_zte_cpo.sys [2011-05-20 9984]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-12-11 1343400]
S1 MpKsl9f5ee3b9;MpKsl9f5ee3b9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9E6CFF6-3C6B-41DA-91CE-36E114939772}\MpKsl9f5ee3b9.sys [2014-12-14 39464]
S2 Garmin Core Update Service;Garmin Core Update Service;c:\program files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2013-11-08 250712]
S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2009-12-03 99896]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2011-07-14 9216]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-13 50688]
S3 mvusbews;USB EWS Device;c:\windows\system32\Drivers\mvusbews.sys [2009-12-03 17408]
S3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816]
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [2010-09-01 61952]
S3 vodafone_zte_cdc_acm;Vodafone Vodafone ZTE CDC-ACM driver (ZTE);c:\windows\system32\DRIVERS\vodafone_zte_cdc_acm.sys [2011-05-20 67968]
S3 vodafone_zte_cdc_ecm;vodafone_zte_cdc_ecm;c:\windows\system32\DRIVERS\vodafone_zte_cdc_ecm.sys [2011-05-20 52224]
S3 vodafone_zte_ecm_enum;Vodafone Vodafone ZTE DC Enumerator (ZTE);c:\windows\system32\DRIVERS\vodafone_zte_ecm_enum.sys [2011-05-20 47488]
S3 vodafone_zte_ecm_enum_filter;vodafone_zte_ecm_enum_filter;c:\windows\system32\DRIVERS\vodafone_zte_ecm_enum_filter.sys [2011-05-20 47488]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL9F5EE3B9
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-11-26 05:26 1087304 ----a-w- c:\program files\Google\Chrome\Application\39.0.2171.71\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-12-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-11 18:52]
.
2014-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-11 09:14]
.
2014-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-12-11 09:14]
.
.
------- Supplementary Scan -------
.
uStart Page = www.google.com
mStart Page = www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: Interfaces\{31C2065A-3D4B-4F63-8233-79CB20897662}: NameServer = 196.207.32.83 196.207.32.69
TCP: Interfaces\{C94DD8A2-DF61-4101-9FC2-3B365208FAAC}: NameServer = 196.207.32.83 196.207.32.69
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1223691178-2309870278-1147259856-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:ea,b0,76,f5,95,8a,c4,1c,1f,f3,bf,f8,ce,d4,52,b4,35,4d,d3,ef,38,
80,93,07,aa,d8,2c,3e,cb,27,c8,1f,a9,be,1b,38,35,b1,e5,b4,cd,11,28,3b,5b,1e,\
"rkeysecu"=hex:55,d2,1e,22,c7,79,73,81,d4,12,a7,2e,30,14,9e,90
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-12-14 11:51:17
ComboFix-quarantined-files.txt 2014-12-14 09:51
.
Pre-Run: 99 099 602 944 bytes free
Post-Run: 98 767 794 176 bytes free
.
- - End Of File - - E90CAA66427370B301955DEEDE46419E
A36C5E4F47E84449FF07ED3517B43A31

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the Need to remove "Mystartsearch"  EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on Need to remove "Mystartsearch"  EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the Need to remove "Mystartsearch"  EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check Need to remove "Mystartsearch"  EsetAcceptTerms
•Click the Need to remove "Mystartsearch"  EsetStart button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check Need to remove "Mystartsearch"  EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push Need to remove "Mystartsearch"  EsetListThreats
•Push Need to remove "Mystartsearch"  EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the Need to remove "Mystartsearch"  EsetBack button.
•Push Need to remove "Mystartsearch"  EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionNeed to remove "Mystartsearch"  EmptyEset results

more_horiz
Hey Dave!

Thanks again for all your trouble. Big Grin
It seems that the "mystartsearch" Tab/Toolbar is now gone, but the "BuyNsave" extension still loads itself.

Here follows the list of threats picked up by the ESET Scan:

C:\AdwCleaner\Quarantine\C\Program Files\File Type Assistant\ftacfg.exe.vir Win32/FileTypeAssistant.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\File Type Assistant\TSASetup.exe.vir a variant of Win32/FileTypeAssistant.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\File Type Assistant\tsassist.exe.vir a variant of Win32/FileTypeAssistant.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\File Type Assistant\temp\~tmp.exe.vir a variant of Win32/FileTypeAssistant.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir Win32/Toolbar.Babylon.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\users\user\AppData\Roaming\Systweak\ssd\SSDPTstub.exe.vir Win32/Systweak.G potentially unwanted application
C:\AdwCleaner\Quarantine\C\Windows\System32\roboot.exe.vir a variant of Win32/Systweak.A potentially unwanted application
C:\ProgramData\gponcfdndaijlkafcapmlahdmgofnjoe\oiqH.js JS/Kryptik.ATB trojan
C:\Users\All Users\gponcfdndaijlkafcapmlahdmgofnjoe\oiqH.js JS/Kryptik.ATB trojan
C:\Users\user\AppData\Roaming\1O1L1I1PtF1F1C1N\Java Platform SE Free Download Packages\uninstaller.exe Win32/InstallCore.PC potentially unwanted application
C:\Users\user\AppData\Roaming\1O1L1I1PtF1F1C1N\VLC media player Free Download Packages\uninstaller.exe Win32/InstallCore.PC potentially unwanted application
C:\Users\user\Downloads\Download.exe a variant of Win32/Adware.MultiPlug.DZ application
C:\Users\user\Downloads\FreeFileViewerSetup [1].exe a variant of Win32/FileTypeAssistant.A potentially unwanted application
C:\Users\user\Downloads\Logitech_QuickCam_V-UCU56_Driver_Update_03-2014 (1).exe a variant of Win32/Systweak.H potentially unwanted application
C:\Users\user\Downloads\Logitech_QuickCam_V-UCU56_Driver_Update_03-2014 (2).exe a variant of Win32/Systweak.H potentially unwanted application
C:\Users\user\Downloads\Logitech_QuickCam_V-UCU56_Driver_Update_03-2014.exe a variant of Win32/Systweak.H potentially unwanted application
C:\Users\user\Downloads\SkypeSetup-18800929-vffsb.exe Win32/InstallCore.PC potentially unwanted application

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
but the "BuyNsave" extension still loads itself.

How do you see that? How does it affect your computer?

descriptionNeed to remove "Mystartsearch"  EmptyBuyNsave 3,64

more_horiz
Hey Dave

I delete it time and time again and it goes away, but as soon as I open and close Chrome it is back under my extensions. I have tried enabling and disabling it.

I attach a word file with screen snips of what I see under Chrome Extensions and what it shows me if I click on permissions. I'll call the file "BuyNsave Screen Snips"

I am not sure it is a threat and for the moment I don't have problems, but I find that, randomly, I get popup adds when using Chrome. Computer programs to pornsites. Anything and once that starts the whole thing goes crazy.


descriptionNeed to remove "Mystartsearch"  EmptyPop up Ad

more_horiz
Hey Dave

It just happened again.
I attach a word file with a snip of the ad that always appears first just before things go crazy.

Marthinus

descriptionNeed to remove "Mystartsearch"  EmptyAttachment 2

more_horiz
Sorry I see I missed the attachments...

descriptionNeed to remove "Mystartsearch"  EmptyAttachment 1

more_horiz
The attachment that was supposed to accompany my previous message...

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
You could try uninstalling and re-installing Chrome.

descriptionNeed to remove "Mystartsearch"  EmptyResult

more_horiz
Thanks Dave!

It all seems fine again now.

(Unistalled and reinstalled Chrome as you suggetsed)

Thank You!

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
Good. A little bit of cleanup.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.

Need to remove "Mystartsearch"  Diskcleanup2

Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.

Need to remove "Mystartsearch"  Diskcleanup

This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
****************************************
This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:

  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create Registry backup
  • Purge System Restore Points
  • Re-set system settings

Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.
******************************************
I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
Cheers Mate

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

descriptionNeed to remove "Mystartsearch"  EmptyRe: Need to remove "Mystartsearch"

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum