Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 26-9-2014 Scan Time: 18:12:28 Logfile: MBAM Scanlog.txt Administrator: Yes Version: 2.00.0.1000 Malware Database: v2014.09.26.06 Rootkit Database: v2014.09.19.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Chameleon: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Koos Scan Type: Threat Scan Result: Completed Objects Scanned: 316184 Time Elapsed: 23 min, 18 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Shuriken: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 2 PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{CE681A67-9477-CBE6-EB9D-FE534875F98D}, , [f747cb278af10f27c3e9c0cefa08d12f], PUP.Optional.ReMarkit.A, HKU\S-1-5-21-1845523287-1893952805-4285506245-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Re-markit, , [c9754ca6384316203a7c3fca956e1be5], Registry Values: 2 PUP.Optional.Ask.A, HKU\S-1-5-21-1845523287-1893952805-4285506245-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [6dd1ce2427543204f000414c6b97ce32], PUP.Optional.Ask.A, HKU\S-1-5-21-1845523287-1893952805-4285506245-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{4F524A2D-5350-4500-76A7-7A786E7484D7}, 䨭?卐??ꝶ硺???, , [6dd1ce2427543204f000414c6b97ce32] Registry Data: 1 PUP.Optional.SimplyTech.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|newtab, %appdata%\SimplyTech\home\home.htm, Good: (www.google.com), Bad: (%appdata%\SimplyTech\home\home.htm),,[79c5fcf683f8a0966b4a53b0e22335cb] Folders: 0 (No malicious items detected) Files: 1 PUP.Optional.BuenoSearch.A, C:\Users\Koos\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "variations_seed_signature": "MEUCIHz147i/WR3/zK77lw8a/LmcwZfGUPVlgm2wo4B3aBJSAiEA3dK8ZcbMAFHj/0piF+MHSTCxP6+Qt79AQo8nXsS+B58=" ,"homepage":"http://www.buenosearch.com/?babsrc=HP_kms&affID=128493&tt=&mntrid=96C10C6076525DE7&tsp=5345","homepage_is_newtabpage":false,"netLength":4625,"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13051030151661501","restore_on_startup":4,"urls_to_restore_on_startup":["http://www.buenosearch.com/?babsrc=HP_kms&affID=128493&tt=&mntrid=96C10C6076525DE7&tsp=5345"],"startup_urls":["http://www.buenosearch.com/?babsrc=HP_kms&affID=128493&tt=&mntrid=96C10C6076525DE7&tsp=5345"]},"default_search_provider_data":{"template_url_data":{"favicon_url":"","keyword":"buenosearch","short_name":"buenosearch","url":"http://www.buenosearch.com/?babsrc=SP_kms&affID=128493&tt=&mntrid=96C10C6076525DE7&tsp=5345&q={searchTerms}"}},"homepage":"http://www.buenosearch.com/?babsrc=HP_kms&affID=128493&tt=&mntrid=96C10C6076525DE7&tsp=5345","homepage_is_newtabpage":false,"netLength":4625}), ,[53ebfcf6b6c5181eacddd171b3528878] Physical Sectors: 0 (No malicious items detected) (end)