Go Back   Yahoo Booters And Yahoo Tools > Technology related > VipraSys Lab

VipraSys Lab Have you been infected by a program found anywhere on the internet ? Did you find any program which you think is possibly infected but not sure, post it here and get a solution from our dedicated members.



Welcome to the VipraSys forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features such as download links. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, Register Now by clicking here!

Post New Thread  Reply
 
LinkBack Thread Tools Display Modes
Old 07-04-2008, 07:05 PM   #1 (permalink)
Banned
 
Join Date: Dec 2007
Location: Cali
Posts: 659

Thanks: 325
Thanked 1,871 Times in 405 Posts
Reputation: 28177
Hypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond repute
New Post Check me on new pc :yrock:

Logfile of HijackThis v1.99.1
Scan saved at 11:01:49 AM, on 7/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Documents and Settings\Chris\My Documents\My Stuff\(Hitting Stuff)\SAFC\****ty Ass ****in Cracker.exe
C:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe
C:\Documents and Settings\Chris\My Documents\My Stuff\(Not Yahoo)\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Only registered users can see links. ]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Only registered users can see links. ]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Only registered users can see links. ]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Only registered users can see links. ]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: wbsys.dll,avgrsstx.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
Hypn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following 2 Users Say Thank You to Hypn For This Useful Post:
as1f3102 (07-05-2008), ___Dre___ (07-04-2008)
Old 07-04-2008, 07:07 PM   #2 (permalink)
~~Special-Ones~~
 
~~ViT~~'s Avatar
 
Join Date: Feb 2007
Location: In the middle of nothing... in the middle of everything ...
Posts: 14,760

Thanks: 560
Thanked 31,033 Times in 6,647 Posts
Reputation: 109103
~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute
Default Re: Check me on new pc :yrock:

noting

if u tink u have something just run a combofix in normal mode and post the notpade
~~ViT~~ is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-04-2008, 07:12 PM   #3 (permalink)
Banned
 
Join Date: Dec 2007
Location: Cali
Posts: 659

Thanks: 325
Thanked 1,871 Times in 405 Posts
Reputation: 28177
Hypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond reputeHypn has a reputation beyond repute
Default Re: Check me on new pc :yrock:

ComboFix 08-07-04.1 - Chris 2008-07-04 11:10:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1512 [GMT -7:00]
Running from: C:\Documents and Settings\Chris\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\msvrc20.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.
2008-07-03 12:36 . 2008-07-03 19:20 <DIR> d-------- C:\Program Files\DivX
2008-07-02 22:38 . 2008-07-02 22:38 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\Apple Computer
2008-07-02 22:37 . 2008-07-03 01:07 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-02 22:37 . 2008-07-03 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-02 21:24 . 2008-07-02 21:24 <DIR> d-------- C:\Documents and Settings\Chris\Shared
2008-07-02 21:24 . 2008-07-02 21:24 <DIR> d-------- C:\Documents and Settings\Chris\Incomplete
2008-07-02 21:24 . 2008-07-02 21:37 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\FrostWire
2008-07-02 15:41 . 2008-07-02 15:47 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\YTK Lite
2008-07-02 14:59 . 2007-05-03 01:36 778,240 --a------ C:\WINDOWS\system32\SkinCrafter2.dll
2008-07-02 14:58 . 2006-01-20 14:19 389,120 --a------ C:\WINDOWS\system32\actskn43.ocx
2008-07-02 14:24 . 2004-07-01 04:56 90,112 --a------ C:\WINDOWS\system32\YMSG12ENCRYPT.dll
2008-07-02 14:07 . 2008-07-02 14:07 265,728 --a------ C:\WINDOWS\system32\MSCOMCTL.oca
2008-07-02 14:07 . 2008-07-02 14:07 28,672 --a------ C:\WINDOWS\system32\prjchameleon.oca
2008-07-02 12:48 . 2008-07-03 20:50 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-02 12:42 . 2008-01-04 07:30 20,480 --a------ C:\WINDOWS\system32\VcHook.dll
2008-07-02 12:15 . 2008-07-02 12:15 <DIR> d-------- C:\Documents and Settings\Chris\temp
2008-07-02 12:15 . 2008-07-02 12:20 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\TeamViewer
2008-07-02 10:10 . 2008-07-02 10:10 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-02 10:10 . 2008-07-02 10:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-02 09:15 . 2008-07-02 09:15 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\MSN6
2008-07-02 09:15 . 2008-07-02 09:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-07-02 07:16 . 2008-07-02 07:16 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-01 23:25 . 2008-07-01 23:25 <DIR> d-------- C:\Program Files\IObit
2008-07-01 23:14 . 2008-07-04 09:52 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-01 23:14 . 2008-07-01 23:14 <DIR> d-------- C:\Program Files\AVG
2008-07-01 23:14 . 2008-07-01 23:24 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\AVGTOOLBAR
2008-07-01 23:14 . 2008-07-01 23:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-01 23:14 . 2008-07-02 07:16 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-01 23:14 . 2008-07-02 07:16 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-01 22:46 . 2008-07-01 22:46 <DIR> d-------- C:\WINDOWS\Sun
2008-07-01 22:19 . 2008-07-01 22:19 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-07-01 22:11 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-07-01 21:59 . 2008-07-01 21:59 <DIR> d-------- C:\Program Files\Stardock
2008-07-01 21:31 . 2008-07-01 21:32 98,304 --a------ C:\WINDOWS\system32\kewlbutton.ocx
2008-07-01 21:24 . 2008-07-01 21:24 98,304 --a------ C:\WINDOWS\system32\prjChameleon.ocx
2008-07-01 21:22 . 2008-07-02 07:50 360,064 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-07-01 21:18 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-01 21:17 . 2008-07-01 21:18 <DIR> d-------- C:\Program Files\Java
2008-07-01 21:17 . 2008-07-01 21:17 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-01 21:05 . 1998-06-02 12:05 103,424 --a------ C:\WINDOWS\extrac32.exe
2008-07-01 21:05 . 2008-07-01 21:05 0 --a------ C:\WINDOWS\WB.ini
2008-07-01 21:00 . 2007-07-11 15:06 42,672 --a------ C:\WINDOWS\system32\wbsys.dll
2008-07-01 21:00 . 2005-01-22 19:05 20,480 --a------ C:\WINDOWS\system32\wbload.dll
2008-07-01 21:00 . 2008-07-01 21:13 4,264 --a------ C:\WINDOWS\langorig.ini
2008-07-01 20:48 . 2007-07-09 06:16 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-07-01 20:48 . 2008-06-13 06:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-01 20:35 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-07-01 20:33 . 2008-07-01 20:33 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-01 20:33 . 2008-07-01 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-01 08:22 . 2008-07-01 08:22 <DIR> d-------- C:\Program Files\NETGEAR
2008-07-01 08:22 . 2007-04-27 06:00 1,069,056 --a------ C:\WINDOWS\system32\libeay32.dll
2008-07-01 08:22 . 2005-07-20 04:53 966,765 --a------ C:\WINDOWS\system32\acAuth.dll
2008-07-01 08:22 . 2007-12-25 11:24 344,064 --a------ C:\WINDOWS\system32\SCMLib.dll
2008-07-01 08:22 . 2007-12-26 10:47 272,128 --a------ C:\WINDOWS\system32\drivers\wg111v2.sys
2008-07-01 08:22 . 2007-12-18 15:46 266,240 --a------ C:\WINDOWS\system32\WG1v2lib.dll
2008-07-01 08:22 . 2005-01-25 14:30 143,360 --a------ C:\WINDOWS\system32\IpLib.dll
2008-07-01 08:22 . 2006-07-27 14:26 36,864 --a------ C:\WINDOWS\system32\RtlGina2.dll
2008-07-01 08:22 . 2008-07-01 08:22 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-07-01 08:13 . 2008-07-01 08:13 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-01 08:13 . 2004-08-04 00:56 2,897,920 --a------ C:\WINDOWS\system32\xpsp2res.dll
2008-07-01 08:13 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\002237_.tmp
2008-07-01 08:12 . 2008-07-01 08:12 <DIR> d-------- C:\WINDOWS\EHome
2008-07-01 08:04 . 2005-03-24 15:39 59,136 --a------ C:\WINDOWS\system32\drivers\EAPPkt.sys
2008-07-01 08:03 . 2008-07-01 08:03 <DIR> d-------- C:\Documents and Settings\Chris\Application Data\InstallShield
2008-06-10 17:04 . 2008-06-10 17:04 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-06-10 17:04 . 2008-06-10 17:04 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-07-02 14:50 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-07-02 04:41 --------- d-----w C:\Program Files\Realtek
2008-07-01 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-01 14:57 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-07-01 14:55 --------- d-----w C:\Program Files\Driver
2008-07-01 14:54 --------- d-----w C:\Program Files\VIA
2008-07-01 14:54 --------- d-----w C:\Program Files\S3
2008-07-01 14:54 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-01 14:35 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
------- Sigcheck -------
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2003-03-31 05:00 332928 244a2f9816bc9b593957281ef577d976 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2008-07-01 21:22 359040 27a5959c94ee173a063ca06bd14f021a C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\SoftwareDistribution\Download\146ae5e7b 51a37f45e0e5cf03d0d5e3c\sp2gdr\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\SoftwareDistribution\Download\146ae5e7b 51a37f45e0e5cf03d0d5e3c\sp2qfe\tcpip.sys
2008-07-02 07:50 360064 e5a5bd94feba349e9dd0d5d90268bdf1 C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-02 07:16 1232152]
"VTTimer"="VTTimer.exe" [2006-09-21 16:36 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2007-02-06 07:30 176128 C:\WINDOWS\system32\VTTrayp.exe]
"SkyTel"="SkyTel.EXE" [2007-05-28 20:39 1826816 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 14:49 16377344 C:\WINDOWS\RTHDCPL.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2008-07-01 08:22:04 1261568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2007-09-23 10:10 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll,avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [2007-03-26 15:26]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX3 2.sys [2007-03-29 11:36]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [2007-03-26 15:26]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-02 07:16]
R1 BIOS;BIOS;C:\WINDOWS\System32\drivers\BIOS.sys [2005-03-15 23:23]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-02 07:16]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-02 07:16]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-02 07:16]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2007-12-26 10:47]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-02-27 01:14]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-07-03 23:30:00 C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job"
- C:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoCare.exe
"2008-07-04 03:00:34 C:\WINDOWS\Tasks\AwcProUpdate.job"
- C:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoUpdate.ex
- C:\Program Files\IObit\Advanced WindowsCare V2 Pro\
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Only registered users can see links. ]
Rootkit scan 2008-07-04 11:11:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-07-04 11:11:38
ComboFix-quarantined-files.txt 2008-07-04 18:11:36
Pre-Run: 151,395,323,904 bytes free
Post-Run: 151,388,352,512 bytes free
167 --- E O F --- 2008-07-03 07:13:00
Hypn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-05-2008, 12:37 PM   #4 (permalink)
~~Special-Ones~~
 
~~ViT~~'s Avatar
 
Join Date: Feb 2007
Location: In the middle of nothing... in the middle of everything ...
Posts: 14,760

Thanks: 560
Thanked 31,033 Times in 6,647 Posts
Reputation: 109103
~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute~~ViT~~ has a reputation beyond repute
Default Re: Check me on new pc :yrock:

all ok

if u have some problem with Advanced WindowsCare
is beacuse that gabage dll come with the prog

C:\WINDOWS\msvrc20.dll
~~ViT~~ is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to ~~ViT~~ For This Useful Post:
__CHILLI__ (07-05-2008)
Post New Thread  Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
bro plz check my log ^:)^ __~lord.ExpLoit~__ VipraSys Lab 3 04-11-2008 10:38 AM
check it bro vit =)):)) _kalbo_ VipraSys Lab 3 04-11-2008 10:22 AM
check log bro ~~ftp~~ VipraSys Lab 1 04-11-2008 10:07 AM
Check It ~~ViT~~ Yahoo! Tools 0 11-25-2007 04:42 PM
Y-X-Bot-Check ~~ViT~~ Yahoo! Tools 1 05-31-2007 03:27 PM


All times are GMT. The time now is 12:56 PM.

Page generated in 0.2100 seconds (75.42% PHP - 24.58% MySQL) with 17 queries

Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0..
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The logos and trademarks used on this site are the property of their respective owners.
We are not responsible for comments posted by our users, as they are the property of the poster.