View Single Post
Old 01-22-2008, 09:12 PM   #44 (permalink)
BunnMan
Registered User
 
Join Date: Jan 2008
Posts: 30
OS: Windows XP Home SP2 V.5.1


Re: Bad Malware infection - Spy-rid, InfeStop, Easy Spyware Cleaner

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-22 23:11:41
Windows 5.1.2600 Service Pack 2

scanning processes ...

System [4]
C:\WINDOWS\SYSTEM32\SMSS.EXE [588] 0x8228F640
C:\WINDOWS\SYSTEM32\CSRSS.EXE [636] 0x82411590
C:\WINDOWS\SYSTEM32\WINLOGON.EXE [660] 0x8225C1D8
C:\WINDOWS\SYSTEM32\SERVICES.EXE [704] 0x82559020
C:\WINDOWS\SYSTEM32\LSASS.EXE [716] 0x822E6020
C:\WINDOWS\SYSTEM32\ati2evxx.exe [884] 0x8228BBF8
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [900] 0x822C8020
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [972] 0x82303830
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [1068] 0x822E65A0
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [1192] 0x823143D8
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [1236] 0x824C2840
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe [1344] 0x822D99D8
C:\WINDOWS\explorer.exe [1732] 0x8196B4E0
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [1852] 0x81932020
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [1880] 0x819315E8
C:\Program Files\Grisoft\AVG7\avgamsvr.exe [1908] 0x8176CDA0
C:\Program Files\Grisoft\AVG7\avgupsvc.exe [1952] 0x817ECC18
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe [1972] 0x81756DA0
C:\Program Files\Grisoft\AVG7\avgemc.exe [1988] 0x817FF748
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE [2028] 0x81762BE0
C:\WINDOWS\SYSTEM32\HPZipm12.exe [148] 0x81759A50
C:\Program Files\PurgeIE\PurgeIE_Service.exe [188] 0x81742700
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [348] 0x8175DA30
C:\WINDOWS\SYSTEM32\MsPMSPSv.exe [412] 0x817F0660
C:\Program Files\HP\HP Software Update\hpwuschd2.exe [1036] 0x8172D638
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\ctsysvol.exe [1044] 0x817B5BE0
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe [1184] 0x81941970
C:\WINDOWS\SYSTEM32\CTFMON.EXE [176] 0x822C2A20
C:\Program Files\Messenger\msmsgs.exe [228] 0x817AE668
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [236] 0x82391DA0
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [932] 0x824A4968
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\logitechdesktopmessenger.exe [1808] 0x823955E0
C:\WINDOWS\SYSTEM32\ALG.EXE [1544] 0x817B8020
C:\Program Files\Logitech\SetPoint\SetPoint.exe [1676] 0x8175E740
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE [1712] 0x8177D840
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe [2300] 0x817B2428
C:\Program Files\SpywareGuard\sgmain.exe [2352] 0x823436C0
C:\Program Files\SpywareGuard\sgbhp.exe [2440] 0x822A4410
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE [2456] 0x82423540
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe [2552] 0x822D1550
C:\Program Files\Internet Explorer\iexplore.exe [2876] 0x8239AA20
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn4\YTBSDK.exe [2972] 0x816F37B8
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe [3788] 0x8173F6B8
C:\Documents and Settings\Daddy\My Documents\querySvc.exe [3664] 0x816D4020
C:\WINDOWS\SYSTEM32\CMD.EXE [3908] 0x81802B28
C:\DOCUME~1\Daddy\LOCALS~1\Temp\RarSFX0\catchme.exe [820] 0x824FC678



------ Services [Running]

SERVICE_NAME: ALG
SERVICE_NAME: Apple Mobile Device
SERVICE_NAME: Ati HotKey Poller
SERVICE_NAME: AudioSrv
SERVICE_NAME: AVG Anti-Spyware Guard
SERVICE_NAME: Avg7Alrt
SERVICE_NAME: Avg7UpdSvc
SERVICE_NAME: AvgCoreSvc
SERVICE_NAME: AVGEMS
SERVICE_NAME: Browser
SERVICE_NAME: Creative Service for CDROM Access
SERVICE_NAME: CryptSvc
SERVICE_NAME: DcomLaunch
SERVICE_NAME: Dhcp
SERVICE_NAME: Dnscache
SERVICE_NAME: ERSvc
SERVICE_NAME: Eventlog
SERVICE_NAME: EventSystem
SERVICE_NAME: FastUserSwitchingCompatibility
SERVICE_NAME: helpsvc
SERVICE_NAME: lanmanserver
SERVICE_NAME: lanmanworkstation
SERVICE_NAME: LmHosts
SERVICE_NAME: Netman
SERVICE_NAME: Nla
SERVICE_NAME: PlugPlay
SERVICE_NAME: Pml Driver HPZ12
SERVICE_NAME: PolicyAgent
SERVICE_NAME: ProtectedStorage
SERVICE_NAME: PurgeIEservice
SERVICE_NAME: RasMan
SERVICE_NAME: RpcSs
SERVICE_NAME: SamSs
SERVICE_NAME: Schedule
SERVICE_NAME: seclogon
SERVICE_NAME: SENS
SERVICE_NAME: SharedAccess
SERVICE_NAME: ShellHWDetection
SERVICE_NAME: srservice
SERVICE_NAME: SSDPSRV
SERVICE_NAME: stisvc
SERVICE_NAME: TapiSrv
SERVICE_NAME: TermService
SERVICE_NAME: Themes
SERVICE_NAME: TrkWks
SERVICE_NAME: w32time
SERVICE_NAME: WebClient
SERVICE_NAME: winmgmt
SERVICE_NAME: WMDM PMSP Service
SERVICE_NAME: wscsvc
SERVICE_NAME: wuauserv
SERVICE_NAME: WZCSVC

------ Services [Stopped]

SERVICE_NAME: Alerter
SERVICE_NAME: AppMgmt
SERVICE_NAME: aspnet_state
SERVICE_NAME: ATI Smart
SERVICE_NAME: AVGFwSrv
SERVICE_NAME: BITS
SERVICE_NAME: CiSvc
SERVICE_NAME: ClipSrv
SERVICE_NAME: clr_optimization_v2.0.50727_32
SERVICE_NAME: COMSysApp
SERVICE_NAME: dmadmin
SERVICE_NAME: dmserver
SERVICE_NAME: Fax
SERVICE_NAME: HidServ
SERVICE_NAME: HTTPFilter
SERVICE_NAME: IDriverT
SERVICE_NAME: ImapiService
SERVICE_NAME: iPod Service
SERVICE_NAME: LexBceS
SERVICE_NAME: Messenger
SERVICE_NAME: mnmsrvc
SERVICE_NAME: MSDTC
SERVICE_NAME: MSIServer
SERVICE_NAME: NetDDE
SERVICE_NAME: NetDDEdsdm
SERVICE_NAME: Netlogon
SERVICE_NAME: NetSvc
SERVICE_NAME: NtLmSsp
SERVICE_NAME: NtmsSvc
SERVICE_NAME: RasAuto
SERVICE_NAME: RDSessMgr
SERVICE_NAME: RemoteAccess
SERVICE_NAME: RpcLocator
SERVICE_NAME: RSVP
SERVICE_NAME: SCardSvr
SERVICE_NAME: Spooler
SERVICE_NAME: SwPrv
SERVICE_NAME: SysmonLog
SERVICE_NAME: upnphost
SERVICE_NAME: UPS
SERVICE_NAME: VSS
SERVICE_NAME: WmdmPmSN
SERVICE_NAME: WmiApSrv
SERVICE_NAME: WMPNetworkSvc
SERVICE_NAME: WudfSvc
SERVICE_NAME: xmlprov

------ Drivers [Running]

SERVICE_NAME: abp480n5
SERVICE_NAME: ACPI
SERVICE_NAME: adpu160m
SERVICE_NAME: AFD
SERVICE_NAME: agp440
SERVICE_NAME: agpCPQ
SERVICE_NAME: Aha154x
SERVICE_NAME: aic78u2
SERVICE_NAME: aic78xx
SERVICE_NAME: AliIde
SERVICE_NAME: alim1541
SERVICE_NAME: amdagp
SERVICE_NAME: amsint
SERVICE_NAME: asc
SERVICE_NAME: asc3350p
SERVICE_NAME: asc3550
SERVICE_NAME: atapi
SERVICE_NAME: ati2mtag
SERVICE_NAME: audstub
SERVICE_NAME: AVG Anti-Spyware Driver
SERVICE_NAME: AvgAsCln
SERVICE_NAME: AvgClean
SERVICE_NAME: AvgMfx86
SERVICE_NAME: AvgTdi
SERVICE_NAME: Beep
SERVICE_NAME: catchme
SERVICE_NAME: cbidf
SERVICE_NAME: cd20xrnt
SERVICE_NAME: Cdfs
SERVICE_NAME: Cdrom
SERVICE_NAME: CmdIde
SERVICE_NAME: Cpqarray
SERVICE_NAME: ctsfm2k
SERVICE_NAME: dac2w2k
SERVICE_NAME: dac960nt
SERVICE_NAME: Disk
SERVICE_NAME: dpti2o
SERVICE_NAME: E100B
SERVICE_NAME: Fips
SERVICE_NAME: FltMgr
SERVICE_NAME: Ftdisk
SERVICE_NAME: GEARAspiWDM
SERVICE_NAME: Gpc
SERVICE_NAME: hpn
SERVICE_NAME: HPZid412
SERVICE_NAME: HPZipr12
SERVICE_NAME: HPZius12
SERVICE_NAME: HTTP
SERVICE_NAME: i2omgmt
SERVICE_NAME: i2omp
SERVICE_NAME: i8042prt
SERVICE_NAME: Imapi
SERVICE_NAME: ini910u
SERVICE_NAME: IntelC51
SERVICE_NAME: IntelC52
SERVICE_NAME: IntelC53
SERVICE_NAME: IntelIde
SERVICE_NAME: intelppm
SERVICE_NAME: IpFilterDriver
SERVICE_NAME: IpNat
SERVICE_NAME: IPSec
SERVICE_NAME: isapnp
SERVICE_NAME: Kbdclass
SERVICE_NAME: KSecDD
SERVICE_NAME: L8042Kbd
SERVICE_NAME: LHidKe
SERVICE_NAME: LHidUsbK
SERVICE_NAME: LMouKE
SERVICE_NAME: MCSTRM
SERVICE_NAME: mnmdd
SERVICE_NAME: Modem
SERVICE_NAME: MODEMCSA
SERVICE_NAME: mohfilt
SERVICE_NAME: Mouclass
SERVICE_NAME: mouhid
SERVICE_NAME: MountMgr
SERVICE_NAME: mraid35x
SERVICE_NAME: MRxDAV
SERVICE_NAME: MRxSmb
SERVICE_NAME: Msfs
SERVICE_NAME: mssmbios
SERVICE_NAME: Mup
SERVICE_NAME: Nbf
SERVICE_NAME: NDIS
SERVICE_NAME: NdisTapi
SERVICE_NAME: Ndisuio
SERVICE_NAME: NdisWan
SERVICE_NAME: NDProxy
SERVICE_NAME: NetBIOS
SERVICE_NAME: NetBT
SERVICE_NAME: Npfs
SERVICE_NAME: Ntfs
SERVICE_NAME: Null
SERVICE_NAME: omci
SERVICE_NAME: ossrv
SERVICE_NAME: P17
SERVICE_NAME: Parport
SERVICE_NAME: PartMgr
SERVICE_NAME: PCI
SERVICE_NAME: PCIIde
SERVICE_NAME: perc2
SERVICE_NAME: perc2hib
SERVICE_NAME: pfc
SERVICE_NAME: PfModNT
SERVICE_NAME: PptpMiniport
SERVICE_NAME: PSched
SERVICE_NAME: Ptilink
SERVICE_NAME: PxHelp20
SERVICE_NAME: ql1080
SERVICE_NAME: Ql10wnt
SERVICE_NAME: ql12160
SERVICE_NAME: ql1240
SERVICE_NAME: ql1280
SERVICE_NAME: RasAcd
SERVICE_NAME: Rasl2tp
SERVICE_NAME: RasPppoe
SERVICE_NAME: Raspti
SERVICE_NAME: Rdbss
SERVICE_NAME: RDPCDD
SERVICE_NAME: redbook
SERVICE_NAME: serenum
SERVICE_NAME: Serial
SERVICE_NAME: sisagp
SERVICE_NAME: Sparrow
SERVICE_NAME: sr
SERVICE_NAME: Srv
SERVICE_NAME: swenum
SERVICE_NAME: symc810
SERVICE_NAME: symc8xx
SERVICE_NAME: sym_hi
SERVICE_NAME: sym_u3
SERVICE_NAME: sysaudio
SERVICE_NAME: Tcpip
SERVICE_NAME: TermDD
SERVICE_NAME: TosIde
SERVICE_NAME: ultra
SERVICE_NAME: Update
SERVICE_NAME: usbccgp
SERVICE_NAME: usbehci
SERVICE_NAME: usbhub
SERVICE_NAME: usbprint
SERVICE_NAME: usbscan
SERVICE_NAME: usbuhci
SERVICE_NAME: VgaSave
SERVICE_NAME: viaagp
SERVICE_NAME: ViaIde
SERVICE_NAME: VolSnap
SERVICE_NAME: Wanarp
SERVICE_NAME: wdmaud
SERVICE_NAME: WmBEnum
SERVICE_NAME: WmXlCore

------ Drivers [Stopped]

SERVICE_NAME: Abiosdsk
SERVICE_NAME: ACPIEC
SERVICE_NAME: aec
SERVICE_NAME: AsyncMac
SERVICE_NAME: Atdisk
SERVICE_NAME: Atmarpc
SERVICE_NAME: bvrp_pci
SERVICE_NAME: cbidf2k
SERVICE_NAME: Cdaudio
SERVICE_NAME: Changer
SERVICE_NAME: dmboot
SERVICE_NAME: dmio
SERVICE_NAME: dmload
SERVICE_NAME: DMusic
SERVICE_NAME: drmkaud
SERVICE_NAME: Fastfat
SERVICE_NAME: Fdc
SERVICE_NAME: Flpydisk
SERVICE_NAME: gameenum
SERVICE_NAME: HidUsb
SERVICE_NAME: Ip6Fw
SERVICE_NAME: IpInIp
SERVICE_NAME: IRENUM
SERVICE_NAME: kbdhid
SERVICE_NAME: kmixer
SERVICE_NAME: lbrtfdc
SERVICE_NAME: mrtRate
SERVICE_NAME: MSKSSRV
SERVICE_NAME: MSPCLOCK
SERVICE_NAME: MSPQM
SERVICE_NAME: nv
SERVICE_NAME: NwlnkFlt
SERVICE_NAME: NwlnkFwd
SERVICE_NAME: PalmUSBD
SERVICE_NAME: ParVdm
SERVICE_NAME: PCIDump
SERVICE_NAME: Pcmcia
SERVICE_NAME: PDCOMP
SERVICE_NAME: PDFRAME
SERVICE_NAME: PDRELI
SERVICE_NAME: PDRFRAME
SERVICE_NAME: Point32
SERVICE_NAME: rdpdr
SERVICE_NAME: RDPWD
SERVICE_NAME: Secdrv
SERVICE_NAME: Sfloppy
SERVICE_NAME: Simbad
SERVICE_NAME: splitter
SERVICE_NAME: swmidi
SERVICE_NAME: TDPIPE
SERVICE_NAME: TDTCP
SERVICE_NAME: Udfs
SERVICE_NAME: USBAAPL
SERVICE_NAME: USBSTOR
SERVICE_NAME: wanatw
SERVICE_NAME: WDICA
SERVICE_NAME: WmFilter
SERVICE_NAME: WmVirHid
SERVICE_NAME: WpdUsb
SERVICE_NAME: WS2IFSL
SERVICE_NAME: WudfPf
SERVICE_NAME: WudfRd
BunnMan is offline