Mike19 bing desktop is not on my computer.
Bob
Yes I reinstalled my os, any validation problems should be resolved. I went back to firefox after reinstalling my os. I ran combofix, it did not resolve the bing problem. The problem is minor, but still annoying.
Bing has not taken over my homepage, merely the search address bar as shown in the photo where the text is highlighted. It used to search threw googles search engine, all of a sudden it changed to bing.
I just got back from a camping trip thanks for the responses here is the combofix log.
p.s. Hey bob I believe the old python code on my old os was left over from the diablo 2 bots I had used and uninstalled year(s) ago. And my mouse hardware was to blame for the bad clicks I was having.
ComboFix 12-07-21.01 - Josh 07/22/2012 16:14:00.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4094.3060 [GMT -7:00]
Running from: c:\users\Josh\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 23:18 . 2012-07-22 23:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-22 20:55 . 2012-07-22 20:55 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BCCB76E3-6072-4FAA-849F-33E928A8ADBE}\offreg.dll
2012-07-21 23:01 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BCCB76E3-6072-4FAA-849F-33E928A8ADBE}\mpengine.dll
2012-07-12 00:56 . 2012-07-12 00:56 388096 ----a-r- c:\users\Josh\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-12 00:56 . 2012-07-12 00:56 -------- d-----w- c:\program files (x86)\Trend Micro
2012-07-10 22:41 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-10 21:43 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-07-02 12:45 . 2012-07-02 12:45 -------- d-----w- c:\users\Default\AppData\Local\Google
2012-07-02 04:25 . 2012-07-02 04:25 -------- d-----w- c:\windows\Sun
2012-07-02 04:24 . 2012-07-02 04:24 -------- d-----w- c:\users\Josh\AppData\Local\CRE
2012-07-02 04:24 . 2012-07-02 04:24 -------- d-----w- c:\program files (x86)\Conduit
2012-07-02 04:24 . 2012-07-02 05:06 -------- d-----w- c:\users\Josh\AppData\Local\Conduit
2012-07-02 04:20 . 2012-07-02 04:20 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-07-02 04:14 . 2012-07-02 04:14 -------- d-----w- c:\program files (x86)\Oracle
2012-07-02 04:14 . 2012-05-05 02:29 772504 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-07-02 04:14 . 2012-05-05 02:29 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-07-02 04:13 . 2012-07-02 04:13 -------- d-----w- c:\program files (x86)\Java
2012-06-24 22:04 . 2012-06-24 22:04 -------- d-----w- c:\program files (x86)\AviSynth 2.5
2012-06-24 22:03 . 2010-07-15 18:30 290816 ----a-w- c:\windows\SysWow64\stFLVSource.ax
2012-06-24 22:03 . 2012-06-24 22:03 -------- d-----w- c:\program files (x86)\Common Files\SourceTec
2012-06-24 22:03 . 2009-08-17 16:54 1184984 ----a-w- c:\windows\SysWow64\wvc1dmod.dll
2012-06-24 22:03 . 2012-06-24 22:03 -------- d-----w- c:\program files (x86)\Sothink Video Converter
2012-06-24 22:03 . 2009-08-17 16:54 438272 ----a-w- c:\windows\SysWow64\Mpeg2DecFilter.ax
2012-06-24 22:03 . 2009-08-17 16:54 217088 ----a-w- c:\windows\SysWow64\CoreFLACDecoder.ax
2012-06-24 22:03 . 2009-03-18 00:38 70656 ----a-w- c:\windows\SysWow64\RLAPEDec.ax
2012-06-24 20:38 . 2012-06-24 20:38 -------- d-----w- c:\program files (x86)\BurnAware Free
2012-06-23 23:12 . 2012-06-23 23:12 -------- d-----w- c:\users\Josh\AppData\Local\Macromedia
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-11 18:07 . 2012-06-05 23:50 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-11 18:07 . 2012-06-05 23:50 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-10 22:39 . 2012-06-04 11:23 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-06-04 23:25 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-06-04 23:25 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-06-04 11:48 . 2012-06-04 11:48 97280 ----a-w- C:\bootsect.exe
2012-06-04 11:31 . 2012-06-04 11:31 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-06-04 11:31 . 2012-06-04 11:31 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-06-04 11:31 . 2012-06-04 11:31 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-06-04 11:31 . 2012-06-04 11:31 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-06-04 11:31 . 2012-06-04 11:31 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-06-04 11:31 . 2012-06-04 11:31 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-06-04 11:31 . 2012-06-04 11:31 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-06-04 11:31 . 2012-06-04 11:31 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-06-04 11:31 . 2012-06-04 11:31 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-06-04 11:31 . 2012-06-04 11:31 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-06-04 11:31 . 2012-06-04 11:31 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-06-04 11:31 . 2012-06-04 11:31 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-06-04 11:31 . 2012-06-04 11:31 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-06-04 11:31 . 2012-06-04 11:31 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-06-04 11:31 . 2012-06-04 11:31 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-06-04 11:31 . 2012-06-04 11:31 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-06-04 11:31 . 2012-06-04 11:31 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-06-04 11:31 . 2012-06-04 11:31 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-06-04 11:31 . 2012-06-04 11:31 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-06-04 11:31 . 2012-06-04 11:31 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-06-04 11:31 . 2012-06-04 11:31 82432 ----a-w- c:\windows\system32\icardie.dll
2012-06-04 11:31 . 2012-06-04 11:31 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-06-04 11:31 . 2012-06-04 11:31 697344 ----a-w- c:\windows\system32\msfeeds.dll
2012-06-04 11:31 . 2012-06-04 11:31 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-06-04 11:31 . 2012-06-04 11:31 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-06-04 11:31 . 2012-06-04 11:31 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-06-04 11:31 . 2012-06-04 11:31 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-06-04 11:31 . 2012-06-04 11:31 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-06-04 11:31 . 2012-06-04 11:31 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-06-04 11:31 . 2012-06-04 11:31 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-06-04 11:31 . 2012-06-04 11:31 448512 ----a-w- c:\windows\system32\html.iec
2012-06-04 11:31 . 2012-06-04 11:31 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-06-04 11:31 . 2012-06-04 11:31 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-06-04 11:31 . 2012-06-04 11:31 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-06-04 11:31 . 2012-06-04 11:31 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-06-04 11:31 . 2012-06-04 11:31 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-06-04 11:31 . 2012-06-04 11:31 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-06-04 11:31 . 2012-06-04 11:31 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-06-04 11:31 . 2012-06-04 11:31 222208 ----a-w- c:\windows\system32\msls31.dll
2012-06-04 11:31 . 2012-06-04 11:31 197120 ----a-w- c:\windows\system32\msrating.dll
2012-06-04 11:31 . 2012-06-04 11:31 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-06-04 11:31 . 2012-06-04 11:31 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-06-04 11:31 . 2012-06-04 11:31 160256 ----a-w- c:\windows\system32\wextract.exe
2012-06-04 11:31 . 2012-06-04 11:31 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-06-04 11:31 . 2012-06-04 11:31 149504 ----a-w- c:\windows\system32\occache.dll
2012-06-04 11:31 . 2012-06-04 11:31 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-06-04 11:31 . 2012-06-04 11:31 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-06-04 11:31 . 2012-06-04 11:31 12288 ----a-w- c:\windows\system32\mshta.exe
2012-06-04 11:31 . 2012-06-04 11:31 114176 ----a-w- c:\windows\system32\admparse.dll
2012-06-04 11:31 . 2012-06-04 11:31 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-06-04 11:31 . 2012-06-04 11:31 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-06-04 11:31 . 2012-06-04 11:31 103936 ----a-w- c:\windows\system32\inseng.dll
2012-06-02 22:19 . 2012-06-21 19:40 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 19:40 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 19:40 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 19:40 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 19:40 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 22:19 . 2012-06-21 19:40 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 19:40 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 19:40 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 22:15 . 2012-06-21 19:40 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-05-31 19:25 . 2012-06-05 21:38 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-05-22 21:26 . 2012-06-08 05:00 224088 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2012-05-22 21:26 . 2012-06-08 05:00 130904 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2012-05-22 21:26 . 2012-05-22 21:26 147288 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2012-05-04 11:06 . 2012-06-14 06:02 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 11:00 . 2012-06-16 03:33 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-05-04 10:03 . 2012-06-14 06:02 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 06:02 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 09:59 . 2012-06-16 03:33 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-05-01 05:40 . 2012-06-14 06:02 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-14 06:02 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:41 . 2012-06-14 06:02 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 05:41 . 2012-06-14 06:02 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:34 . 2012-06-14 06:02 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 05:37 . 2012-06-14 06:02 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 05:37 . 2012-06-14 06:02 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-24 05:37 . 2012-06-14 06:02 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-14 06:02 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:36 . 2012-06-14 06:02 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-04-24 04:36 . 2012-06-14 06:02 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-06-17 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\users\Josh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files (x86)\MagicDisc\MagicDisc.exe [2012-6-14 576000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Play Wireless USB Adapter Utility.lnk - c:\program files (x86)\Belkin\F7D4101\V1\PBN.exe [2009-11-25 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-04 116648]
R2 WLANBelkinService;Belkin WLAN service;c:\program files (x86)\Belkin\F7D4101\V1\wlansrv.exe [2009-12-29 36864]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 250056]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-04 116648]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [x]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-05-22 147288]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-06-04 1255736]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-03-06 69976]
S2 MotoHelper;MotoHelper Service;c:\program files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-12-06 214896]
S3 ALSysIO;ALSysIO;c:\users\Josh\AppData\Local\Temp\ALSysIO64.sys [x]
S3 BCMH43XX;N+ Wireless USB Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [2009-11-06 838136]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-02 187392]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-05 18:07]
.
2012-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-04 10:38]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-04 10:38]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1265617423-3445245865-536936970-1000Core.job
- c:\users\Josh\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-02 10:38]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1265617423-3445245865-536936970-1000UA.job
- c:\users\Josh\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-02 10:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-06-21 02:02 755224 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-06-21 02:02 755224 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-06-21 02:02 755224 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-06-21 02:02 755224 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.hulu.com/?src=topnav
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.3.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\shell32.dll
FF - ProfilePath - c:\users\Josh\AppData\Roaming\Mozilla\Firefox\Profiles\oew56lwd.default\
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-22 16:20:02
ComboFix-quarantined-files.txt 2012-07-22 23:20
.
Pre-Run: 535,927,402,496 bytes free
Post-Run: 535,783,829,504 bytes free
.
- - End Of File - - 698554BBECB8BEF8A512C9584ECF30F9