GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-05-23 15:50:37 Windows 6.1.7600 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 SAMSUNG_HD161HJ rev.JF100-19 149,05GB Running: w74b9sff.exe; Driver: C:\Users\Azrael\AppData\Local\Temp\kwrdypoc.sys ---- Kernel code sections - GMER 2.1 ---- .text ntoskrnl.exe!ZwSaveKeyEx + 13B1 830768E9 1 Byte [06] .text ntoskrnl.exe!KiDispatchInterrupt + 5A2 830963B2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [744F250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [744F2494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [744D5624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [744D56E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [744E8573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [744E4D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [744E50CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [744E51A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [744E66D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [744E82CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [744E8819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [744E907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [744EE21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll IAT C:\Windows\Explorer.EXE[1704] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [744E4C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Export ?????????????????????????????????????h??? ?????????????????????1????????????&????????????????????}??????nettun.inf??52??? ???????????????????U?-???????? ???????????????????????????????Microsoft????????e??????????????? ?????????????????????*??"?????l?k?????????monitor.inf:Generic.NTx86:PnPMonitor.Install:6.1.7600.16385:*pnp09ff?3???????????G????????m?Fi??????????????????????????????6to4mp.ndi??????? ?????????????????????1????????,???????????? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????????4??????????s????????????????????????????????S???????????????????????????????????B????`??????4???-??????????????? ?????????????????????-????????????????????????????????-A??*6to4mp?AA???????????????????B???????????????????????????h??nettun.inf??52??????????????? ?????????????????????1????????????????????? ?????????????????????1?????????????????????????0??????????? ??????????????????nettun.inf??t???6-21-2006????????????????????n???????????????????3????0?????????????tunnel??????? ? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????Wi??????????????????????????????????Parallel arbitrator???????R??????????????d????N????????????D?????????????E?????s3B??????48??????????7???Tcpip6?TCPIP6TUNNEL??9??ip???????????????e??????4???????4???????????????DF???????????o??????re???r?s?s?s?s?s???s?f????????????????s??????????E??????4???Root\*6TO4MP\0161????????????????h????????????z??????????????????????v???????????????????????????????????????????????o??????re??????????????????Re???????????M??????ft???????????y???????????????????k???????????????????h??11????????????????????????????????????????????????*??????}????dtBT???????????????????????????????????????????????????????????????????????????????????8??????????????????????int?F}??tunnel??0????????????????n????z??????`????????*??????4????d"{E??? ?????????????????????*??"?????l?&??????{??????????????????????????? l??????e?????e I????????????????????J??????????????d?????????????????????l????text?7??????????????? ?????????????????????1????????????????????? ?????????????????????1??????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ?????????????????????????????p??????s?????????????????????????????X??????e????????????????????????????:??????F?g67???????????B???????????????????????????g??????9????????v???????e??????00??{4d36e972-e325-11ce-bfc1-08002be10318}??????????????????????????????5-??Microsoft????????f??? ???????1?????????????,????????$????????>???????????>???????????????>???????????>???????????????????>???????????>???????:?>????'9???????"?>???>?????"?"???>?????:???>?????"?"???????"?????"?"???>?=????????????????????????????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Domain|LPort=RPC|App=%SystemRoot%\system32\vds.exe|Svc=vds|Name=@FirewallAPI.dll,-34502|Desc=@FirewallAPI.dll,-34503|EmbedCtxt=@FirewallAPI.dll,-34501|???????????t????????????5??sC???????????m??ta??Sine?????$???????i??????????????????el??????????????????????????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=3390|RA4=LocalSubnet|RA6=LocalSubnet|App=System|Name=@FirewallAPI.dll,-30793|Desc=@FirewallAPI.dll,-30796|EmbedCtxt=@FirewallAPI.dll,-30752|?????????????&???????h???????????????????v???&???????5???????????????????l???&??????????????????????????????? ???????????????????????????w??????os??Microsoft???? ???????@???????????????????? ?0???????????HID_Mouse_Inst????? Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Route ????el??????????????????????????16???????????????????????????????????????????0??????F}????????N??????c????????????.??????????t??Karta Microsoft 6to4 #107???????????????????????????Karta Microsoft 6to4 #110????????????????e??????????????Typ??????????????0??????????????????@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4?????N????????????D?????????????c?????s x??????9???{4d36e972-e325-11ce-bfc1-08002be10318}\0119?81??? ???????&???????&????X??????y??????{4d36e972-e325-11ce-bfc1-08002be10318}\0151??&???????????????????????????????????????&??????????? ???????1???????????????????6?????s-9???????????????????????????5??e ??????????????????????????????????????????????????????????? ??????????????????@nettun.inf,%6to4mp.displayname%;Karta Microsoft 6to4?????:??????B?g\D???????l??????????Typ??t??????????????????????????*6to4mp?????? ???????8?????2????{4d36e972-e325-11ce-bfc1-08002be10318}??????1????????????????????B????X??????e????????4?????????????16???????????s??????l,??{4d36e972-e325-11ce-bfc1-08002be10318}\0121 Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Export ?????????????????????? ??????????????????????????????????????8??\{???????????????e???????????????????????????????R???????????????h??????????? ???????????????????~???????????????????????????????b????????m?????????????????????Net??????????????????????????B???????4???????4??tunnel??????*6to4mp??-???????l??? ???????8??????n"??? ??????????????????????????????????????????????Adres sieciowy??Ty??? ????????????????????????????????????????????????????????c?tu???????????????t???????????t??ow???????????i???e??tunnel?FD ????>?????????????Sterownik karty Microsoft 6to4??? ??? ??????????????tu??tunnel???????????????9??????89??????????????????????????? ?????????????????????,?????????????????f????????????????????????N????????????D????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}??????? ???????1?????????????,????????$?0????????????e??????????????????????????????s??????????????????????????????? ???????`??????????????????????????????????????????? ???????`???????????`?????????????? ???????????????????????????????? ???????`?????????????,????????????????????????? ???????`???????????`????????*?????????????netfxcustomperfcounters.1.0?SharedPerfIPCBlock?Cor_Private_IPCBlock?Cor_Public_IPCBlock_?????????????????????????0??? ???????`???????????`?,????????,?????????s??????????`???????q??clbcatq.dll??????????`??????2????e?e?d???????`??????????advapi32.dll?????`???`???????????????????`??????????COMDLG32.dll????IMM32.dll?????,??`? Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???k????tunnel?43F???????????n???????4??@%systemroot%\system32\drivers\hwpolicy.sys,-101?????????????p???????????????????????????????????????????????B??USB001?|????Microsoft????u?u?t???????y????b??n?????????e??????????????????????????????Z??p????????h?????????????????System32\DRIVERS\fvevol.sys????????o?&?o?&?n???n?n???????????????????l?l?p?t?t?n?n??????????????????????? ???????o?????n???????,???????????????????o????? ???????n?????n???????,?? ?????????????????? ???????n?????????????,??L?????????????????? ???????n?????n???????,????????????&???????????????????????? ???????n?????n?? ????,??????6????????????????????????????????????n?????????????4???????????????????????u?????????????????????????????????????????????n?&?n?&???????????????????? ???????????????????U?,??????????????#7c6??Root\*6TO4MP\0137?????0??????v???????|??? ???i???r??????????????????*teredo?????????????????????????#???? ???????U???????????U?,??????????????????????????????????????????????????????????????????????????????????}?????@system32\DRIVERS\pci.sys,#65536;PCI bus %1 Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind ???k?m???????????????????h???????e??{00000000-0000-0000-ffff-ffffffffffff}??????????????????s????????????m?ms???? ???????k?????k?????k?,???????????? ???????R????m?m?.???k??{4d36e972-e325-11ce-bfc1-08002be10318}???????????S???????e???g?i?i?f?i?j?i?k?k?k?k????????????????????????N??????u???????????????l???????????????????????????????????v???????/??? ??????????????t??????????????g??????????????????????X????????????????4?????????????2???m?m???????????????????s??????????????????????????:??s????????h?????????????????????HIDClass?????????????????k??? ???????k?????k?????k?,?????????? ? ???????C???? ???????k?????????????,????????N???????????{8ECC055D-047F-11D1-A537-0000F8753ED1}?????????k?&??????????????????????????????????????????????????????????????????????????t???????????????t????k???k???????j???.???????.??? ??????????????????LPLAYER??????????????????????????k??? ???????k?????k?????k?,??????????!? ???????L????????????????????k??? ???????k???????????f?,????????^???????????????????????????????????????????t??????k?&? Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route ????????????????@nettun.inf,%msft%;Microsoft?p????2?????????????????tunnel??????????????Sawtooth Up??????????????0??4f???????????`?????s?`?????????????????????e????ROOT\*6TO4MP\0001???@oem3.inf,%hid\vid_046d&pid_ca03.devicename%;Logitech MOMO Racing (HID)?????? ?????????????????????1????????????????????\\?\USB#VID_0FCE&PID_0171#BX9033SZ1G#{48f4db72-7c6a-4ab0-9e1a-470e3cdbf26a}??????????????????k???f???????l???????????v???????????w?????????????????s??????????????>??????t??????USBPRINT\HPDeskjet_F300_serieDFCE?HPDeskjet_F300_serieDFCE??????Karta Microsoft 6to4????????6to4mp.ndi???h??? ???????i?????e?h??@nettun.inf,%msft%;Microsoft????S5230?30G???? l?????????????????tunnel????????????????????????????????*??????i?????????n?i??Net?????11???????????????p??? ???m???????????i???@?@?A?A?A?A????????? ???????????????????e?1????????????????????SEMC Mass Storage USB Device????? ???????D?????4}"??????????????????Net?????????????????????L2?03???????m???? ???????????????????????????????????5????z??????????????m????0??????j? Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export ?????????????????????????????????????' ??2??????text????????t???????di?????????????? 1??????F}??? ???????????????????????????????s????`???????????????????????????????????X??????????t???????????E??????-4???????5???????????????????????????????????????????????t??11???????????????????????e???????m??????????????????Sterownik modu?u wyliczaj?cego dysku wirtualnego Microsoft?11c??11???????????????????????????????#????????????????????????m?????????????????????????????????????????????11????????????????????????m??????????????d????????m?fP????????????????????????N??????0?????D01??????2??????????????????????????????????????????????????????????????????????s?????????????i???e????N??????D?????S\v?????????????????s???????????????????s?????????????????????????????e???????l???????????v??_N??*6to4mp??????????????e??52???????????4??????????*6to4mp???????????????????z????????????????u????????????????????text?????????????????t??? ?????????????????????1????????????????????? ???????????????????y?1????????z????????????????????c??p6? Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Bind ???i?l??????????????xe??? ???????i?????i?????;?-??(????????????????????????????????????????s?????i?i????? ???????i?????i???????3?????????????????????????8???j?j????? ???????i???????????i?3?????????????????????y???????????5?????????????i???????? ????8?????????????????j?????i??????????????? ???????j?????i???????1????????????????????? ???????i???????????i?1?????????????????????????????u???????????i???/???8??mshdc.inf????i?i???????i????? ???????j?????i???????1?????????????????????????????n??Ge????B??i???o??NT??? ???????i???????????i?1?????????????????????????????????????????i??????????atapi_Inst???????i?i???????i????? ???????j?????i???????1????????????????????? ???????i???????????i?1????????*?????????????????????????????*??i??????????internal_ide_channel?????i?i???????i????? ???????j?????i???????1????????????????????? ???????i???????????i?1?????????????????????????????8???????????i??????????Microsoft????i?iSy?????i????? ???????j?????i???????1????????????????????? ?j???j???j???i???i???i???i???i???i???i????????? ? Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Route ??????????????????N??????E????D334????????????????????????????????????????????????,Po??czenie lokalne* 33???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????0Karta Microsoft 6to4 #26?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export ?????s??@nettun.inf,%msft%;Microsoft?A??Karta Microsoft 6to4 #41????@nettun.inf,%msft%;Microsoft????Karta Microsoft 6to4 #42????? ???t???0?????000????2??????A??????DA??{4d36e972-e325-11ce-bfc1-08002be10318}?BF}????N??????2????D-43????2?????????????16???????????????e????N??????i???????k??? ~????????????0?????????????????????v???????????????????????????????????????????i???t??????????????????????????????????????Typ??????????????k?k????????????????????????????????????????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????{4d36e972-e325-11ce-bfc1-08002be10318}\0055?? ????2?????????????16??{4d36e972-e325-11ce-bfc1-08002be10318}??????? ???z??????????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0056?????{4d36e972-e325-11ce-bfc1-08002be10318}?21C????2??????3??????11?????????????????s????? ???y???0?????E83??? ???????6?????AP.??????????????????{4d36e972-e325-11ce-bfc1-08002be10318}?002??? ???s???g?????i?l??{4d36e972-e325-11ce-bfc1-08002be10318}\0058?? ??{4d36e972-e325-11ce-bfc1-08002be10318}? Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Bind ???i?p??WPD??????v?|?v???????????.???;???????e???????e??System????????P??t?????????e??????N??k?????????e?????????f???????????f???????????f?f?h?????f?????f??????????????????$???4????? ??????? ????t?????????? ????????????????????????????????????????? ????????$???f??????????????????????????????$???4????? ??????? ????t?????????? ????????????????????????????????????????? ????????$???f??????????????????????????????$???4????? ??????? ????t?????????? ????????????????????????????????????????? ?????????X??????n?????????????????????sde??{00000000-0000-0000-ffff-ffffffffffff}??Si??4&313ffe17&0??????N??????e????Dlne????