I hope this is ok, I couldn't find "Notepad" to upload it
I have looked at D:Users\Lizbee and the "shopping helper smartbar engine" still appears in her list of programs
Zoek.exe v5.0.0.0 Updated 24-12-2014
Tool run by Rob on Sat 27/12/2014 at 23:58:15.35.
Microsoft Windows 8 6.2.9200 x64
Running in: Normal Mode Internet Access Detected
Launched: D:\Users\Rob\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
28/12/2014 12:02:27 AM Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully
C:\Program Files\office.tmp deleted successfully
D:\Users\dylan_000\AppData\Roaming\Apple Computer deleted successfully
D:\Users\Lizbee\AppData\Roaming\BitTorrent deleted successfully
D:\Users\Lizbee\AppData\Roaming\uTorrent deleted successfully
D:\Users\Rob\AppData\Roaming\uTorrent deleted successfully
D:\Users\Robert\AppData\Roaming\.minecraft deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-788829986-3988713853-2924854022-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4929A628-B626-41CC-9EA5-BA91173651B8} deleted successfully
HKEY_USERS\S-1-5-21-788829986-3988713853-2924854022-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{604F777C-6CFC-4DFB-B7D6-C1A91829567F} deleted successfully
HKEY_USERS\S-1-5-21-788829986-3988713853-2924854022-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6D6135D6-4062-4CF1-9CBD-961507EB593} deleted successfully
HKEY_USERS\S-1-5-21-788829986-3988713853-2924854022-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D321E672-6740-4947-993-602C414280AD} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Batch Command(s) Run By Tool======================
==== Deleting Files \ Folders ======================
D:\Users\Lizbee\AppData\Local\nst2194.tmp deleted
D:\Users\Lizbee\AppData\Local\com deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
==== Firefox Start and Search pages ======================
ProfilePath: D:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\upltv1l6.default
user_pref("browser.search.defaultenginename", "Secure Search");
ProfilePath: D:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\72vjhc9c.default
user_pref("browser.search.defaultenginename", "Secure Search");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [19/12/2014 01:08 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04/04/2014 06:36 PM]
==== Firefox Extensions ======================
ProfilePath: D:\Users\Lizbee\AppData\Roaming\Mozilla\Firefox\Profiles\39vj6o4q.default
- Undetermined - {a30b5f37-0a36-419b-d6be-36e1bd3686f2}
- Shopping Helper Smartbar - %ProfilePath%\extensions\{a30b5f37-0a36-419b-d6be-36e1bd3686f2}
ProfilePath: D:\Users\Rob\AppData\Roaming\Mozilla\Firefox\Profiles\4puhgwi4.default
- McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
- Undetermined - {4ED1F68A-5463-4931-9384-8FFF5ED91D92}
ProfilePath: D:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\72vjhc9c.default
- McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Telstra Extension - %AppDir%\browser\extensions\
mcciwbch@motive.com.xpi
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
==== Firefox Plugins ======================
Profilepath: D:\Users\Rob\AppData\Roaming\Mozilla\Firefox\Profiles\4puhgwi4.default
424899266BA430CCE5DDB6C1B4BE1B99 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll - Shockwave Flash
18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013
==== Chromium Look ======================
Google Chrome Version: 39.0.2171.95 (Up to date, latest Stable version: 39.0.2171.95)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
edmgmpmklgfbohogafcfobonnkogchec - C:\Program Files (x86)\Common Files\Motive\extensions\MotiveRequest.crx[02/10/2014 02:18 PM]
Google Voice Search Hotword (Beta) - Dav3b_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Telstra Extension - Dav3b_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec
Google Voice Search Hotword (Beta) - David\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Telstra Extension - David\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec
Google Voice Search Hotword (Beta) - dylan_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Telstra Extension - dylan_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec
SiteAdvisor - dylan_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
Google Voice Search Hotword (Beta) - Lizbee\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Telstra Extension - Lizbee\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec
SiteAdvisor - Lizbee\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
Google Voice Search Hotword (Beta) - Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Telstra Extension - Rob\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec
Google Voice Search Hotword (Beta) - Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Telstra Extension - Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec
SiteAdvisor - Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="
www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="
www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="
http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="
http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD4CA175-B85B-434A-8A3B-7E04CDD1741F} deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
D:\Users\Dav3b_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
D:\Users\harveynorman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
D:\Users\harveynorman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
D:\Users\Lizbee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
D:\Users\Lizbee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
D:\Users\Rob\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
D:\Users\Lizbee\AppData\Local\Mozilla\Firefox\Profiles\39vj6o4q.default\cache2 emptied successfully
D:\Users\Robert\AppData\Local\Mozilla\Firefox\Profiles\72vjhc9c.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
D:\Users\Dav3b_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
D:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
D:\Users\Lizbee\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
D:\Users\Rob\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=6 folders=4 632830 bytes)
==== Empty Temp Folders ======================
D:\Users\Dav3b_000\AppData\Local\Temp emptied successfully
D:\Users\David\AppData\Local\Temp emptied successfully
D:\Users\Default\AppData\Local\Temp emptied successfully
D:\Users\Default User\AppData\Local\Temp emptied successfully
D:\Users\dylan_000\AppData\Local\Temp emptied successfully
D:\Users\harveynorman\AppData\Local\Temp emptied successfully
D:\Users\Lizbee\AppData\Local\Temp emptied successfully
D:\Users\Rob\AppData\Local\Temp will be emptied at reboot
D:\Users\Robert\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted
==== EOF on Sun 28/12/2014 at 0:16:09.86 ======================