Zoek.exe v5.0.0.0 Updated 08-September-2015
Tool run by Susan on Fri 09/11/2015 at 0:37:39.70.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Susan\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
9/11/2015 12:39:30 AM Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\Users\Susan\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Susan\AppData\Local\EmieSiteList deleted successfully
C:\Users\Susan\AppData\Local\EmieUserList deleted successfully
C:\Users\Susan\AppData\Local\PackageAware deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-666262517-897078804-3328256414-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EA3226F9-75B7-492D-AEAF-F051FEC430F8} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\zhemnbvl.default
user.js not found
---- Lines Search removed from prefs.js ----
user_pref("extensions.xpiState", "{\"app-profile\":{\"
bingsearch.full@microsoft.com\":{\"d\":\"C:\\\\Users\\\\Susan\\\\AppData\\\\Roaming\\\\Mozilla\\
---- FireFox user.js and prefs.js backups ----
prefs_20150911_0121_.backup
==== Batch Command(s) Run By Tool======================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
==== Deleting Files \ Folders ======================
C:\PROGRA~3\{FF4D2268-63EF-4017-9D38-9BE01EEF9643} deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\zhemnbvl.default\searchplugins\bingp.xml deleted
C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\zhemnbvl.default\extensions\bingsearch.full@microsoft.com deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\zhemnbvl.default
user_pref("browser.startup.homepage", "
Google");
user_pref("browser.search.defaultenginename", "Bing ");
user_pref("browser.search.defaultenginename.US", "Secure Search");
user_pref("browser.search.selectedEngine", "Secure Search");
user_pref("keyword.URL", "
Yahoo Search - Web Search");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [05/04/2015 01:26 AM]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [04/30/2015 10:37 AM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"MFVersion"="MF38.0.5 (x86 en-US)" []
==== Firefox Extensions ======================
ProfilePath: C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\zhemnbvl.default
- McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\zhemnbvl.default
18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013
684F2DF31062413E094280891DCB6EE1 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1219160.dll - Shockwave for Director / Shockwave for Director
EC55112EDB2CE5BC2BFCACDB9C2150F4 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll - Shockwave Flash
E3B4EA121F7BDEB0F6366E2BA9608CB5 - C:\Users\Susan\AppData\Local\Citrix\Plugins\104\npappdetector.dll - Citrix Online Web Deployment Plugin 1.0.0.104
==== Chromium Look ======================
Google Chrome Version: 45.0.2454.85
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[04/29/2015 04:07 PM]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
bmkckgpgekmanipelfidlhmkfcjicion - No path found[]
Google Voice Search Hotword (Beta) - Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
{searchTerms} - Google Search"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
{searchTerms} - Bing"
{652B4C65-E555-408E-93B2-247C7EFBCF81} Google Url="
{searchTerms} - Google Search"
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Susan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Susan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Susan\AppData\Local\Mozilla\Firefox\Profiles\zhemnbvl.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
Sorry -- I didn't post the resulting file. Here it is. ==== C:\zoek_backup content ======================
C:\zoek_backup (files=18 folders=3 10860799 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Susan\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Susan\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on Fri 09/11/2015 at 1:45:27.56 ======================
Scan with Farbar Recovery Scan Tool
Please re-run
Farbar Recovery Scan Tool to give me a fresh look at your system.
- Right-click on
icon and select
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Make sure that Addition option is checked.
- Press Scan button and wait.
- The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
I hope including them as uploads is OK -- Pls let me know if it isn't. Here they are.