GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2011-02-10 00:32:14 Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST9120822AS rev.3.ALD Running: 75wh7syr.exe; Driver: C:\Users\XxXxX\AppData\Local\Temp\fwryykod.sys ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Bind ????????????Teredo Tunneling Pseudo-Interface?????$?????????????????Root\*6TO4MP\0024???? ???????1?????????????,??N?????$?????????i?p??? ?????????????o?????????????????????????y??????{4d36e972-e325-11ce-bfc1-08002be10318}\0026?? ??{AADE5F5F-ECF0-4D29-8A1D-C4784EC3C0C5}??????? ???????????????????????????????????????A??? ????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ????????{36fc9e60-c465-11cf-8056-444553540000}\0010??&??? @??????????????????k???????????????????j??????s???????????????t???????????????t????????????????????????????p??????????{36fc9e60-c465-11cf-8056-444553540000}???5??????????{4d36e97d-e325-11ce-bfc1-08002be10318}\0006?in??@netrasa.inf,%msft%;Microsoft????????????????????????????o????*????????????????n????@volsnap.inf,%msft%;Microsoft???t?????X?????????????????????????? ???????k???????????k?,???????????????????S????? ?????????????????????,????????N???????????LegacyDriver????????????????????LegacyDriver????????????????????????????t????????????????????w??????????volsnap??????i?k?k?k?k???k????X??????????????????????????e???????????????? ????????????s????????????????????????????????? ?????????????????????-??(???????????????????s?????? ?????????????????????-??4?????????????????????????????????? ?????????????????????-?????????????????????y??????????? ?????????????????????,??????"???????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ????????? ??????????????????????????*6to4mp?????? ?????????????????????1????????????????????? ???????????????????s?1?????????????????????????????????????7???????????????*??AT??? ?????????????s???????1????????????&???????????????????????? ?????????????s???????1????????????????????? ???????o?????????????-????????T????????c???w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?x?x?w?w?w?w?x?w?w?x?x?x?x?w?w?w?w?w?w?w?w?w?w?w?x?x?x?x?x?x?x?x?x?x?x?x?w?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?y?y?y?y?y?y?y?y?y?x?x?y?y?y?y?y?y?y?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?x?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?w?x?x?x?x?x?x?x?x?x?x?x?x?x?y?y?x?x?y???????????x???????????y?y?y?y?y?y?y??????????????????????????????????????????????????????????????????????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Bind ????DC???????????????????????A????????????????????????????????m?????????????????\e???????C??????????????????????????????????????????????????????????te????$??????l??????????ROOT\*6TO4MP\0121????????????????????????????????1??????????? ???????????????&???????????????????????2???????????*??????????? ??????????????????? ???????????????????????????-???????????????????????????????????????"???t??6.1.7600.16385??????? P??????6?????C9-????*??????F????d"{2??? *?????????????????Karta Microsoft 6to4??????????X??????e??????? ???????Z?????????????1??????????I?&???????????????????????? ?????????????????????1??????*?0??? ????????????????????u???????????????????????t??????????Po??czenie lokalne* 130?????????????????????l??????????????? ??? ??? ??????? ??????????????? ??? ??? ??????? ??????? ??????? ??? ??????? ???????????????????????????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{C5FD0974-A5F4-403E-9607-99D80A546317}] SEQPACKET 136?????????????????????????????????????????????????? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Route ????????? ???????}????????????????????"?????????????8C??tunnel?Att??????????????????????????int?-B??????????????????????????????????????????????? ?????????????????????,??????????????????????N?????????????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}??????? ???????1?????????????,????????$?????????????????????????????????????~??????????????????????CA???????????}???e??Net??????????6????????????N??????~??????????????? ???????|???????????l?:????????????&????????????????????F??6to4mp.ndi??????????????????????????Microsoft???? ?????????????????????1????????????????????????????????????????????????????????Microsoft?????????,??????????????????????????o???????????????????.??????02????z?????????????????????io??v2.10|Action=Allow|Active=FALSE|Dir=Out|Protocol=17|RPort=1900|RA4=LocalSub Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Bind ????????? ?????????????????????-??????????????????????sCED??? ??????????????x???? ?????????????????????,?????????????????f??? ?????????????????????1??L????????? ???????68????????????????P?????? ?????????????????????1????????????&???????????????????????? ?????????????????????1??????????????????????????????????????N??????e????Dlne??? ?????????????????????-??????????????????????sl,-??? ?????????????????????,?????????????????f??? ?????????????????????1??L????????? ???????68????????????????????????z??????I??ll??? ?????????????????????-????????????????????????????????????????*6to4mp?????? ???????Z?????????????1????????????&???????????????????????? ?????????????????????1??????*?0??? ???????in???????????e??????????d4??????????? ????????????0??????w???e??Po??czenie lokalne* 147?????{4d36e972-e325-11ce-bfc1-08002be10318}?CED??? ??????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0256???????4?????????????16??Karta Microsoft 6to4 #243?????:?????????????@nettun.inf,%msft%;Microsoft??????X??????????????????????????e? Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Route ????????????????????????????????????????????{FB11B485-1D85-4F31-80F8-E26486D0CAC4}???&????? ???????O???? ???????k???????????k?,????????`??????????????????????????s?????}?|gr??????? ???????k???????????k?,?????????????????????T??NativeWifiP?????fltmgr????? Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind ???o?q?????????????g??????????????????????????????P??p?????????e?????????????????????????? ??n?????????t????s???%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe????Microsoft .NET Framework NGEN????????????????????????????????6?g59??????????????t???Net??????????????????????????????????????????????????n??????????????? ???????n?????????????,?????????????????f???????????o??? ???????n?????n???????-??L????????? ??????Bri???????n???7??????? ???????n?????????????,??????????????????????0?????input.inf:Standard.NTx86:HID_Inst:6.1.7600.16385::generic_hid_device:usb\class_03&subclass_01:usb\class_03??????? ???????n?????n???????3????????????????????? ???????n???????????n?3?????????????????????????????M??se???????n???????????n?nUS?????n????? ???????n?????n???????3???????????????????????o???n???n?????????????????o??? ???????n?????o???????-????????????&???????????????????????? ??????Ho???????????n?-????????????????????PS/2+USB Mouse?????????n????? ???????n?????n???????3????????????&????????????????????????o???o? Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route ?????o???????????R??????????tunnel??????????????tunnel???T??????????????????????????????s???? t?????????????????????????????????????????????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}??????? X??????????????????????p?????????????????????????s????????????????????????????????????????? ??????????????????T_????h??s??????s??????????????????????????????????????????????????????s B??USB\ROOT_HUB&VID8086&PID2831&REV0003?USB\ROOT_HUB&VID8086&PID2831?USB\ROOT_HUB???????????????????&???????????????5???????????????z??????? ??????????????????????????????t???? ???k???4?????????????????????????s??????????????N???????????D?????Net???????N??????5?????D0F??LegacyDriver????????????????????volsnap???????N???????????????????N?????? ????DOS ????N???????????D???????