GMER 2.1.19155 - http://www.gmer.net Rootkit scan 2013-03-28 17:41:59 Windows 6.1.7600 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS542520K9SA00 rev.BBDOC33P 186,31GB Running: gmer.exe; Driver: C:\Users\XXX\AppData\Local\Temp\uxriqpow.sys ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 84E60579 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 84E84F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x94008000, 0x2D5378, 0xE8000020] .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x9AF5E000, 0xBB22, 0xE8000020] .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x9AF72300, 0x1BEE, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[368] USER32.dll!DialogBoxParamW 768C564A 5 Bytes JMP 74CB44C0 c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll .text C:\Windows\system32\wininit.exe[460] USER32.dll!DialogBoxParamW 768C564A 5 Bytes JMP 74CB44C0 c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll .text C:\Windows\system32\services.exe[520] USER32.dll!DialogBoxParamW 768C564A 5 Bytes JMP 74CB44C0 c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll .text C:\Windows\system32\lsass.exe[548] USER32.dll!DialogBoxParamW 768C564A 5 Bytes JMP 74CB44C0 c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll .text C:\Windows\system32\winlogon.exe[608] USER32.dll!DialogBoxParamW 768C564A 5 Bytes JMP 74CB44C0 c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll .text ... ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtDeleteFile] [74CB97E0] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryInformationFile] [74CB8F00] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtSetInformationFile] [74CB9830] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtDeleteKey] [74CBD810] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtOpenKey] [74CBD6D0] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtEnumerateKey] [74CBD4A0] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtDeleteValueKey] [74CBD860] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtSetValueKey] [74CBD5F0] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryValueKey] [74CBD580] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtCreateKey] [74CBD660] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtOpenFile] [74CB9680] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryKey] [74CB8EC0] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[520] @ C:\Windows\system32\services.exe [ntdll.dll!NtClose] [74CBD790] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\winlogon.exe[608] @ C:\Windows\system32\winlogon.exe [ntdll.dll!NtClose] [74CBD790] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\system32\winlogon.exe[608] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!LoadLibraryW] [74CB9510] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryW] [74CB9510] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryA] [74CB94C0] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [ntdll.dll!NtClose] [74CBD790] c:\progra~2\browse~1\261095~1.52\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [739C250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [739C2494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [739A5624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [739A56E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [739B8573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [739B4D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [739B50CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [739B51A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [739B66D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [739B82CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [739B8819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [739B907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [739BE21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1528] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [739B4C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Bind ????????? l??????e?????inf??@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4???{4d36e972-e325-11ce-bfc1-08002be10318}\0214?8}??@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4???{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?2D3??@nettun.inf,%msft%;Microsoft????@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4???{00000000-0000-0000-FFFF-FFFFFFFFFFFF}??"{??{4d36e972-e325-11ce-bfc1-08002be10318}\0216?????{4d36e972-e325-11ce-bfc1-08002be10318}\0205?????{4d36e972-e325-11ce-bfc1-08002be10318}\0211?8}??@nettun.inf,%msft%;Microsoft?????????????????????????????????????????????????B??X???3-???????????????????????e??????????????????????????????1a??????????????? ?????????????????????.??"?????l???????-4???????????????????????????????????e??*6to4mp?????nettun.inf??12??*6to4mp?????? ?????????????????????.??????????????????????s381??? ??????????????x???? ?????????????????????.????????????????????? ?????????????????????1??L????????? ???????68????????????????dem ??? ?????????????????????1????????????&?????????????????? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Route ?????????????o??????????????????Net?1???Microsoft???????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????Net?????????Net?????????????????????????????????????Net??????????????????????????d??????????????????????? ???????n????????????X??????t???t???????????t???????????e???????????????????????????????????????o??s?????????????????????????????????????????????????????????0??????w???????????????v???????????6??nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.1.7600.16385:*6to4mp?9??????????????????????????????????????????20??? l??????????????????????????????n???????????????t???????????????????????????????????n??????????Po??czenie lokalne* 341?ep??? ?????????????????????1??????*?0??? ?????????????????????????????????????????????????????????N??????r??????????? ???????Z?????????????1????????????&?????????????????????????????????????????.Po??czenie lokalne* 279????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Export ????????????????6.1.7600.16385?EA-????X???????????????`???????????????:??????0?gd_??????}"??.NTx86??????gendisk?????????em??????? ??tunnel??????????8}??nettun.inf?t%\??????????????????int??h???????????u??????????????????????????????@disk.inf,%genmanufacturer%;(Standardowe stacje dysk?w)?????tunnel??????????????????????????????????????????? ???????P?????46\??Net?????text????????f????????????????????????????1???????.???????????????????2??\D????????????????????N??????0??????????????????????????????? ??????????????????Microsoft????????????B???$???????t??????????????????????????????Microsoft???usb.inf?de??????e4??tunnel??????6.1.7600.16385??????????????Karta Microsoft 6to4????????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????*6to4mp??????????????n???????C??.NT?in??? ?????????????????????1????????????????????? ???????????????????{?1????????????????????????????????????????????????????*6to4mp?????? ?????????????????????1????????????????????? ????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????????TO?????????????????D????????????????????????????????????????????????????????????????????????tunnel??'????????????????????????????????????????B???????????????????????????????????????????????????????e??????????? (??????t???????????????_??Net???????????????R?????????????????????????????????????????s????????????????????????????j??Net?????? ???????|???????????i?:????????????&????????????????????2???????????i?????e76??Tcpip\Parameters\Interfaces\{E329E3B9-B1FB-4C90-8FF8-15F218EAF196}??{E??? ???????|?????????????9??????4?????&????????????????????-??????????????????????????????????????????????? ???????5??????BT??? ???????9?????0A3???????????-???7???????????D?????????d79??????????????????? ??????????????????Net??????????????v????????????????????????*???????????des ??????tunnel??????????????????s????????????????????y???b??e???????????11?ata??????????????????????BS??????????????????????Microsoft???? ???h???c??????????????????????\{???????????????????????????????????????6?????e????????????????? ???????|????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ????????? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????B??7B??6.1.7600.16385?_Tc??????C0????:??????-?g85??@nettun.inf,%msft%;Microsoft?_??????55???????????????????8??????????*6to4mp?\D??? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????3??8B???????????m??Tc??*6to4mp?21??? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????6??64???????????-??B4??????BC??? ?????????????????????1????????????&????????????????????5??????????????Urz?dzenie pami?ci masowej USB??"{??usbstor.inf?28???????????2??62??USBSTOR_BULK?F??? ?????????????????????1??L????????? ??????ft ???????????????2??? ?????????????????????.??"????????????????0BT???????????"??????F8??? ?????????????????????.?????????????????f??? ???????0?????B3D??USBSTOR\DiskHUAWEI__SD_Storage______2.31?USBSTOR\DiskHUAWEI__SD_Storage______?USBSTOR\DiskHUAWEI__?USBSTOR\HUAWEI__SD_Storage______2?HUAWEI__SD_Storage Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ?????z?????????????????????????????????????????????????????t???t???t????????? ???????t?????t???????,??L?????????????????????255.0.0.0???? ???????o??????????????????????P???????????? ???????t???????????t?,????????????&???????????????????????? ???q??????????d???v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|App=%ProgramFiles%\Windows Media Player\wmplayer.exe|Name=@FirewallAPI.dll,-31003|Desc=@FirewallAPI.dll,-31006|EmbedCtxt=@FirewallAPI.dll,-31002|?????????y??????????????????????WpdFsGroup??????????????????????????????????????Net?????????????????????????????????????????????????????tunnel?ip6???????????????j??????????????????@disk.inf,%disk_devdesc%;Stacja dysk?w??????usbcdcncm_6&35a029bf&1&0001_01???"???????????????????b??e???????????????????wpdbusenum\fs???????????????????em??????ge???????????#??????????????????gt???t??text?B???????????????????????"???????????k???????h??????????????? :?????????????????????????????????{4d36e967-e325-11ce-bfc1-08002be10318}\0010?????????????{00000000-0000-0000-0000-000000000000}????????????????????????????????????????????oft???tunnel????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ?????????????????8??????????*6to4mp?\D??? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????3??8B???????????m??Tc??*6to4mp?21??? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????6??64???????????-??B4??????BC??? ?????????????????????1????????????&????????????????????5??????????????Urz?dzenie pami?ci masowej USB??"{??usbstor.inf?28???????????2??62??USBSTOR_BULK?F??? ?????????????????????1??L????????? ??????ft ???????????????2??? ?????????????????????.??"????????????????0BT???????????"??????F8??? ?????????????????????.?????????????????f??? ???????0?????B3D??USBSTOR\DiskHUAWEI__SD_Storage______2.31?USBSTOR\DiskHUAWEI__SD_Storage______?USBSTOR\DiskHUAWEI__?USBSTOR\HUAWEI__SD_Storage______2?HUAWEI__SD_Storage______2?USBSTOR\GenDisk?GenDisk??57??? 4?????????????s ??USBSTOR\Disk?USBSTOR\RAW??????N??????9?????D2}??{e4d5f38c-2998-11e1-888f-806e6f6e6963}?F9B???? ??????1???e??????#?????????????N??????-????D491??{4d Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ?????5?????_???????_?????????$??????????????????????????????????????Microsoft???? ???????a????????????????????"??????????????I??????$???4????? ??????? ??????????????????????????????????????????????????????? ??????????? ??????????? ???????????????????????????????????????????0?????????????????????????**??????????+%?????????????? ???????H?????????????????? ???????? ???????????????????Y???????0???????????Y????????$???????????????????????????????$???????o??????????????????em???$???????????????????????????????$???????1??????????????????#{???$???????D??????????????????? ??@nettun.inf,%msft%;Microsoft????tunnel?513??????8}???????????????????????????????1???????????????????????????!???????????????????????????????????????????????????7??????????? ???????????7??????????????????{4d36e966-e325-11ce-bfc1-08002be10318}\0000??????????????????6??9-??????????int??????????????????????????????????????????{???????????B???????????????????????7????:????????giv???????????????????????????????????????????{???????????6???????????m????? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Bind ????????? ???????0??????s3??WpdFs?????????0???????????????????????????????0?????????????text????Microsoft???????????????????x???????????text????????????????nettun.inf???e??????????????????????????ESET?????????????????????_???????????????????????????P??????????????????? ?????????????????????.??"?????N???????????????????????????Po??czenie lokalne* 354??k??? ?????????????????????.????????????????????????? ???????????k??????x_??? ?????????????????????1??L????????? ??????-40??? ?????????????????????1????????????&????????????????????1??? ?????????????????????1????????????????????? ?????????????????????1????????z???????????? ?????????????????????1????????????????????????????????????????????????????????????????????????????????? ?????????????????????1????????????????????????5:??????????????????????????????????????5:????????????????????.Po??czenie lokalne* 166????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Route ????????????????tunnel??????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}??18??????18??????????@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4???Karta Microsoft 6to4 #126???@nettun.inf,%msft%;Microsoft????Karta Microsoft 6to4 #145?????N??????C????DCB5??????????????? ??int????????????????????????????????????????????? ???????int???????????????????????????????2??????3???3??????x????P????????????.Po??czenie lokalne* 405????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Export ????????? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????A??C-??6.1.7600.16385?A54????:??????S?g_T??@nettun.inf,%msft%;Microsoft?2???????????????????????????p??????????*6to4mp?-4??? ?????????????????????1?????????????????????????????????????0??-B???????????}??S_??? ???????Z?????????????1????????????&????????????????????S???????????-??????????Po??czenie lokalne* 167??????????????????? ??S????Z?????????????1????????????&???????????????????????? ??S??????????????????1??????*?.??? ???????????Karta Microsoft 6to4????????????????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????6.1.7600.16385????????:????????g????@nettun.inf,%msft%;Microsoft????int?????Typ??????????????e??????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????? ??????????????????*6to4mp?????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????$???????????????????? ?????????????????????1????????????&???????????????????????????????text????? ?????????????????????1??????*?0??? ???????????? ?????????????????????1????????????&????????????????????P??Po??czenie lokalne* 141?5?????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Route ????????????? ?????????????????????.??????????????????????s?????? ?????????????????????1??L????????? ????????????????????????????????????l??0???? ?????????????????????1????????????????????????????? ?????????????????????.??"?????N? ??????????????????v????????m?????????????????????????????)???Karta Microsoft 6to4 #123???????????????? ?????????????????????1????????????&???????????????????????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????4??}?????z??????a??a ??????????? ?????????????????????1??????????????????????????????????????????????????????C7-A563-299A????????????????0??????4??????????????????????????? ?????????????????????1????????????&???????????????????????????????Po??czenie lokalne* 461?????????????? ?????????????????????1????????????&????????????????????2??????? ?????????????????????1??????*?0??? ???????????????????????????????????Po??czenie lokalne* 462 Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Export ????????????????????????????s???????????????????????ud???????????K?????????tso???????????????????????????????????????????_???????????????????????????????????p???????????????????????????????????????e???????????????????????????????j???????????????????????????????????????k???i???????????????????????????????p???????'???s????????????????????????????????????????????????????X??????p???t??nettun.inf? 6t????:????????g?????????????????????????????????e???e????2??????1???????????????j????????????????????????????.Po??czenie lokalne* 275????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Bind ????????????????????????????????????????????????6-21-2006???????STORAGE\Volume\_??_USBSTOR#Disk&Ven_HUAWEI&Prod_SD_Storage&Rev_2.31#7&1b0def16&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}?????? ?????????????????????1????????????????????WUDFCoInstaller.dll?????????????? ??????????????? ?????????????????????,??????????????#Mas????J??????S???????e??Microsoft???? ???????T?????????????,??????????3?&????????????????????????????????????????????????\???????s????$??????}???????6??Root\*6TO4MP\0170???????????????????a ??tunnel?0-4??? ???????0?????????????,????????J???O????????????????????????????????????????}???????????:??????om??Microsoft?????$??????5???????A??Root\*6TO4MP\0169???*6to4mp???????????????$?????????????????Root\*6TO4MP\0171?????????????????????????$??????{???????s??????????usbcdcncm\Vid_12D1&Subclass_02&Prot_16&ext_ctrl?usbcdcncm\Vid_12d1&Pid_1506&MI_01&ext_ctrl??XX??????????????????????????????????????????????USB\UNKNOWN?????Root\*6TO4MP\0172????????????4??????D-????$?????????????????Root\*6TO4MP\0173???Net Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Route ????????text????? ????????????????????????????"?????????????C-???????????6????????m244???????????R??????????? ?????????????????????1????????????&????????????????????E??tunnel??BA???????????R??????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{7C7BBDEC-180D-4983-A67B-2962A724456B}] SEQPACKET 155???????????? ?$???????????????????1??????*?0??? ???????????????? ?????????????????????1??????*?0??? ???????????? ?????????????????????1??????*?0??? ???????????????? ?????????????????????1????????????????????????????????????nettun.inf?ese??? ??????????????????6to4mp.ndi??????? ??????????????????6-21-2006???? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????????????p??????6to4mp.ndi??es???????????m??????????Microsoft???????? ?????????????????????1??L????????? ???????????? ?????????????????????1????????????&????????????????????d??????????? ?????????????????????1?????????????????????????????????????????????C??59??????????? ??????????????????????????????????????????tunnel????????0???? Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Export ????el???????????????????????????????????????????????????????????????????????????????????????????F???????????????????????????????????????????????????????????7???????????????????7??????????????????????????????????????????????????????????????????????????????????????????????????? ???????????????????d???????????????????????????????????????????????????????????????????????????????.???????????????????n???????????????????7???????????????????????????????????????5?????????????????????????????????????????????????????????????????????????? ????????????????????????n???????????????????P???????????????????????????????????????d???????????????????n???????????????????n???????????????????????????????????????$??????????????????????????????*6to4mp?????? l??????C?????-B0??*6to4mp??B????????????L???????????????????????????????????`??B??????\c??????\c??*6to4mp???????? ?29=??????????????????????????????????????????????????????????????????????????????????????????????????2??????????e??????$???4????? ??????? ???????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Linkage@Bind ????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0191?98??input.inf????????????????????????9????N??????e???????e??????????? ?????????????????????.????????X???????????? ?????????????????????.????????X?????????????????????????????0Po??czenie lokalne* 1065???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Linkage@Route ????????????????????????16???????????????????6???0??? ?????????????????????.??"?????l???????98??{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?j?j??@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4?????????????????????????????????????m??????????????f??????????49??disk.inf????? ?????????????????????.??????????????????????s?????? ???????9??????x???? ?????????????????????.????????????????????? ?????????????????????1??L????????? ???????64??????????????????????? ?????????????????????1????????????&????????????????????4??? ?????????????????????1??????????????????????z??????6??1-??????$???4????? ??????? ??????????????????????????????????????????????????????? ??????????? ??????????? ??????????????????(?(???(?(?(???????(?(?(?(???(???(?????(?(???????@?@**?????(?(??+%?????(???@???? ??(????H????????(?(?(?(??? ???????? ????(???(?(???(?(??Y????@???????(?????(Y??@????@nettun.inf,%msft%;Microsoft?i??Karta Microsoft 6to4 #193?????X?????????????Microsoft???????4m??????11???????????e??????4???????????*6to4mp?????????????????????{00 Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Linkage@Export ????FF????N??????c??????????Net??????????????$???????e????????????????????????????????????????????????????????????????????????????N???????????D??????????????????????e??Net???????2??????s???e??? ??????????????????int?????????????????????????????????*6to4mp?????????ow????????????????????????????.Po??czenie lokalne* 662????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Bind ???????????@????????????input.inf????????????????????&??????????USB?N?????(??@???????????????-?@????????? ???????5??????????????????????????????serialui.dll????? P??|???B?????08D??????????????????????input.inf????????????????????????????????????????????@???????????????????A???????e??PCIIDE\IDEChannel\4&31187e8f&0&0????????USB??????????@???????????4??????????? ???????\?~?Z?????????????p???????????????????? ???????????????????????????????????PCIIDE\IDEChannel\4&5cb7943&0&0??????????^???}???e????*??|???F????d?\D??????????????????? ??#???????????????????????????????????s???????????????????????????????? ????????????????????H??@??????????PCI\VEN_1002&DEV_95C4&SUBSYS_FF501179&REV_00\4&3cb988f&0&0010?????B?????????????????????????? ??????Keyboard????????????input.inf???.NT?????????input.inf?????B?????????????????????????????????hdc?C:??????????????????????????????????????????????SCSIAdapter???????T??@???????????????????@???????h??????? ??????????????????????????????????????????? ??? ????????????????????????????????? Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Route ??????????T???????????c??????????????????????5???????????????5??7-13-2009???scecli????????????????????????6??????5?????????5?5???????????????1???????????5???????????5??ks.inf?wdmaudio.inf?hdaudio.inf??????{?|????????????? ???????5????????????????????????????"??@??????????????????????????????????????????*NTKERN?????????????????????????F???Microsoft???COM4????DOT4_????????????5???????????5????&??@????????c?????*6to4mp?????????????????? P??????C?????UNN?????z?u???? ???????????c??????????&??? ???????5???????5??msv1_0??????.NT??????????????5???????????s???@?@?U??????????MEDIA???? ??????????????n????????????????????????o???&???????????t???/???h??????????????????????????????????????E=???????????????????????????????e???????????????????????????????e???????t???????????????????????h???????????????h??????????????????.NT??????????f???????p???????????????h????V???????????c?????disk.inf?????????????????h??@%SystemRoot%\System32\StorProp.dll,-17000??????disk.inf????? ???????@???????????????????? ?????????????disk.inf????? ? Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Export ???@????????????input.inf????????????????????&??????????USB?N?????(??@???????????????-?@????????? ???????5??????????????????????????????serialui.dll????? P??|???B?????08D??????????????????????input.inf????????????????????????????????????????????@???????????????????A???????e??PCIIDE\IDEChannel\4&31187e8f&0&0????????USB??????????@???????????4??????????? ???????\?~?Z?????????????p???????????????????? ???????????????????????????????????PCIIDE\IDEChannel\4&5cb7943&0&0??????????^???}???e????*??|???F????d?\D??????????????????? ??#???????????????????????????????????s???????????????????????????????? ????????????????????H??@??????????PCI\VEN_1002&DEV_95C4&SUBSYS_FF501179&REV_00\4&3cb988f&0&0010?????B?????????????????????????? ??????Keyboard????????????input.inf???.NT?????????input.inf?????B?????????????????????????????????hdc?C:??????????????????????????????????????????????SCSIAdapter???????T??@???????????????????@???????h??????? ??????????????????????????????????????????? ??? ????????????????????????????????????????? Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ?????p????X??????b???t???????????????d???????j????????????????????????????H????????????????????????? ??????g??????N??t?????????n????????RV??????????????t????v?v?????v?v?v???????????????????????????/???????????????5 ?????????s????????j??USB??????????z????????????????????`??p?????????n????????????4&d8b462b&0??7??????????????t???????????????t????????????????????????i???????????j?o????USB?l0??????????????????p????|?|?}??????????????????????????????t????????l???}?}t???????t???2-27-2012????????o??????????\SystemRoot\system32\DRIVERS\lsi_fc.sys??3???????j??????p???SCSI Miniport?????P??j???????????d??lsi_fc.inf_x86_neutral_a7088f3644ca646a??????j?j?j?j?j?j????????????????t?????????????????????????????????????????R??j????????h?????\SystemRoot\system32\DRIVERS\lsi_sas.sys?3???????j??????p???SCSI Miniport?????R??j???????????d??lsi_sas.inf_x86_neutral_a4d6780f72cbd5b4?????j?j?j?j?j?j?j??????"??????g????????????????t?????????????????????????????????????????T??j????????h?????\SystemRoot\system32\DRIVERS\lsi_sas2.sys?????? Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ????????@disk.inf,%disk_devdesc%;Stacja dysk?w??????? ???????f??????sf??sffp_sd?????????t ???g?g?????????e???????e??volsnap??????j?j?j????h??g ??0????????r??9???????g???l??)????g?gt ??????????????????????volsnap?????UMB\UMBUS??????????????????????????????????????s?????i?i?g??Volume??????udfs?5??? ???????g???????????g?.??????$???????????????s?????????????????????????? ??? ???????g???????????g?.??????"?h???????????? 4??g???????????????g??? ???????f?????g???????.?????????????????1??? ???????g?????g???????.??"?????????????????ti???????U???????e???????g??? ???????g?????g???????.??"?????z???????????????{4d36e97d-e325-11ce-bfc1-08002be10318}??????????????????????????ms_ndiswanip????DiskDrive????g?g?????g?????g????h????????????????????????????????????????????????????0??????????????????????????????????????????? ???????g???????????g??? ???????g?????g???????1??L????????? ??????????????g???g???g??achi??? ???????g?????g???????1????????????&????????????????????O??? ???????g?????g???????1????????????????????? ???????g????? Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ?????????????p??????????????? ???????o?????p??????????????$???0?????????@%SystemRoot%\system32\wevtsvc.dll,-201?????? 4??p??????????????NT AUTHORITY\LocalService???????????????????????????????????????????? ???????????????????????????p????`??p??????????????????SeChangeNotifyPrivilege?SeImpersonatePrivilege????????>???????????h??????????????????????????p?p?p???? ??g??????p??????????o?????p???????????????????p??????p????v?v?????????????\??????\L???????????????????????????p???????p???????????p?p?p?p?p?p?p???????:???????????.?.?.???????????????p??????????6-21-2006????????p??? ???????o??????????????????????R?H?????????Video Save????????X??????????4???p?p?p???????s??*6to4mp??5???????????????????????p??????de??????????????????s???RpcSs?????????????????*????????????e????????????????????????????????? ??????t????u?up???system32\DRIVERS\AgileVpn.sys???system32\drivers\rdpencdd.sys???????????????t????????g???W???e???? ??????????e???????????????????????p??????????????tunnel?C76???????p????????????????????????????????b??q? Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ?????j??????????????????LegacyDriver?E???????????4?????????j????? ???????i?????j???????1????????????????????? ???????j???????????j?1????????????????????????????????????storprop.dll,AtaPropPageProvider???????j????? ???????i?????j???????1????????????????????? ?i???i???j?? j???j???j???j???j???j???j????????? ???????j???????????j?1????????B????????????j?jpr????:??j???????????????????????????i?????j????? ???????i?????j???????1????????????????????? ???????j???????????j?1????????:????????????????????????????j?j????internal_ide_channel??????B??j??????????storprop.dll,HdcCoInstaller??????j?jle???????????3?????????????????????????j????? ???????i?????j???????1????????????????????? ???????j???????????j?1????????????????????????????????????????????????????? ?????????j????????????????????????? ??l???k?????m?k???????f???u?????????n????????????G:\?????????????STORAGE\Volume???????????j??? B??j??????????????DETECTEDInternal\ACPI_HAL?DETECTED\ACPI_HAL????????????????????????????s????????????????s???????$????t????????????????? Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ?????????????????0???????????????j????????????\??j?????????e?????????j??????p???FSFilter Virtualization?????????????????ms??@%systemroot%\system32\drivers\luafv.sys,-100?????6??j????????h???????????????\??j?????????e?????????????????????????????j????????????????????????????????8??j????????h????????????????????????Urz?dzenie pami?ci masowej USB????????N?????????????????????1???????????????? ? Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export ?????s??????????? ???????? ????????????1????????????&???????????????????????????????????????????? ?????????????????????1????????????????????????????? ?????????????????????1?????????????????????????????e???e????2?????????????????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????generic_hid_device?f?f??????ow??????? ?????????????????????1????????????????????????????????????????? ?????????????????????1????????2???????????Urz?dzenie wej?ciowe USB????????????????????????????????????????????? ?????????????????????1????????????????????? ?????????????????????1????????????????????????????????????????????????????????????? ?????????????????????1????????????????????????????????????????????????????? ?????????????????????1????????????????????????????????????????????? ?????????????????????1????????????????????? ?????????????????????1??????????????????????&??????f???f??????????????????????????? ?????????????????????1????????????????????? ?????????????????????1??????? Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Bind ???j?t???k???????????????????????????????f?g?k?j????sE???f?j?k?k????????? ???Z???????????????????????????4????N??l??????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}???4???????~???D??sE??Printer??e??Volume???????????l???????y?????????????????s?????????g??????????????????????????????5???Microsoft????k??????????????? ??k??????????cp???????????????????????????e???.???e??????????????????????? ???n???/?????/?/??????????????t???????????????????????????????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}?i.i????N????????????4????? ???e??????????????disk????????????????????UMB??????????????2?????s?2???l?l???????????????????????????????????????????????s?????????????????k???????????????p???????????D???E???????????????????????????????????????D?????s\a??pk?k?k?k????s????????k??????s???????????????" ???????k???.??s????????o??@volume.inf,%msft%;Microsoft??????N??k???5?????D??????N??k????????D???????N??k???????????????????`???????e??.NT??????????????s?s?????????????????????????????$??????????STORAGE\Volume????????????????? Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Route ???k?y???h?hme???????????v???????????????e????N??h???8?????D68??? ????????????????????X??k??????????usbhub?5??????N??h?????????D?????????????7???????????????i??????????????????????????{00000000-0000-0000-ffff-ffffffffffff}???????????????o?????????n32??? ???????????????????h??????????????? ???????h?????h???????1?????????????????????????????;???