GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-10 13:17:47
Windows 5.1.2600 Service Pack 2
---- User code sections - GMER 1.0.15 ----
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[188] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[188] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[188] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[188] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[188] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[188] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[572] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10034020
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[572] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10033F4C
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[572] WS2_32.dll!send 71AB428A 5 Bytes JMP 10033734
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[572] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10032D80
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[572] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10032CD0
.text C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe[572] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10033F14
.text C:\WINDOWS\system32\winlogon.exe[628] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\winlogon.exe[628] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\winlogon.exe[628] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\winlogon.exe[628] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\winlogon.exe[628] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\winlogon.exe[628] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\services.exe[676] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\services.exe[676] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\services.exe[676] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\services.exe[676] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\services.exe[676] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\services.exe[676] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\lsass.exe[688] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\lsass.exe[688] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\lsass.exe[688] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\lsass.exe[688] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\lsass.exe[688] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\lsass.exe[688] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\svchost.exe[868] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\svchost.exe[868] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\svchost.exe[868] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\svchost.exe[868] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\svchost.exe[868] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\System32\svchost.exe[1028] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\System32\svchost.exe[1028] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\System32\svchost.exe[1028] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\System32\svchost.exe[1028] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\System32\svchost.exe[1028] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\System32\svchost.exe[1028] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\Explorer.EXE[1672] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\Explorer.EXE[1672] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\Explorer.EXE[1672] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\Explorer.EXE[1672] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\Explorer.EXE[1672] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\Explorer.EXE[1672] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\System32\svchost.exe[1736] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\System32\svchost.exe[1736] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\System32\svchost.exe[1736] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\System32\svchost.exe[1736] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\System32\svchost.exe[1736] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\System32\svchost.exe[1736] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\spoolsv.exe[1832] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\spoolsv.exe[1832] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\spoolsv.exe[1832] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\spoolsv.exe[1832] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\spoolsv.exe[1832] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\spoolsv.exe[1832] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\PROGRA~1\Mozilla Firefox\firefox.exe[2488] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\PROGRA~1\Mozilla Firefox\firefox.exe[2488] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\PROGRA~1\Mozilla Firefox\firefox.exe[2488] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\PROGRA~1\Mozilla Firefox\firefox.exe[2488] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\PROGRA~1\Mozilla Firefox\firefox.exe[2488] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\PROGRA~1\Mozilla Firefox\firefox.exe[2488] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
? C:\WINDOWS\System32\svchost.exe[3028] image checksum mismatch; number of sections mismatch; time/date stamp mismatch; unknown module: MFC42.DLLunknown module: OLEAUT32.dll
.text C:\WINDOWS\System32\svchost.exe[3028] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\System32\svchost.exe[3028] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\System32\svchost.exe[3028] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\System32\svchost.exe[3028] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\System32\svchost.exe[3028] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\System32\svchost.exe[3028] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\wuauclt.exe[3084] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\wuauclt.exe[3084] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\wuauclt.exe[3084] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\wuauclt.exe[3084] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\wuauclt.exe[3084] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\wuauclt.exe[3084] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\ctfmon.exe[3688] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\WINDOWS\system32\ctfmon.exe[3688] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\WINDOWS\system32\ctfmon.exe[3688] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\WINDOWS\system32\ctfmon.exe[3688] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\WINDOWS\system32\ctfmon.exe[3688] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\WINDOWS\system32\ctfmon.exe[3688] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14