Outlaw Josey Wales,
Thanks for your help! Here you go (also attached).
-Dean
Zoek.exe v5.0.0.0 Updated 02-April-2015
Tool run by dean.harrison on Sun 04/05/2015 at 12:37:18.03.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\dean.harrison\Desktop\Malware\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
4/5/2015 12:38:46 PM Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\PROGRA~2\Batch PDF deleted successfully
C:\Program Files\My Dell deleted successfully
C:\PROGRA~3\Expert PDF 7 deleted successfully
C:\PROGRA~3\Expert PDF Jobs deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\Users\dean.harrison\AppData\Roaming\Expert PDF 7 deleted successfully
C:\Users\dean.harrison\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\dean.harrison\AppData\Local\CrashDumps deleted successfully
C:\Users\dean.harrison\AppData\Local\VirtualStore deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Batch Command(s) Run By Tool======================
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Batch PDF not found
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~2\Mozilla Firefox\extensions\
lesstabs@lesstabs.com deleted
C:\PROGRA~2\Mozilla Firefox\browser\nsprotector.js deleted
C:\PROGRA~2\Mozilla Firefox\vitruvian-autoenable.cfg deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\!vitruvian-autoenable.js deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\!vitruvian-csp.js deleted
C:\PROGRA~2\Mozilla Firefox\browser\defaults\preferences\!vitruvian-autoenable.js deleted
C:\PROGRA~2\Mozilla Firefox\browser\defaults\preferences\!vitruvian-csp.js deleted
C:\PROGRA~2\LessTabs deleted
C:\PROGRA~2\W3i deleted
C:\PROGRA~2\MyPC Backup deleted
C:\PROGRA~3\W3i deleted
C:\PROGRA~3\Winferno deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted
C:\WINDOWS\SysWow64\AI_RecycleBin deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\DEAN~1.HAR\AppData\Roaming\Mozilla\Firefox\Profiles\zzhy5ncz.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.search.defaultenginename", "Yahoo");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
http://www.google.com/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{383101F1-8261-4467-8199-2C13EA3A6B59}"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"
{383101F1-8261-4467-8199-2C13EA3A6B59} Unknown Url="Not_Found"
{70804EBF-5708-443C-B909-8A2A4947A9D3} Google Url="
http://www.google.com/search?q={sea...ource}&ie={inputEncoding?}&oe={outputEncoding?}"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-73945207-3909077387-3593498368-1001\Software\Microsoft\Internet Explorer\SearchScopes\{383101F1-8261-4467-8199-2C13EA3A6B59} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{383101F1-8261-4467-8199-2C13EA3A6B59} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{383101F1-8261-4467-8199-2C13EA3A6B59} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\
lesstabs@lesstabs.com deleted successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\dean.harrison\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\dean.harrison\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\DEAN~1.HAR\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\DEAN~1.HAR\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Users\dean.harrison\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\dean.harrison\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Users\DEAN~1.HAR\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\DEAN~1.HAR\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
==== Empty FireFox Cache ======================
C:\Users\dean.harrison\AppData\Local\Mozilla\Firefox\Profiles\zzhy5ncz.default\cache2 emptied successfully
C:\Users\DEAN~1.HAR\AppData\Local\Mozilla\Firefox\Profiles\zzhy5ncz.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=62 folders=20 1202157 bytes)
==== Empty Temp Folders ======================
C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\dean.harrison\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\DEAN~1.HAR\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\DEAN~1.HAR\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
==== EOF on Sun 04/05/2015 at 13:10:58.83 ======================