Page 2 of 2 FirstFirst 12
Results 11 to 15 of 15

Thread: Microsoft Support Scan

  1. #11
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    Juliet,

    Things are running fine now. Malwarebytes was running a scan last time when I was trying to use the computer. Here are the results of the latest fix:

    Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by Gossett (2016-04-03 09:58:58) Run:2
    Running from C:\Users\Gossett\Desktop
    Loaded Profiles: Gossett (Available Profiles: Gossett & DefaultAppPool)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    start
    CreateRestorePoint:
    CloseProcesses:
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
    SearchScopes: HKLM -> {F61A00D0-BEBF-4F15-A38D-1CFAC7700002} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
    SearchScopes: HKU\S-1-5-21-4142238215-960131931-375975803-1000 -> DefaultScope {E5CE5988-2621-4932-8C3C-8AA701FF3421} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US679D20140729&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-4142238215-960131931-375975803-1000 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
    SearchScopes: HKU\S-1-5-21-4142238215-960131931-375975803-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    SearchScopes: HKU\S-1-5-21-4142238215-960131931-375975803-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
    SearchScopes: HKU\S-1-5-21-4142238215-960131931-375975803-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=chr-atty
    SearchScopes: HKU\S-1-5-21-4142238215-960131931-375975803-1000 -> {E5CE5988-2621-4932-8C3C-8AA701FF3421} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US679D20140729&p={searchTerms}
    CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US679D20140729&p={searchTerms}
    CHR Plugin: (Chrome PDF Viewer) - C:\Users\Gossett\AppData\Local\Google\Chrome\Application\49.0.2623.87\pdf.dll => No File
    CHR Plugin: (Shockwave Flash) - C:\Users\Gossett\AppData\Local\Google\Chrome\Application\49.0.2623.87\gcswf32.dll => No File
    CHR Plugin: (Norton Confidential) - C:\Users\Gossett\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.4.6_0\npcoplgn.dll => No File
    CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
    CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll => No File
    CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll => No File
    CHR Plugin: (Java(TM) Platform SE 7 U4) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll => No File
    CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll => No File
    CHR Plugin: (Google Update) - C:\Users\Gossett\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => No File
    CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => No File
    S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
    C:\Users\Gossett\AppData\Local\Temp\sqlite3.dll
    EmptyTemp:
    End
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" => key removed successfully
    HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => key removed successfully
    HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
    HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found.
    "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F61A00D0-BEBF-4F15-A38D-1CFAC7700002}" => key removed successfully
    HKCR\CLSID\{F61A00D0-BEBF-4F15-A38D-1CFAC7700002} => key not found.
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
    HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" => key removed successfully
    HKCR\Wow6432Node\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found.
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => key removed successfully
    HKCR\Wow6432Node\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found.
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
    HKCR\Wow6432Node\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found.
    HKU\S-1-5-21-4142238215-960131931-375975803-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
    "HKU\S-1-5-21-4142238215-960131931-375975803-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" => key removed successfully
    HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found.
    "HKU\S-1-5-21-4142238215-960131931-375975803-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => key removed successfully
    HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found.
    "HKU\S-1-5-21-4142238215-960131931-375975803-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => key removed successfully
    HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found.
    "HKU\S-1-5-21-4142238215-960131931-375975803-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}" => key removed successfully
    HKCR\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4} => key not found.
    "HKU\S-1-5-21-4142238215-960131931-375975803-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E5CE5988-2621-4932-8C3C-8AA701FF3421}" => key removed successfully
    HKCR\CLSID\{E5CE5988-2621-4932-8C3C-8AA701FF3421} => key not found.
    Chrome DefaultSearchURL => removed successfully
    C:\Users\Gossett\AppData\Local\Google\Chrome\Application\49.0.2623.87\pdf.dll => not found.
    C:\Users\Gossett\AppData\Local\Google\Chrome\Application\49.0.2623.87\gcswf32.dll => not found.
    C:\Users\Gossett\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.4.6_0\npcoplgn.dll => not found.
    C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => not found.
    C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll => not found.
    C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll => not found.
    C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll => not found.
    C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll => not found.
    C:\Users\Gossett\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => not found.
    c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => not found.
    wfpcapture => service removed successfully
    C:\Users\Gossett\AppData\Local\Temp\sqlite3.dll => moved successfully
    EmptyTemp: => 96 MB temporary data Removed.


    The system needed a reboot.

    ==== End of Fixlog 09:59:42 ====

  2. #12
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,858

    Default

    Things are running fine now.
    Good deal.

    I think your good to go.

    DelFix
    • Please download DelFix or from Here and save the file to your Desktop.
    • Double-click DelFix.exe to run the programme.
    • Place a checkmark next to the following items:
    • Activate UAC
    • Remove disinfection tools

    • Click the Run button.
    • -- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


    ~~~~~~~~~~~~~


    • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
    • CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
    • Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
    • Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
    • NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
    • Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
    • Secunia PSI will scan your computer for vulnerable softwarethat is outdated, and automatically find the latest update for you.
    • SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
    • Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
    • Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.


    Want to help others? Join the ClassRoom and learn how.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #13
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    Juliet,

    Thank you very much. I have removed the programs and things look to be working well. I really appreciate your help.

    Greg

  4. #14
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,858

    Default

    We're glad to help
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #15
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,858

    Default

    Glad we could help.

    Since this issue appears resolved ... this Topic is closed.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •