Understood. I am able to use the main mode now.
The library is not open today and is the only place I can go that has a safe computer. I will avoid my usual sites(yes I do handle money online, but very rarely, however info can still be obtained from my MMO accounts if stolen.. And before my desktop was taken over, I deleted my cache/temp files/cookies. At least I hope it went through), for now.
The combo fix log:
ComboFix 09-07-25.08 - MORAN 07/26/2009 14:55.1.2 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2447 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\17929534
c:\documents and settings\All Users\Application Data\17929534\17929534
c:\documents and settings\All Users\Application Data\17929534\17929534.exe
c:\documents and settings\MORAN\Desktop\System Security 2009.lnk
c:\documents and settings\MORAN\Start Menu\Programs\System Security
c:\documents and settings\MORAN\Start Menu\Programs\System Security\System Security
C:\install.exe
c:\windows\ctfmon.exe
c:\windows\Installer\3a77b.msi
c:\windows\lsass.exe
c:\windows\system32\drivers\geyekriuagvatx.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\sdra64.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 16:14 . 2009-07-26 16:15 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-07-26 14:45 . 2009-07-26 14:45 ——– d-s—w- c:\documents and settings\Administrator\UserData
2009-07-26 14:24 . 2009-07-26 14:24 ——– d—–w- c:\program files\Trend Micro
2009-07-25 18:23 . 2009-07-25 18:23 ——– d—–w- c:\documents and settings\MORAN\Local Settings\Application Data\WinZip
2009-07-25 18:22 . 2009-07-25 18:23 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2009-07-24 18:47 . 2009-07-25 17:34 ——– d—–w- c:\program files\Bethesda Softworks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 18:17 . 2009-03-13 23:13 ——– d—–w- c:\documents and settings\MORAN\Application Data\MegauploadToolbar
2009-07-26 14:50 . 2009-02-05 11:13 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-26 13:58 . 2009-06-22 15:24 ——– d—–w- c:\documents and settings\All Users\Application Data\ATTToolbar
2009-07-26 13:57 . 2009-06-22 15:24 ——– d—–w- c:\documents and settings\MORAN\Application Data\ATTToolbar
2009-07-24 19:31 . 2009-02-05 10:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-24 18:49 . 2009-06-04 19:36 ——– d—–w- c:\program files\Messenger Plus! Live
2009-07-15 14:36 . 2009-03-01 19:55 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-14 21:39 . 2009-02-10 12:06 ——– d—–w- c:\documents and settings\MORAN\Application Data\uTorrent
2009-06-26 17:27 . 2009-03-23 12:09 ——– d—–w- c:\program files\AIM6
2009-06-26 17:26 . 2009-03-04 22:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-26 17:25 . 2009-06-26 17:25 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-25 12:42 . 2009-06-25 12:42 25214 —-a-r- c:\documents and settings\MORAN\Application Data\Microsoft\Installer\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}\ARPPRODUCTICON.exe
2009-06-25 12:41 . 2009-06-25 12:41 ——– d—–w- c:\program files\Common Files\Jasc Software Inc
2009-06-25 12:41 . 2009-06-25 12:41 ——– d—–w- c:\program files\Jasc Software Inc
2009-06-25 12:33 . 2009-06-25 12:33 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2009-06-25 11:27 . 2009-06-25 11:27 ——– d—–w- c:\program files\SystemRequirementsLab
2009-06-25 11:27 . 2009-06-25 11:27 290816 —-a-w- c:\documents and settings\MORAN\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
2009-06-25 11:27 . 2009-06-25 11:27 290816 —-a-w- c:\documents and settings\MORAN\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
2009-06-25 11:27 . 2009-06-25 11:27 290816 —-a-w- c:\documents and settings\MORAN\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
2009-06-25 11:27 . 2009-06-25 11:27 290816 —-a-w- c:\documents and settings\MORAN\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
2009-06-25 11:27 . 2009-06-25 11:27 ——– d—–w- c:\documents and settings\MORAN\Application Data\SystemRequirementsLab
2009-06-22 16:06 . 2009-05-17 17:23 ——– d—–w- c:\program files\Common Files\Motive
2009-06-22 15:24 . 2009-06-22 15:24 ——– d—–w- c:\program files\ATTToolbar
2009-06-22 15:23 . 2009-06-22 15:23 ——– d—–w- c:\program files\ATT-SST
2009-06-22 15:19 . 2009-05-17 17:23 ——– d—–w- c:\documents and settings\MORAN\Application Data\Motive
2009-06-21 17:16 . 2009-06-21 17:16 390664 —-a-w- c:\documents and settings\MORAN\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-12 13:49 . 2009-05-07 13:47 ——– d—–w- c:\program files\Java
2009-06-12 13:48 . 2009-06-12 13:48 152576 —-a-w- c:\documents and settings\MORAN\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 13:28 . 2009-06-10 13:28 3510272 —-a-w- c:\windows\system32\nvgames.dll
2009-06-10 13:28 . 2009-06-10 13:28 4022272 —-a-w- c:\windows\system32\nvdisps.dll
2009-06-10 13:28 . 2009-06-10 13:28 86016 —-a-w- c:\windows\system32\nvmctray.dll
2009-06-10 13:28 . 2009-06-10 13:28 168004 —-a-w- c:\windows\system32\nvsvc32.exe
2009-06-10 13:28 . 2009-06-10 13:28 143360 —-a-w- c:\windows\system32\nvcolor.exe
2009-06-10 13:28 . 2009-06-10 13:28 13758464 —-a-w- c:\windows\system32\nvcpl.dll
2009-06-10 13:28 . 2009-06-10 13:28 229376 —-a-w- c:\windows\system32\nvmccs.dll
2009-06-10 11:03 . 2009-06-10 11:03 671744 —-a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 11:03 . 2009-06-10 11:03 1580550 —-a-w- c:\windows\system32\nvdata.bin
2009-06-10 11:03 . 2009-06-10 11:03 1310720 —-a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 11:03 . 2009-02-05 11:13 457248 —-a-w- c:\windows\system32\nvudisp.exe
2009-06-10 11:03 . 2008-12-26 08:08 9998336 —-a-w- c:\windows\system32\nvoglnt.dll
2009-06-10 11:03 . 2008-12-26 08:08 815104 —-a-w- c:\windows\system32\nvapi.dll
2009-06-10 11:03 . 2008-12-26 08:08 8087712 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 11:03 . 2008-12-26 08:08 5908608 —-a-w- c:\windows\system32\nv4_disp.dll
2009-06-10 11:03 . 2008-12-26 08:08 1720320 —-a-w- c:\windows\system32\nvcuda.dll
2009-06-10 11:03 . 2008-12-26 08:08 151552 —-a-w- c:\windows\system32\nvcodins.dll
2009-06-10 11:03 . 2008-12-26 08:08 151552 —-a-w- c:\windows\system32\nvcod.dll
2009-06-07 17:05 . 2009-06-07 17:05 4096 —-a-w- c:\windows\d3dx.dat
2009-06-07 17:04 . 2009-06-07 17:04 ——– d—–w- c:\program files\PlayOnline
2009-06-04 20:39 . 2009-02-05 10:56 457248 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-06-04 20:08 . 2009-06-04 20:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-04 06:24 . 2009-06-04 06:24 ——– d–h–r- c:\documents and settings\MORAN\Application Data\SecuROM
2009-06-04 06:24 . 2009-02-23 05:12 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-05-21 15:33 . 2009-05-07 13:47 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-19 05:36 . 2009-06-26 17:25 97072 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 05:36 . 2009-06-26 17:25 2884832 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 05:36 . 2009-06-26 17:25 28 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\unregister.bat
2009-05-19 05:36 . 2009-06-26 17:25 25 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\register.bat
2009-05-19 05:36 . 2009-06-26 17:25 1484856 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 05:36 . 2009-06-26 17:25 142040 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 05:36 . 2009-06-26 17:25 30512 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 05:36 . 2009-06-26 17:25 111920 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-07 13:46 . 2009-05-07 13:46 152576 —-a-w- c:\documents and settings\MORAN\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-28 14:55 . 2009-04-28 14:55 70936 —-a-w- c:\windows\system32\PhysXLoader.dll
2009-02-20 11:20 . 2009-02-20 11:20 57231 —-a-w- c:\program files\Bookmarks 2009-02-20.json
2009-07-23 04:12 . 2009-02-10 10:44 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-02-10 2356088]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-03-17 102400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2008-09-19 1529856]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-17 16855552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-10 1657376]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\MORAN\\My Documents\\Downloads\\Microsoft Office Word 2008 + CD KEY\\Microsoft Office Word 2008 + CD KEY.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\att-nap\\McciBrowser.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [5/26/2009 2:28 PM 55152]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/4/2009 6:09 PM 24652]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-17929534 - c:\documents and settings\All Users\Application Data\17929534\17929534.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.att.net
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: 0.0.0.0
Trusted Zone: motive.com\patttbc.att
FF - ProfilePath - c:\documents and settings\MORAN\Application Data\Mozilla\Firefox\Profiles\bm1dsqyn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-26 14:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3596)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-26 15:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-26 19:03
Pre-Run: 180,123,983,872 bytes free
Post-Run: 180,764,278,784 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
214