Combofix 1:
ComboFix 09-03-15.01 - heartlab 2009-03-16 10:29:46.1 - NTFSx86
Running from: c:\documents and settings\heartlab\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090316-0] *On-access scanning disabled* (Updated)
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
AV: eScan Anti-Virus (AV) Edition for Windows *On-access scanning disabled* (Updated)
FW: eScan Firewall For Windows *enabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\heartlab\Start Menu\Programs\WatchFree
c:\windows\regedit.com
c:\windows\system32\Cache
c:\windows\system32\drivers\gaopdxcnetepvqvyschlkihufeiuaxawgmeuma.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxiwfqvfuscuwoupmqtaempvdfgntsxuud.dll
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.
2009-03-13 11:15 . 2009-03-13 11:15 <DIR> d-------- c:\program files\Avira
2009-03-13 11:15 . 2009-03-13 11:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-12 19:20 . 2009-03-12 19:21 <DIR> d-------- c:\program files\ERUNT
2009-03-12 00:33 . 2009-03-12 00:33 25 --a------ c:\windows\escan.dbf
2009-03-11 16:24 . 2008-12-23 10:31 247,944 --a------ c:\windows\system32\drivers\bdfsfltr.sys
2009-03-11 16:24 . 2009-03-11 16:24 20 --a------ c:\windows\WIN.PRO
2009-03-11 16:23 . 2009-03-11 16:23 <DIR> d-------- c:\documents and settings\heartlab\Application Data\MicroWorld
2009-03-11 16:22 . 2009-03-11 16:22 <DIR> d-------- c:\documents and settings\remoteservice\Documents
2009-03-11 16:22 . 2009-03-11 16:22 <DIR> d-------- c:\documents and settings\remoteservice
2009-03-11 16:22 . 2009-03-11 16:22 <DIR> d-------- c:\documents and settings\LocalService\Documents
2009-03-11 16:22 . 2009-03-11 16:22 142,624 --a------ c:\windows\winsbak2.reg
2009-03-11 16:22 . 2009-03-11 16:22 20,626 --a------ c:\windows\winsbak.reg
2009-03-11 16:22 . 2009-03-10 19:29 210 --a------ C:\bootini.ins
2009-03-11 16:20 . 2009-02-12 22:45 118,784 --a------ c:\windows\killproc.exe
2009-03-11 16:20 . 2008-08-08 14:02 22,784 --a------ c:\windows\system32\drivers\econceal.sys
2009-03-11 16:19 . 2008-11-03 21:35 509,952 --a------ c:\windows\system32\eInstall.exe
2009-03-11 16:18 . 2009-03-16 10:26 <DIR> d-------- c:\program files\eScan
2009-03-11 14:40 . 2009-03-13 03:33 0 --a------ C:\23990098.$$$
2009-03-11 11:12 . 2009-03-11 11:15 6,827,726 --a------ c:\windows\REGBK00.ZIP
2009-03-11 11:08 . 2009-03-11 11:08 28 --a------ c:\windows\Lic.xxx
2009-03-11 11:06 . 2009-03-13 03:47 <DIR> d-------- c:\program files\Common Files\MicroWorld
2009-03-11 11:06 . 2009-03-11 11:06 626,688 --a------ c:\windows\system32\msvcr80.dll
2009-03-11 11:06 . 2009-03-11 11:06 548,864 --a------ c:\windows\system32\msvcp80.dll
2009-03-11 11:06 . 2008-04-13 19:12 146,432 --a------ c:\windows\R.COM
2009-03-11 11:06 . 2008-04-13 19:12 135,680 --a------ c:\windows\system32\T.COM
2009-03-11 11:06 . 2009-03-11 11:06 28,672 --a------ c:\windows\system32\eEmpty.exe
2009-03-11 11:06 . 2005-09-22 23:22 522 --a------ c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-03-11 11:05 . 2009-03-11 23:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\MicroWorld
2009-03-11 00:30 . 2009-03-11 00:30 <DIR> d-------- c:\documents and settings\heartlab\Application Data\Research In Motion
2009-03-10 23:07 . 2009-03-10 23:07 <DIR> d-------- c:\program files\Alwil Software
2009-03-10 19:33 . 2009-03-10 19:33 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-10 19:33 . 2009-03-10 19:33 <DIR> d-------- c:\program files\AVG
2009-03-10 19:33 . 2009-03-16 10:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-10 19:33 . 2009-03-10 19:33 325,640 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-10 19:33 . 2009-03-10 19:33 107,912 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-10 19:33 . 2009-03-10 19:33 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-10 17:10 . 2009-03-11 09:57 664 --a------ c:\windows\system32\d3d9caps.dat
2009-03-10 15:22 . 2009-03-10 15:22 <DIR> d-------- c:\documents and settings\heartlab\Application Data\Malwarebytes
2009-03-10 15:15 . 2009-03-13 11:13 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-10 15:15 . 2009-03-10 15:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-10 15:15 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-10 15:15 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-10 10:50 . 2007-12-24 17:37 138,384 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-03-10 10:49 . 2009-03-10 18:28 <DIR> d-------- c:\documents and settings\heartlab\Application Data\HouseCall 6.6
2009-03-10 00:27 . 2009-03-10 00:27 <DIR> d-------- c:\program files\Roxio
2009-03-10 00:27 . 2009-03-10 00:27 <DIR> d-------- c:\program files\Common Files\Sonic Shared
2009-03-10 00:27 . 2009-03-10 00:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Roxio
2009-03-10 00:26 . 2009-03-10 00:26 <DIR> d-------- c:\program files\Common Files\Roxio Shared
2009-03-10 00:15 . 2007-01-18 10:24 26,496 -ra------ c:\windows\system32\drivers\RimSerial.sys
2009-03-10 00:14 . 2009-03-10 00:14 <DIR> d-------- c:\program files\Research In Motion
2009-03-10 00:14 . 2009-03-10 00:15 <DIR> d-------- c:\program files\Common Files\Research In Motion
2009-03-07 14:35 . 2009-03-03 23:40 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-03-06 01:49 . 2009-03-06 01:52 <DIR> d-------- c:\program files\Rainmeter
2009-03-06 01:46 . 2009-03-10 15:49 <DIR> d-------- c:\documents and settings\heartlab\.rainlendar2
2009-03-06 01:45 . 2009-03-06 01:46 <DIR> d-------- c:\program files\Rainlendar2
2009-03-06 00:28 . 2009-03-06 00:28 <DIR> d-------- c:\program files\EvilLyrics
2009-02-25 17:24 . 2009-02-25 17:32 <DIR> d-------- C:\Photos
2009-02-25 17:10 . 2009-02-25 17:38 727 -rah----- c:\windows\EPMBatch.ept
2009-02-25 16:59 . 2009-02-25 16:59 <DIR> d-------- c:\documents and settings\heartlab\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-25 16:51 . 2009-02-25 16:51 <DIR> d-------- c:\program files\EASEUS
2009-02-25 16:33 . 2009-02-25 16:33 <DIR> d--h----- c:\windows\$hf_mig$
2009-02-25 16:24 . 2009-02-25 16:24 <DIR> d-------- c:\windows\IIS Temporary Compressed Files
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\system32\scripting
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\system32\en
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\system32\bits
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\l2schemas
2009-02-24 15:21 . 2009-02-24 15:21 <DIR> d-------- c:\windows\ServicePackFiles
2009-02-19 00:12 . 2009-02-25 12:44 <DIR> d-------- c:\documents and settings\heartlab\Application Data\NBC Direct
2009-02-19 00:11 . 2009-02-19 00:11 <DIR> d-------- c:\program files\Pando Networks
2009-02-19 00:11 . 2009-02-19 00:19 <DIR> d-------- c:\documents and settings\heartlab\Application Data\IDM
2009-02-19 00:11 . 2009-02-25 17:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\PMB Files
2009-02-19 00:11 . 2009-02-19 00:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\NBC Direct
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-13 15:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-13 15:23 --------- d-----w c:\program files\SpywareBlaster
2009-03-13 15:13 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-13 15:08 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-10 05:30 --------- d-----w c:\program files\Microsoft Silverlight
2009-03-10 05:27 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-04 04:40 64,160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-02-26 17:31 --------- d-----w c:\program files\Common Files\Adobe
2009-02-25 14:34 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-25 02:30 --------- d-----w c:\documents and settings\heartlab\Application Data\Move Networks
2009-02-24 21:47 --------- d-----w c:\program files\Java
2009-02-13 04:15 65,024 ----a-w c:\windows\inst_tsp.exe
2009-02-13 04:15 495,616 ----a-w c:\windows\system32\mwtsp.dll
2009-02-13 04:11 176,128 ----a-w c:\windows\system32\mwnsp.dll
2009-02-13 02:31 226,304 ----a-w c:\windows\inst_tspx.exe
2009-02-13 01:15 --------- d-----w c:\program files\Common Files\Sling Media
2009-02-12 22:32 1,085,440 ----a-w c:\windows\system32\contfilt.dll
2009-02-12 16:49 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-09 22:27 --------- d-----w c:\documents and settings\heartlab\Application Data\AdobeUM
2009-02-09 17:58 628,736 ----a-w c:\windows\system32\eslogon.dll
2009-02-04 04:38 --------- dc-h--w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-04 04:38 --------- d-----w c:\program files\Lavasoft
2009-02-04 04:38 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-04 04:37 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-03 13:35 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-02-03 13:25 --------- d-----w c:\program files\MSXML 4.0
2009-02-03 05:34 --------- d-----w c:\documents and settings\heartlab\Application Data\Search Settings
2009-02-03 00:04 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-29 18:08 --------- d-----w c:\program files\eRightSoft
2009-01-29 18:08 --------- d-----w c:\program files\AviSynth 2.5
2009-01-29 17:23 --------- d-----w c:\program files\Free FLV Converter
2009-01-29 17:10 --------- d-----w c:\program files\Search Settings
2009-01-28 20:46 --------- d-----w c:\program files\Real
2009-01-28 20:46 --------- d-----w c:\program files\Common Files\xing shared
2009-01-28 20:46 --------- d-----w c:\program files\Common Files\Real
2009-01-28 20:33 --------- d-----w c:\program files\Hotspot Shield
2009-01-26 15:20 --------- d-----w c:\documents and settings\heartlab\Application Data\Apple Computer
2009-01-25 03:59 --------- d-----w c:\program files\iTunes
2009-01-25 03:59 --------- d-----w c:\program files\iPod
2009-01-25 03:59 --------- d-----w c:\program files\Common Files\Apple
2009-01-25 03:59 --------- d-----w c:\program files\Bonjour
2009-01-25 03:59 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-25 03:59 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-25 03:56 --------- d-----w c:\program files\QuickTime
2009-01-15 23:36 274,432 ----a-w c:\windows\system32\TubeFinder.exe
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 13:30 216,064 --sh--r c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
2008-06-12 17:57 1111904 --a------ c:\program files\Search Settings\kb127\SearchSettings.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-01-28 15:33 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\heartlab\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-24 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-28 185896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-03 515416]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-24 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"eScan Updater"="c:\progra~1\eScan\TRAYICOS.EXE" [2009-02-12 2779136]
"MailScan Dispatcher"="c:\progra~1\eScan\LAUNCH.EXE" [2009-02-12 761856]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
c:\documents and settings\heartlab\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2008-12-16 869376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-10 19:33 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eSLogOn]
2009-02-09 12:58 628736 c:\windows\system32\eslogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2006-02-14 12:00 8704 c:\windows\system32\PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
backup=c:\windows\pss\Cisco Systems VPN Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^heartlab^Start Menu^Programs^Startup^Rainmeter.lnk]
path=c:\documents and settings\heartlab\Start Menu\Programs\Startup\Rainmeter.lnk
backup=c:\windows\pss\Rainmeter.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
--a------ 2009-01-14 23:44 2210632 c:\program files\Pando Networks\Media Booster\PMB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
--a------ 2009-02-21 03:18 4333568 c:\program files\Rainlendar2\Rainlendar2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
--a------ 2008-06-12 17:57 991584 c:\program files\Search Settings\SearchSettings.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2006-03-24 16:30 282624 c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\PROGRA~1\\eScan\\DOWNLOAD.EXE"=
"c:\\PROGRA~1\\eScan\\TRAYICOS.EXE"=
"c:\\PROGRA~1\\COMMON~1\\MICROW~1\\Agent\\MWAGENT.EXE"=
"c:\\PROGRA~1\\eScan\\LICENSE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
"58508:TCP"= 58508:TCP

MB P2P TCP Listening Port
"58508:UDP"= 58508:UDP

MB P2P UDP Listening Port
R2 studfsvc;SevenTen UDF 2.01 File System;c:\program files\Common Files\UdfViewer\studfsvc.exe [2005-02-21 1159168]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2008-11-25 8704]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2008-11-25 3072]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-03 951120]
R4 avg8emc;AVG Free8 E-mail Scanner; [x]
R4 avg8wd;AVG Free8 WatchDog; [x]
R4 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-10 325640]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-10 107912]
S0 710udfsd;710udfsd;c:\windows\system32\drivers\710udfsd.sys [2004-07-06 8016]
S0 710udfvd;710udfvd;c:\windows\system32\drivers\710udfvd.sys [2004-06-25 8936]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-03 64160]
S1 aswSP;avast! Self Protection; [x]
S1 ECONCEAL;ECONCEAL; [x]
S2 710udffs;710udffs;c:\windows\system32\drivers\710udffs.sys [2005-02-21 98928]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 EconService;eConServ;c:\progra~1\escan\EconSer.exe [2007-06-13 424448]
S2 eScan-trayicos;eScan Server-Updater;c:\progra~1\eScan\TRAYSSER.EXE [2009-02-12 87040]
S2 eScan Monitor Service;eScan Monitor Service;c:\docume~1\ALLUSE~1\APPLIC~1\MICROW~1\eScanBD\avpmapp.exe [2009-03-09 180736]
S2 SlingAgentService;SlingAgent Service;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [2008-12-10 88576]
S3 ProcObsrves;ProcObsrves;c:\progra~1\eScan\ProcObsrves.sys [2009-01-17 11264]
--- Other Services/Drivers In Memory ---
*Deregistered* - 710udffs
*Deregistered* - 710udfsd
*Deregistered* - 710udfvd
*Deregistered* - Aavmker4
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AntiVirScheduler
*Deregistered* - AntiVirService
*Deregistered* - Apple Mobile Device
*Deregistered* - Arp1394
*Deregistered* - Aspi32
*Deregistered* - aswFsBlk
*Deregistered* - aswMon2
*Deregistered* - aswRdr
*Deregistered* - aswSP
*Deregistered* - aswTdi
*Deregistered* - aswUpdSv
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avast! Antivirus
*Deregistered* - avast! Mail Scanner
*Deregistered* - avast! Web Scanner
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - awecho
*Deregistered* - awlegacy
*Deregistered* - bdfsfltr
*Deregistered* - Beep
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - CVPND
*Deregistered* - CVPNDRVA
*Deregistered* - Dhcp
*Deregistered* - DNE
*Deregistered* - Dnscache
*Deregistered* - ECONCEAL
*Deregistered* - EconService
*Deregistered* - ERSvc
*Deregistered* - eScan-trayicos
*Deregistered* - eScan Monitor Service
*Deregistered* - EventSystem
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gernuwa
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - IISADMIN
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - Lbd
*Deregistered* - LmHosts
*Deregistered* - LVCOMSer
*Deregistered* - LVPr2Mon
*Deregistered* - LVPrcSrv
*Deregistered* - LVSrvLauncher
*Deregistered* - mnmdd
*Deregistered* - Modem
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - MSCamSvc
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - MWAgent
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - OMCI
*Deregistered* - PartMgr
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProcObsrv
*Deregistered* - ProcObsrves
*Deregistered* - ProtectedStorage
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RimVSerPort
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SlingAgentService
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - stisvc
*Deregistered* - studfsvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - tapvpn
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - tmcomm
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - W3SVC
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wltrysvc
*Deregistered* - WMPNetworkSvc
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-03-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-03 23:39]
2009-03-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-707799472-2889999743-2908758316-1005.job
- c:\documents and settings\heartlab\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-24 22:45]
.
- - - - ORPHANS REMOVED - - - -
BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
MSConfigStartUp-BitTorrent DNA - c:\program files\DNA\btdna.exe
MSConfigStartUp-DirectPlayerCore - g:\nbc direct\DirectPlayerCore.exe
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://hlrmdemo/admintool2/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} - hxxp://betaimg.sling.com/sli/sling_player_ax/WebSlingPlayer.cab?1.0.0.19
FF - ProfilePath - c:\documents and settings\heartlab\Application Data\Mozilla\Firefox\Profiles\sre6y4bd.default\
FF - component: c:\documents and settings\heartlab\Application Data\Mozilla\Firefox\Profiles\sre6y4bd.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\documents and settings\heartlab\Application Data\IDM\bin\flash\platform\WINNT\plugins\npidmdcp.dll
FF - plugin: c:\documents and settings\heartlab\Application Data\Mozilla\Firefox\Profiles\sre6y4bd.default\extensions\{9EB34849-81D3-4841-939D-666D522B889A}\plugins\npSlingPlayer.dll
FF - plugin: c:\documents and settings\heartlab\Application Data\Mozilla\Firefox\Profiles\sre6y4bd.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\heartlab\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-16 10:33:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\JET995F.tmp 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1004)
c:\windows\system32\eSLogOn.dll
.
Completion time: 2009-03-16 10:37:30
ComboFix-quarantined-files.txt 2009-03-16 15:37:22
Pre-Run: 59,215,802,368 bytes free
Post-Run: 59,459,559,424 bytes free
456 --- E O F --- 2009-02-27 14:36:16
Combofix Log 2 (after Windows Recovery Console):
ComboFix 09-03-15.01 - heartlab 2009-03-16 10:50:14.2 - NTFSx86
Running from: c:\documents and settings\heartlab\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\heartlab\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: avast! antivirus 4.8.1335 [VPS 090316-0] *On-access scanning disabled* (Updated)
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
AV: eScan Anti-Virus (AV) Edition for Windows *On-access scanning disabled* (Updated)
FW: eScan Firewall For Windows *disabled*
.
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.
2009-03-13 11:15 . 2009-03-13 11:15 <DIR> d-------- c:\program files\Avira
2009-03-13 11:15 . 2009-03-13 11:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-12 19:20 . 2009-03-12 19:21 <DIR> d-------- c:\program files\ERUNT
2009-03-12 00:33 . 2009-03-12 00:33 25 --a------ c:\windows\escan.dbf
2009-03-11 16:24 . 2008-12-23 10:31 247,944 --a------ c:\windows\system32\drivers\bdfsfltr.sys
2009-03-11 16:24 . 2009-03-11 16:24 20 --a------ c:\windows\WIN.PRO
2009-03-11 16:23 . 2009-03-11 16:23 <DIR> d-------- c:\documents and settings\heartlab\Application Data\MicroWorld
2009-03-11 16:22 . 2009-03-11 16:22 <DIR> d-------- c:\documents and settings\remoteservice\Documents
2009-03-11 16:22 . 2009-03-11 16:22 <DIR> d-------- c:\documents and settings\remoteservice
2009-03-11 16:22 . 2009-03-11 16:22 <DIR> d-------- c:\documents and settings\LocalService\Documents
2009-03-11 16:22 . 2009-03-11 16:22 142,624 --a------ c:\windows\winsbak2.reg
2009-03-11 16:22 . 2009-03-11 16:22 20,626 --a------ c:\windows\winsbak.reg
2009-03-11 16:22 . 2009-03-10 19:29 210 --a------ C:\bootini.ins
2009-03-11 16:20 . 2009-02-12 22:45 118,784 --a------ c:\windows\killproc.exe
2009-03-11 16:20 . 2008-08-08 14:02 22,784 --a------ c:\windows\system32\drivers\econceal.sys
2009-03-11 16:19 . 2008-11-03 21:35 509,952 --a------ c:\windows\system32\eInstall.exe
2009-03-11 16:18 . 2009-03-16 10:26 <DIR> d-------- c:\program files\eScan
2009-03-11 14:40 . 2009-03-13 03:33 0 --a------ C:\23990098.$$$
2009-03-11 11:12 . 2009-03-11 11:15 6,827,726 --a------ c:\windows\REGBK00.ZIP
2009-03-11 11:08 . 2009-03-11 11:08 28 --a------ c:\windows\Lic.xxx
2009-03-11 11:06 . 2009-03-13 03:47 <DIR> d-------- c:\program files\Common Files\MicroWorld
2009-03-11 11:06 . 2009-03-11 11:06 626,688 --a------ c:\windows\system32\msvcr80.dll
2009-03-11 11:06 . 2009-03-11 11:06 548,864 --a------ c:\windows\system32\msvcp80.dll
2009-03-11 11:06 . 2008-04-13 19:12 146,432 --a------ c:\windows\R.COM
2009-03-11 11:06 . 2008-04-13 19:12 135,680 --a------ c:\windows\system32\T.COM
2009-03-11 11:06 . 2009-03-11 11:06 28,672 --a------ c:\windows\system32\eEmpty.exe
2009-03-11 11:06 . 2005-09-22 23:22 522 --a------ c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-03-11 11:05 . 2009-03-11 23:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\MicroWorld
2009-03-11 00:30 . 2009-03-11 00:30 <DIR> d-------- c:\documents and settings\heartlab\Application Data\Research In Motion
2009-03-10 23:07 . 2009-03-10 23:07 <DIR> d-------- c:\program files\Alwil Software
2009-03-10 19:33 . 2009-03-10 19:33 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-10 19:33 . 2009-03-10 19:33 <DIR> d-------- c:\program files\AVG
2009-03-10 19:33 . 2009-03-16 10:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-10 19:33 . 2009-03-10 19:33 325,640 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-10 19:33 . 2009-03-10 19:33 107,912 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-10 19:33 . 2009-03-10 19:33 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-10 17:10 . 2009-03-11 09:57 664 --a------ c:\windows\system32\d3d9caps.dat
2009-03-10 15:22 . 2009-03-10 15:22 <DIR> d-------- c:\documents and settings\heartlab\Application Data\Malwarebytes
2009-03-10 15:15 . 2009-03-13 11:13 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-10 15:15 . 2009-03-10 15:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-10 15:15 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-10 15:15 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-10 10:50 . 2007-12-24 17:37 138,384 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-03-10 10:49 . 2009-03-10 18:28 <DIR> d-------- c:\documents and settings\heartlab\Application Data\HouseCall 6.6
2009-03-10 00:27 . 2009-03-10 00:27 <DIR> d-------- c:\program files\Roxio
2009-03-10 00:27 . 2009-03-10 00:27 <DIR> d-------- c:\program files\Common Files\Sonic Shared
2009-03-10 00:27 . 2009-03-10 00:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Roxio
2009-03-10 00:26 . 2009-03-10 00:26 <DIR> d-------- c:\program files\Common Files\Roxio Shared
2009-03-10 00:15 . 2007-01-18 10:24 26,496 -ra------ c:\windows\system32\drivers\RimSerial.sys
2009-03-10 00:14 . 2009-03-10 00:14 <DIR> d-------- c:\program files\Research In Motion
2009-03-10 00:14 . 2009-03-10 00:15 <DIR> d-------- c:\program files\Common Files\Research In Motion
2009-03-07 14:35 . 2009-03-03 23:40 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-03-06 01:49 . 2009-03-06 01:52 <DIR> d-------- c:\program files\Rainmeter
2009-03-06 01:46 . 2009-03-10 15:49 <DIR> d-------- c:\documents and settings\heartlab\.rainlendar2
2009-03-06 01:45 . 2009-03-06 01:46 <DIR> d-------- c:\program files\Rainlendar2
2009-03-06 00:28 . 2009-03-06 00:28 <DIR> d-------- c:\program files\EvilLyrics
2009-02-25 17:24 . 2009-02-25 17:32 <DIR> d-------- C:\Photos
2009-02-25 17:10 . 2009-02-25 17:38 727 -rah----- c:\windows\EPMBatch.ept
2009-02-25 16:59 . 2009-02-25 16:59 <DIR> d-------- c:\documents and settings\heartlab\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-25 16:51 . 2009-02-25 16:51 <DIR> d-------- c:\program files\EASEUS
2009-02-25 16:33 . 2009-02-25 16:33 <DIR> d--h----- c:\windows\$hf_mig$
2009-02-25 16:24 . 2009-02-25 16:24 <DIR> d-------- c:\windows\IIS Temporary Compressed Files
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\system32\scripting
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\system32\en
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\system32\bits
2009-02-24 15:23 . 2009-02-24 15:23 <DIR> d-------- c:\windows\l2schemas
2009-02-24 15:21 . 2009-02-24 15:21 <DIR> d-------- c:\windows\ServicePackFiles
2009-02-19 00:12 . 2009-02-25 12:44 <DIR> d-------- c:\documents and settings\heartlab\Application Data\NBC Direct
2009-02-19 00:11 . 2009-02-19 00:11 <DIR> d-------- c:\program files\Pando Networks
2009-02-19 00:11 . 2009-02-19 00:19 <DIR> d-------- c:\documents and settings\heartlab\Application Data\IDM
2009-02-19 00:11 . 2009-02-25 17:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\PMB Files
2009-02-19 00:11 . 2009-02-19 00:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\NBC Direct
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-13 15:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-13 15:23 --------- d-----w c:\program files\SpywareBlaster
2009-03-13 15:13 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-13 15:08 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-10 05:30 --------- d-----w c:\program files\Microsoft Silverlight
2009-03-10 05:27 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-04 04:40 64,160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-02-26 17:31 --------- d-----w c:\program files\Common Files\Adobe
2009-02-25 14:34 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-25 02:30 --------- d-----w c:\documents and settings\heartlab\Application Data\Move Networks
2009-02-24 21:47 --------- d-----w c:\program files\Java
2009-02-13 04:15 65,024 ----a-w c:\windows\inst_tsp.exe
2009-02-13 04:15 495,616 ----a-w c:\windows\system32\mwtsp.dll
2009-02-13 04:11 176,128 ----a-w c:\windows\system32\mwnsp.dll
2009-02-13 02:31 226,304 ----a-w c:\windows\inst_tspx.exe
2009-02-13 01:15 --------- d-----w c:\program files\Common Files\Sling Media
2009-02-12 22:32 1,085,440 ----a-w c:\windows\system32\contfilt.dll
2009-02-12 16:49 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-09 22:27 --------- d-----w c:\documents and settings\heartlab\Application Data\AdobeUM
2009-02-09 17:58 628,736 ----a-w c:\windows\system32\eslogon.dll
2009-02-04 04:38 --------- dc-h--w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-04 04:38 --------- d-----w c:\program files\Lavasoft
2009-02-04 04:38 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-04 04:37 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-03 13:35 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-02-03 13:25 --------- d-----w c:\program files\MSXML 4.0
2009-02-03 05:34 --------- d-----w c:\documents and settings\heartlab\Application Data\Search Settings
2009-02-03 00:04 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-29 18:08 --------- d-----w c:\program files\eRightSoft
2009-01-29 18:08 --------- d-----w c:\program files\AviSynth 2.5
2009-01-29 17:23 --------- d-----w c:\program files\Free FLV Converter
2009-01-29 17:10 --------- d-----w c:\program files\Search Settings
2009-01-28 20:46 --------- d-----w c:\program files\Real
2009-01-28 20:46 --------- d-----w c:\program files\Common Files\xing shared
2009-01-28 20:46 --------- d-----w c:\program files\Common Files\Real
2009-01-28 20:33 --------- d-----w c:\program files\Hotspot Shield
2009-01-26 15:20 --------- d-----w c:\documents and settings\heartlab\Application Data\Apple Computer
2009-01-25 03:59 --------- d-----w c:\program files\iTunes
2009-01-25 03:59 --------- d-----w c:\program files\iPod
2009-01-25 03:59 --------- d-----w c:\program files\Common Files\Apple
2009-01-25 03:59 --------- d-----w c:\program files\Bonjour
2009-01-25 03:59 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-25 03:59 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-25 03:56 --------- d-----w c:\program files\QuickTime
2009-01-15 23:36 274,432 ----a-w c:\windows\system32\TubeFinder.exe
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 13:30 216,064 --sh--r c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-01-28 15:33 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\heartlab\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-24 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-28 185896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-03 515416]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-24 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"eScan Updater"="c:\progra~1\eScan\TRAYICOS.EXE" [2009-02-12 2779136]
"MailScan Dispatcher"="c:\progra~1\eScan\LAUNCH.EXE" [2009-02-12 761856]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
c:\documents and settings\heartlab\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2008-12-16 869376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-10 19:33 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eSLogOn]
2009-02-09 12:58 628736 c:\windows\system32\eslogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2006-02-14 12:00 8704 c:\windows\system32\PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
backup=c:\windows\pss\Cisco Systems VPN Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^heartlab^Start Menu^Programs^Startup^Rainmeter.lnk]
path=c:\documents and settings\heartlab\Start Menu\Programs\Startup\Rainmeter.lnk
backup=c:\windows\pss\Rainmeter.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
--a------ 2009-01-14 23:44 2210632 c:\program files\Pando Networks\Media Booster\PMB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
--a------ 2009-02-21 03:18 4333568 c:\program files\Rainlendar2\Rainlendar2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
--a------ 2008-06-12 17:57 991584 c:\program files\Search Settings\SearchSettings.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2006-03-24 16:30 282624 c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\PROGRA~1\\eScan\\DOWNLOAD.EXE"=
"c:\\PROGRA~1\\eScan\\TRAYICOS.EXE"=
"c:\\PROGRA~1\\COMMON~1\\MICROW~1\\Agent\\MWAGENT.EXE"=
"c:\\PROGRA~1\\eScan\\LICENSE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
"58508:TCP"= 58508:TCP

MB P2P TCP Listening Port
"58508:UDP"= 58508:UDP

MB P2P UDP Listening Port
R2 studfsvc;SevenTen UDF 2.01 File System;c:\program files\Common Files\UdfViewer\studfsvc.exe [2005-02-21 1159168]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2008-11-25 8704]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2008-11-25 3072]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-03 951120]
R4 avg8emc;AVG Free8 E-mail Scanner; [x]
R4 avg8wd;AVG Free8 WatchDog; [x]
R4 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-10 325640]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-10 107912]
S0 710udfsd;710udfsd;c:\windows\system32\drivers\710udfsd.sys [2004-07-06 8016]
S0 710udfvd;710udfvd;c:\windows\system32\drivers\710udfvd.sys [2004-06-25 8936]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-03 64160]
S1 aswSP;avast! Self Protection; [x]
S1 ECONCEAL;ECONCEAL; [x]
S2 710udffs;710udffs;c:\windows\system32\drivers\710udffs.sys [2005-02-21 98928]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 EconService;eConServ;c:\progra~1\escan\EconSer.exe [2007-06-13 424448]
S2 eScan-trayicos;eScan Server-Updater;c:\progra~1\eScan\TRAYSSER.EXE [2009-02-12 87040]
S2 eScan Monitor Service;eScan Monitor Service;c:\docume~1\ALLUSE~1\APPLIC~1\MICROW~1\eScanBD\avpmapp.exe [2009-03-09 180736]
S2 SlingAgentService;SlingAgent Service;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [2008-12-10 88576]
S3 ProcObsrves;ProcObsrves;c:\progra~1\eScan\ProcObsrves.sys [2009-01-17 11264]
--- Other Services/Drivers In Memory ---
*Deregistered* - 710udffs
*Deregistered* - 710udfsd
*Deregistered* - 710udfvd
*Deregistered* - Aavmker4
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AntiVirScheduler
*Deregistered* - AntiVirService
*Deregistered* - Apple Mobile Device
*Deregistered* - Arp1394
*Deregistered* - Aspi32
*Deregistered* - aswFsBlk
*Deregistered* - aswMon2
*Deregistered* - aswRdr
*Deregistered* - aswSP
*Deregistered* - aswTdi
*Deregistered* - aswUpdSv
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avast! Antivirus
*Deregistered* - avast! Mail Scanner
*Deregistered* - avast! Web Scanner
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - awecho
*Deregistered* - awlegacy
*Deregistered* - bdfsfltr
*Deregistered* - Beep
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - CVPND
*Deregistered* - CVPNDRVA
*Deregistered* - Dhcp
*Deregistered* - DNE
*Deregistered* - Dnscache
*Deregistered* - ECONCEAL
*Deregistered* - EconService
*Deregistered* - ERSvc
*Deregistered* - eScan-trayicos
*Deregistered* - eScan Monitor Service
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gernuwa
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - IISADMIN
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - Lbd
*Deregistered* - LmHosts
*Deregistered* - LVCOMSer
*Deregistered* - LVPr2Mon
*Deregistered* - LVPrcSrv
*Deregistered* - LVSrvLauncher
*Deregistered* - mnmdd
*Deregistered* - Modem
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - MSCamSvc
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - MWAgent
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - OMCI
*Deregistered* - PartMgr
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProcObsrv
*Deregistered* - ProcObsrves
*Deregistered* - ProtectedStorage
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RimVSerPort
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SlingAgentService
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - stisvc
*Deregistered* - studfsvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - tapvpn
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - tmcomm
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - W3SVC
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wltrysvc
*Deregistered* - WMPNetworkSvc
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-03-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-03 23:39]
2009-03-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-707799472-2889999743-2908758316-1005.job
- c:\documents and settings\heartlab\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-24 22:45]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://hlrmdemo/admintool2/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} - hxxp://betaimg.sling.com/sli/sling_player_ax/WebSlingPlayer.cab?1.0.0.19
FF - ProfilePath - c:\documents and settings\heartlab\Application Data\Mozilla\Firefox\Profiles\sre6y4bd.default\
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-16 10:52:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1004)
c:\windows\system32\eSLogOn.dll
.
Completion time: 2009-03-16 10:55:58
ComboFix-quarantined-files.txt 2009-03-16 15:55:51
ComboFix2.txt 2009-03-16 15:37:33
Pre-Run: 59,447,697,408 bytes free
Post-Run: 59,433,422,848 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /Execute /fastdetect
437 --- E O F --- 2009-02-27 14:36:16
DDS Log:
DDS (Ver_09-02-01.01) - NTFSx86
Run by heartlab at 11:00:49.14 on Mon 03/16/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_10
AV: eScan Anti-Virus (AV) Edition for Windows *On-access scanning disabled* (Updated)
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
AV: avast! antivirus 4.8.1335 [VPS 090316-0] *On-access scanning disabled* (Updated)
FW: eScan Firewall For Windows *disabled*
============== Running Processes ===============
============== Pseudo HJT Report ===============
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://hlrmdemo/admintool2/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
uRun: [Google Update] "c:\documents and settings\heartlab\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [eScan Updater] c:\progra~1\escan\TRAYICOS.EXE /App
mRun: [MailScan Dispatcher] "c:\progra~1\escan\LAUNCH.EXE" /startup
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
StartupFolder: c:\docume~1\heartlab\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\printk~1.lnk - c:\program files\printkey2000\Printkey2000.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233638298468
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233638288609
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} - hxxp://betaimg.sling.com/sli/sling_player_ax/WebSlingPlayer.cab?1.0.0.19
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Notify: avgrsstarter - avgrsstx.dll
Notify: eSLogOn - eSLogOn.dll
Notify: igfxcui - igfxdev.dll
Notify: PCANotify - PCANotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\heartlab\applic~1\mozilla\firefox\profiles\sre6y4bd.default\
---- FIREFOX POLICIES ----
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-03-16 10:49 <DIR> a-dshr-- C:\cmdcons
2009-03-16 10:18 161,792 a------- c:\windows\SWREG.exe
2009-03-16 10:18 98,816 a------- c:\windows\sed.exe
2009-03-13 11:15 <DIR> --d----- c:\program files\Avira
2009-03-13 11:15 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-03-12 00:33 25 a------- c:\windows\escan.dbf
2009-03-11 16:24 247,944 a------- c:\windows\system32\drivers\bdfsfltr.sys
2009-03-11 16:24 20 a------- c:\windows\WIN.PRO
2009-03-11 16:23 <DIR> --d----- c:\docume~1\heartlab\applic~1\MicroWorld
2009-03-11 16:22 142,624 a------- c:\windows\winsbak2.reg
2009-03-11 16:22 20,626 a------- c:\windows\winsbak.reg
2009-03-11 16:22 210 a------- C:\bootini.ins
2009-03-11 16:20 22,784 a------- c:\windows\system32\drivers\econceal.sys
2009-03-11 16:20 118,784 a------- c:\windows\killproc.exe
2009-03-11 16:19 509,952 a------- c:\windows\system32\eInstall.exe
2009-03-11 16:18 <DIR> --d----- c:\program files\eScan
2009-03-11 14:40 0 a------- C:\23990098.$$$
2009-03-11 11:12 6,827,726 a------- c:\windows\REGBK00.ZIP
2009-03-11 11:08 28 a------- c:\windows\Lic.xxx
2009-03-11 11:06 626,688 a------- c:\windows\system32\msvcr80.dll
2009-03-11 11:06 548,864 a------- c:\windows\system32\msvcp80.dll
2009-03-11 11:06 28,672 a------- c:\windows\system32\eEmpty.exe
2009-03-11 11:06 522 a------- c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-03-11 11:06 146,432 a------- c:\windows\R.COM
2009-03-11 11:06 135,680 a------- c:\windows\system32\T.COM
2009-03-11 11:06 <DIR> --d----- c:\program files\common files\MicroWorld
2009-03-11 11:05 <DIR> --d----- c:\docume~1\alluse~1\applic~1\MicroWorld
2009-03-11 00:30 <DIR> --d----- c:\docume~1\heartlab\applic~1\Research In Motion
2009-03-10 19:33 107,912 a------- c:\windows\system32\drivers\avgtdix.sys
2009-03-10 19:33 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-03-10 19:33 325,640 a------- c:\windows\system32\drivers\avgldx86.sys
2009-03-10 19:33 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-03-10 19:33 <DIR> --d----- c:\program files\AVG
2009-03-10 19:33 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-03-10 17:10 664 a------- c:\windows\system32\d3d9caps.dat
2009-03-10 15:22 <DIR> --d----- c:\docume~1\heartlab\applic~1\Malwarebytes
2009-03-10 15:15 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-03-10 15:15 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-10 15:15 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-03-10 15:15 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-03-10 10:50 138,384 a------- c:\windows\system32\drivers\tmcomm.sys
2009-03-10 10:49 <DIR> --d----- c:\docume~1\heartlab\applic~1\HouseCall 6.6
2009-03-10 00:27 <DIR> --d----- c:\program files\Roxio
2009-03-10 00:27 <DIR> --d----- c:\program files\common files\Sonic Shared
2009-03-10 00:15 26,496 a----r-- c:\windows\system32\drivers\RimSerial.sys
2009-03-10 00:14 <DIR> --d----- c:\program files\common files\Research In Motion
2009-03-10 00:14 <DIR> --d----- c:\program files\Research In Motion
2009-03-07 14:35 15,688 a------- c:\windows\system32\lsdelete.exe
2009-03-06 01:49 <DIR> --d----- c:\program files\Rainmeter
2009-03-06 01:46 <DIR> --d----- c:\documents and settings\heartlab\.rainlendar2
2009-03-06 01:45 <DIR> --d----- c:\program files\Rainlendar2
2009-03-06 00:28 <DIR> --d----- c:\program files\EvilLyrics
2009-02-25 17:24 <DIR> --d----- C:\Photos
2009-02-25 17:10 727 a---hr-- c:\windows\EPMBatch.ept
2009-02-25 16:59 <DIR> --d----- c:\docume~1\heartlab\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-25 16:51 <DIR> --d----- c:\program files\EASEUS
2009-02-25 16:33 <DIR> --d-h--- c:\windows\$hf_mig$
2009-02-25 16:24 <DIR> --d----- c:\windows\IIS Temporary Compressed Files
2009-02-24 15:23 <DIR> --d----- c:\windows\system32\scripting
2009-02-24 15:23 <DIR> --d----- c:\windows\system32\en
2009-02-24 15:23 <DIR> --d----- c:\windows\system32\bits
2009-02-24 15:23 <DIR> --d----- c:\windows\l2schemas
2009-02-24 15:21 <DIR> --d----- c:\windows\ServicePackFiles
2009-02-19 00:12 <DIR> --d----- c:\docume~1\heartlab\applic~1\NBC Direct
2009-02-19 00:11 <DIR> --d----- c:\docume~1\heartlab\applic~1\IDM
2009-02-19 00:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PMB Files
2009-02-19 00:11 <DIR> --d----- c:\program files\Pando Networks
2009-02-19 00:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NBC Direct
==================== Find3M ====================
2009-03-03 23:40 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-24 15:26 87,263 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-02-12 23:15 65,024 a------- c:\windows\inst_tsp.exe
2009-02-12 23:15 495,616 a------- c:\windows\system32\mwtsp.dll
2009-02-12 23:11 176,128 a------- c:\windows\system32\mwnsp.dll
2009-02-12 21:31 226,304 a------- c:\windows\inst_tspx.exe
2009-02-12 17:32 1,085,440 a------- c:\windows\system32\contfilt.dll
2009-02-09 12:58 628,736 a------- c:\windows\system32\eslogon.dll
2009-01-15 18:36 274,432 a------- c:\windows\system32\TubeFinder.exe
2009-01-05 17:33 3,751,995 a------- c:\windows\system32\GPhotos.scr
2008-12-20 18:15 826,368 a------- c:\windows\system32\wininet.dll
2006-05-03 05:06 163,328 ---shr-- c:\windows\system32\flvDX.dll
2007-02-21 06:47 31,232 ---shr-- c:\windows\system32\msfDX.dll
2008-03-16 08:30 216,064 ---shr-- c:\windows\system32\nbDX.dll
============= FINISH: 11:01:46.26 ===============
I also zipped and attached the attach.txt file.
Again, many thanks for your help.